From Our Blog
Fake password-manager alerts could put your vault at risk
You open your inbox and see a message about updated security policies. Nothing about it screams scam. The email looks polished, the wording sounds official and the button promises a quick way to review the changes. That is exactly what makes it dangerous.
LastPass is warning users about a newly identified phishing campaign that uses lookalike domains and a fake DocuSign page to lure people into downloading suspicious software.
The good news is that LastPass says its systems were not affected. The bad news is that scammers are counting on you to trust the logo, overlook the web address and click before taking a closer look. Here is what to watch for before one routine-looking email puts your entire password vault at risk.
Free live CyberGuy class: Sick of Spam? Join us July 22
Join us TODAY, Wednesday, July 22, at 1 PM ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt "CyberGuy" Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. You’ll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.
Reserve your free spot today at CyberGuyLive.com.
FBI HELPS TAKE DOWN AI PHISHING RING
LastPass phishing scam starts with a routine policy email
The phishing email comes from hello@lastpassnewsletter.com. Its known subject line reads, "Action Required: Review Updated LastPass Security Policies." Inside, the message claims LastPass has made service policy changes. It mentions enhanced SaaS monitoring. It also claims administrators can reset master passwords and that the admin console has improved.
Those details make the email sound like a real company notice. However, the sending domain belongs to the attackers. LastPass says lastpassnewsletter[.]com has no affiliation with the company. The email includes a Review & Access Terms button. That button creates the next layer of the trap.
Clicking the button sends you to lastpasscompliance[.]com. The landing page copies the look of DocuSign and claims a document is ready for review. That choice makes sense from a scammer's perspective. Many people receive electronic signature requests at work or while handling personal paperwork. A familiar layout can lower your guard before you inspect the web address.
We have seen the same trust trick in other fake DocuSign email scams. The brand name gives the request a sense of legitimacy, even when the sender and domain do not match. LastPass says Microsoft Defender for Office 365 and Cloudflare classified the phishing site as malicious. The page also prompted visitors to download software that claimed to work on Windows and macOS.
LastPass was still investigating the download when it published its warning. Therefore, you should treat the file as dangerous and avoid opening it. The site also displayed a live support chat box, although it was unclear whether the chat worked. The malicious page had gone offline by the time the campaign was reported. However, attackers can quickly replace blocked domains with new ones.
LastPass users are not the only targets. Bitwarden customers have received similar messages from hello@bitwardennewsletter.com. Those emails directed recipients to bitwardencompliance[.]com. The matching format suggests attackers may be reusing the same campaign structure across password manager brands.
That matters because password manager customers present an attractive target. One stolen master password could put many saved accounts at risk. Multi-factor authentication may still block access, depending on your security settings.
A password manager remains valuable protection. In fact, autofill can help expose a fake website because the manager should recognize the legitimate domain. You can compare current options in our guide to the best password managers for 2026 at cyberguy.com
This campaign follows other LastPass-themed phishing attempts from earlier this year. In January, fake messages warned that users had only 24 hours to back up their vaults before maintenance. Then, a March campaign used fabricated email threads about unauthorized account access.
Both approaches relied on urgency to push people into acting before they verified the message. The new compliance notice uses a calmer approach. It looks like paperwork rather than a crisis. That may make it especially effective because policy updates feel normal and boring.
REDHOOK ANDROID MALWARE CAN QUIETLY HIJACK YOUR PHONE
A few careful steps can keep one convincing email from turning into a much larger problem.
Delete the message or report it as phishing. Do not reply. Avoid opening its links or downloading the file it offers.
Use the official LastPass app or type lastpass.com into your browser. Check for account notices after you sign in through the trusted route.
Lookalike domains often add a trusted brand name to words such as "newsletter" or "compliance." Check the website address before the first slash. A legitimate LastPass address should end in lastpass.com, such as support.lastpass.com, rather than merely containing the word "LastPass."
A password manager may refuse to fill your credentials on a fake domain. Treat that as a warning. Do not copy and paste the password to get around it. Instead, close the page and access your account through the official app or website.
Use a trusted device and go directly to LastPass. Change the master password immediately. Then review your vault for unexpected activity, as LastPass recommends. Next, change passwords for sensitive accounts stored in the vault if you see signs of access. Start with email, financial accounts, cloud storage and social media. Use a different password for every account.
AMAZON RECALL TEXT SCAM COMES WITH RED FLAGS
Do not open software offered by a security notice you reached through email. If you already opened the file, disconnect the affected device from the internet. Then use strong antivirus software to inspect it. Our current best antivirus protection guide at cyberguy.com can help you compare tools that block malicious websites and dangerous downloads. It also covers protection against malware. You can also follow these steps after you clicked a suspicious email and entered information.
Enable multi-factor authentication for your password manager and other important accounts. An authenticator app or security key can add a barrier if someone steals your password. However, never approve a login request you did not initiate. A second security step only helps when you treat unexpected prompts as a warning.
Scammers often use information from data broker sites to make phishing emails feel more personal. That could include your phone number, home address, relatives or past employers. A data removal service can help find and remove some of that information from people-search websites. It will not secure a compromised password manager, but it may give scammers fewer details to use in future attacks. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
Forward questionable LastPass-branded emails to abuse@lastpass.com. LastPass says no one from the company will ever ask for your master password.
What makes this scam dangerous is how normal the email looks. Most people expect password manager alerts to sound urgent. This one arrives dressed up as a boring policy update, which may make you less likely to question it. The biggest red flag is the web address. A company name inside a domain does not mean the company owns it. Before entering a master password or downloading anything, close the email and open the password manager directly. Your master password protects everything stored in your vault. Treat any request for it like someone asking for the keys to your house.
Have you ever received a security email that looked so real you almost clicked? What made you stop and take a closer look? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report
Copyright 2026 CyberGuy.com. All rights reserved.
Robot bird swims underwater then flies away
Watching a diving bird vanish beneath the water can feel almost unreal. One moment it cruises through the sky. Seconds later, it swims after prey before returning to the air. Around 100 bird species can move between those two environments. Engineers have found that natural ability incredibly difficult to recreate at a small scale.
Now, researchers at MIT and the Swiss Federal Institute of Technology Lausanne, known as EPFL, have built a robotic bird that can complete the entire journey. The 8.8-ounce robot flies, plunges into water and swims below the surface. Then it launches back into the air using the same set of flapping wings.
NEW YORK SCHOOL DISTRICT TO DEPLOY HUMANOID ROBOT IN CLASSROOMS THIS FALL
According to the research team, it marks the first bird-scale robot to complete that full cycle through flapping motion alone. The research appeared in the journal Science.
Free live CyberGuy class: Sick of Spam? Join us July 22
Join us TODAY, Wednesday, July 22, at 1 PM ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt "CyberGuy" Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. You’ll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.
Reserve your free spot today at CyberGuyLive.com.
Most amphibious robots use separate systems for air and water. This mechanical bird takes a simpler approach. The robot relies on flapping wings instead of propellers. It also completes its water launch without legs or a complicated wing-folding mechanism.
That design presents a major engineering problem. Water is about 800 times denser than air, so wings face far greater resistance once they enter the water. To handle that dramatic change, the robot adjusts its flapping speed. Its flexible wings also change shape as the surrounding pressure increases.
In the air, the robot can flap its wings up to 11 times per second. Underwater, its flapping rate ranges from 0.1 to 6 times per second. Meanwhile, water pressure can bend the wings by as much as 90%. That flexibility shortens the effective sweep of each stroke and reduces the load on the motor.
The same wings become more effective for flight once the robot reaches the air. Researchers also made the machine neutrally buoyant. As a result, it neither rises nor sinks on its own while underwater. That balance helps conserve battery power because the robot spends less energy fighting buoyancy.
The hardest part begins when the robot tries to leave the water. It completes the transition in under one second using about eight to 10 wingbeats. However, the maneuver requires a careful combination of wing flexibility, tail placement and launch angle.
Researchers found that moderately flexible wings worked best. A rigid wing struggles to adapt underwater, while excessive flexibility reduces the force needed for takeoff. The tail also needs to remain short and close to the body. Otherwise, it can drag through the water and pull the robot back down. An exit angle near 70 degrees produced the strongest results. A flatter approach creates too much tail drag. A nearly vertical launch can make the robot tip backward into the water.
ZELENSKYY ANNOUNCES 'THE FUTURE IS HERE' AFTER WAR'S FIRST ALL-ROBOT CAPTURE
The machine also gives scientists a new way to study real diving birds. Tracking the movement of a live bird beneath the surface can be difficult. With a robot, researchers can adjust one feature and measure how that change affects performance.
For example, many diving birds reduce their wingspan while swimming. Researchers have often connected that behavior with lower energy use. The robot's results suggest that shorter underwater strokes may instead help birds increase speed.
The team also compared the machine's propulsion efficiency with that of real birds. Both fell within a Strouhal number range of 0.2 to 0.4, which researchers associate with efficient movement. However, body size can change the launch strategy. Heavier diving birds may use their legs to help push away from the water, while this lightweight robot relies entirely on its wings.
The robot's most efficient travel mode depends on the distance ahead. According to the team's data, flying uses less energy once a journey extends beyond roughly 51 feet. For shorter trips, staying underwater may make more sense.
Water creates heavy resistance, so swimming becomes increasingly costly over longer distances. A future robot could use that difference to plan its route. It might swim toward a nearby target, surface and then fly to a more distant location.
The prototype costs around $300 in materials and uses parts that researchers can source commercially. The team also released open CAD files for the project. That could allow universities and other builders with access to a 3D printer to reproduce the design.
Eventually, the robotic bird could help scientists monitor waterways and coastal environments. Researchers imagine launching it from shore or a boat. It could fly toward an area of interest, dive to collect a sample and then return with the data.
Potential missions could include taking measurements near an iceberg or observing marine wildlife from a safer distance. Flapping wings may also offer practical advantages in those environments. They avoid exposed high-speed propeller blades and could produce less noise around animals. Underwater, flexible wings may tolerate contact with debris better than rigid propellers.
INSIDE CHINA’S AI ‘WOLF PACK’ DRONES BUILT WITH TAIWAN CONFLICT IN MIND
The current prototype still relies on human control during key parts of its journey. Researchers manually launched the robot during several tests. Timers or basic triggers also activated parts of its diving and swimming behavior.
Autonomous navigation represents the next major step. The robot would need to recognize its surroundings and control each transition without human assistance. Salt water creates another hurdle. Testing has focused on fresh water, so future versions will need stronger protection against corrosion. Longer range and improved endurance would also make the robot more useful outside controlled experiments.
You probably will not see robotic birds patrolling your local beach anytime soon. Still, this project shows how future drones could reach places that traditional flying machines struggle to explore. A single robot could gather information above the water before taking measurements below the surface. That flexibility could reduce the need for separate aircraft and underwater vehicles.
The low material cost also matters. Smaller research teams could experiment with the design without investing in an expensive custom platform. As navigation and battery performance improve, machines like this could make environmental monitoring more accessible.
What stands out here is how much work the researchers get from one flexible set of wings. The robot changes its flapping speed, while the wings naturally bend to handle the resistance underwater. The launch back into the air makes this more than another bird-inspired drone. Pulling off that transition requires the right wing stiffness and a carefully controlled exit angle. The prototype still needs autonomous controls and better protection for saltwater. Even so, its $300 material cost and open design could give other researchers an affordable foundation to build on.
Would robotic birds collecting environmental data make you feel hopeful about conservation, or uneasy about machines blending into natural habitats? Let us know by writing to us at Cyberguy.com.
Sign up for my FREE CyberGuy Report
Copyright 2026 CyberGuy.com. All rights reserved.
CrashStealer Mac malware steals passwords and wallets
A polished installer can make risky software feel routine. You see a familiar Mac window, follow the directions and enter your password when asked. By then, the app may already be working against you.
Security researchers at Jamf Threat Labs have uncovered CrashStealer, a new Mac information stealer that impersonates Apple's crash-reporting software. Jamf first tracked the malware in May 2026 while it appeared to be under development. By early July, researchers detected it in active attacks.
Free live CyberGuy class: Sick of Spam? Join us on July 22.
Join us this Wednesday, July 22, at 1 PM ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt "CyberGuy" Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. You’ll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.
Reserve your free spot today at CyberGuyLive.com.
REDHOOK ANDROID MALWARE CAN QUIETLY HIJACK YOUR PHONE
CrashStealer targets information many people rely on every day. It searches for browser credentials, password-manager data and cryptocurrency wallet information. The malware can copy the Mac login Keychain as well. The malware stands out because its developers wrote it in native C++. Many common Mac stealers rely on AppleScript or simpler software wrappers.
CrashStealer also encrypts the files it collects before sending them to an attacker-controlled server. Meanwhile, anti-debugging features make the malware harder for researchers to examine. However, the first app a victim sees isn’t called CrashStealer. The attack begins with a disk image branded as "Werkbit Setup."
The Werkbit Setup disk image contains a polished installer. Its directions tell the user to right-click the app and choose Open. That action often appears in instructions for software that needs to get around a Mac security warning. In this case, the installer already carried a valid Apple Developer ID and a notarization ticket. Therefore, it could clear Gatekeeper on its first launch. Jamf also found that the disk image itself had been signed, which researchers called unusual for malicious Mac delivery.
The website that distributed Werkbit Setup required a meeting PIN. That setup may have helped the attackers limit access to people who received the correct code. It also made the download feel more exclusive and potentially more believable.
Once opened, Werkbit Setup contacted GitHub for an initial command. It then downloaded a script from the attackers' infrastructure. Next, the script installed a second disk image named CrashReporter.dmg in a hidden temporary folder. The payload used the name CrashReporter and the bundle identifier com.apple.crashreporter. Those details were chosen to resemble an Apple system component. The malware then launched quietly in the background.
Apple uses Gatekeeper alongside Developer ID signing to reduce the risk from downloaded software. Its notarization process checks an app for known malicious content when developers submit it. Gatekeeper can also check whether Apple has revoked the signing certificate. Still, a notarized label should never replace your judgment about where an app came from.
A harmful app can slip through before researchers or Apple identify its behavior. Attackers can also use a trusted first-stage installer to retrieve a different payload after launch. Jamf reported the Developer Team ID connected to Werkbit Setup to Apple after confirming that it had distributed malicious software. The report did not say how many people had been infected.
After CrashStealer launches, it displays a password prompt designed to resemble a legitimate macOS authorization request. The malware checks the password locally with a built-in Mac directory service command.
If the password is wrong, the prompt returns. If it is correct, CrashStealer stores an obfuscated copy and uses the credential to unlock the login Keychain.
The malware can then copy the Keychain database into its collection folder. That makes the prompt one of the most important warning signs. A password request can look convincing, yet the timing may feel wrong. An online meeting installer should not need your Mac password to display a call or download ordinary content.
CrashStealer searches broadly across the Mac. Jamf found code and activity tied to Chromium-based browsers, Safari data and Firefox credential files. The malware also checked wallet extensions such as MetaMask and Phantom. In addition, it targeted password managers that included 1Password, Bitwarden, LastPass and Dashlane. Jamf observed roughly 80 cryptocurrency wallet extensions and 14 password managers in the target list.
A separate file-search tool scans locations such as Documents and Downloads. However, it skips many large installers, apps and media files. That filtering suggests the thieves want compact files that may contain credentials or financial records. Other personal documents may also appeal to the attackers.
CrashStealer stores stolen material inside hidden folders under the user's home directory. It encrypts each collected item with AES-256-GCM. Then it packages groups of encrypted files into hidden ZIP archives before uploading them. Encryption helps the attackers conceal the contents of the stolen files while they sit on the Mac. It also means a leftover archive can confirm that collection occurred even when an investigator cannot read the data inside it.
The malware then copies itself into the Mac's Library cache folder. It creates a LaunchAgent that starts the copied app when the user logs in. The LaunchAgent uses an Apple-like name, which can make the entry blend in during a quick inspection.
HALLUSQUATTING AI ATTACK COULD HIJACK YOUR COMPUTER
You may have encountered this campaign after downloading Werkbit Setup. The risk rises if the website requires a meeting PIN. An unexpected CrashReporter password prompt is another red flag. Be more suspicious when the prompt appears right after installing unrelated software or joining an online meeting.
Also, watch for an unfamiliar app asking for Full Disk Access or permission to reach Documents and Downloads. CrashStealer's configuration included permission messages designed to make broad file access sound necessary for "system administration." Security teams can also look for the hidden CrashReporter locations and LaunchAgent described in Jamf's technical report. However, most home users should avoid digging through system folders unless they know exactly what they are changing.
A few careful habits can help you spot a suspicious Mac installer before it gets access to your passwords and personal files.
Use the Mac App Store when possible. Otherwise, type the developer's official website address yourself. Avoid downloading software from a meeting link, private message or unexpected pop-up unless you can independently confirm the source.
Be wary when an installer tells you to right-click and choose Open or use the Open Anyway button. Apple recommends overriding a security warning only when you trust the app's source. You should also confirm that nobody altered the download.
Look at which app triggered the prompt and why it needs authorization. Cancel the request when the reason does not match what you are doing. Then close the app and verify the download with the company through a separate channel.
Open the Apple menu > System Settings > Privacy & Security. Review Full Disk Access, Files & Folders and Accessibility for apps you do not recognize. Turn off access for anything suspicious.
Next, open System Settings > General > Login Items & Extensions. Review the apps listed under Open at Login and Allow in the Background. Remove or disable unfamiliar entries.
You can also check System Settings > General > Device Management for profiles you do not recognize. This option may appear only when a profile is installed. Do not remove a work or school profile without contacting the administrator first.
Open the Apple menu > System Settings > General > Software Update . Install available updates promptly because they include current security protections.
A trusted antivirus program can help detect known malicious files, suspicious persistence and harmful network behavior. Keep real-time protection enabled and allow the software to update automatically. Jamf says threat-prevention tools can help block and report similar Mac threats. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
Disconnect the Mac from the internet. Do not enter another password on that computer. Run a full scan with trusted security software. You should also contact Apple Support or your workplace IT team.
Next, use a clean device to change the password for your Apple Account, primary email account and password manager. Change passwords for banking, shopping and other sensitive accounts that were saved on the affected Mac. Enable two-factor authentication (2FA) where available and sign out of devices or active sessions you do not recognize.
After the Mac has been cleaned, change its login password because CrashStealer may have captured and validated that credential.
If you use cryptocurrency wallets on the affected Mac, treat their private keys and recovery phrases as exposed. Move remaining funds to newly created wallets from a clean device. Never reuse the old recovery phrase.
If security software cannot confirm that CrashStealer has been fully removed, contact Apple Support or a qualified technician about erasing the Mac and reinstalling macOS. Restore personal files carefully from a backup created before the infection, when possible.
FBI HELPS TAKE DOWN AI PHISHING RING
CrashStealer shows how attackers can wrap harmful software in a convincing Mac experience. The signed Werkbit installer gave the campaign a layer of credibility. Then the fake crash reporter used a familiar password prompt to reach valuable data on the computer. Your best defense begins before the password prompt appears. Verify the source of every installer and stop when the instructions ask you to bypass a warning. Strong antivirus protection and current macOS updates add another barrier.
Would Apple notarization earn your trust, or would you still question a polished Mac installer? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com - trusted by millions who watch CyberGuy on TV daily.
Plus, you'll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.