
Fake LastPass Authenticator Pages Deliver Rapuncel Infostealer
Attackers impersonated LastPass Authenticator on fake GitHub pages to deliver the Rapuncel infostealer in a campaign involving 40 fake brands.

Attackers impersonated LastPass Authenticator on fake GitHub pages to deliver the Rapuncel infostealer in a campaign involving 40 fake brands.
September 21, 2026 | 3 min read

Let’s ask a simple question that seems to be getting lost in all of the credulous fervor around AI: How’s this working out for everyone?
September 21, 2026 | 3 min read

Active since at least August 2025, the malware represents a functional pivot from the threat actor’s existing SparrowDoor backdoor.
September 16, 2026 | 3 min read
Fake LastPass Authenticator Pages Deliver Rapuncel Infostealer
September 21, 2026 | 3 min read
‘We Have Enough AI’: Realism in a Time of Relentless Hype
September 21, 2026 | 3 min read
New SparroWocky Backdoor Targets Latin America
September 16, 2026 | 3 min read
September 16, 2026 | 1 min read
September 8, 2026 | 1 min read
Let’s ask a simple question that seems to be getting lost in all of the credulous fervor around AI: How’s this working out for everyone?
Read More ‘We Have Enough AI’: Realism in a Time of Relentless Hype
Active since at least August 2025, the malware represents a functional pivot from the threat actor’s existing SparrowDoor backdoor.
A new joint advisory from multiple law enforcement agencies this week warned of an Iranian cyber campaign targeting dissidents and journalists in the U.S., UK, and elsewhere.
Read More US, UK Agencies Detail Iranian Malware Campaign Targeting Dissidents
Messages delivered through legitimate third-party email infrastructure had C-suite sender display names, custom signatures, and direct approval notes.
A Russian web developer allegedly behind a massive bank account takeover scheme was extradited to the U.S.
Read More Russian National Extradited to US to Face Bank Account Takeover Charges
Labeled “MikroTrick” by researchers at CERT Polska who discovered and disclosed six vulnerabilities in the software, the campaign targets devices with SSH services reachable from the public internet