Today’s Menu (30-second skim)
- Fake job interviews are being used to infect applicants’ computers: Scammers posing as recruiters sent fake interview files that could steal passwords, ID documents, crypto-wallet data, and other private files.
- A fake LastPass Authenticator download tried to steal people’s saved passwords: Fake download pages copied a trusted security brand to trick people into installing password-stealing malware.
- Fake Cloudflare checks on hacked websites pushed password-stealing malware: Hacked websites showed fake verification screens that told visitors to run a Windows command that installed malware.
1) Fake job interviews are being used to infect applicants’ computers

What happened (plain English): Security agencies warned about a North Korea-linked scam campaign called Contagious Interview, also known as WaterPlum. The attackers pretended to be recruiters and contacted people looking for jobs. They sent fake coding tests, interview files, or project instructions that looked like normal hiring steps. But opening or running those files could install malware on the person’s computer. That malware was designed to steal passwords, crypto-wallet information, ID documents, and other private files. The campaign has reportedly infected at least 30,000 devices in more than 100 countries.
Why it matters to you: A job search already makes people feel rushed, hopeful, and a little nervous, which is exactly what scammers want. A fake recruiter could send you a “skills test” that secretly steals your saved passwords while you think you are applying for work. If your ID photo or tax document is on that computer, the scammer could use it later to impersonate you or try bank fraud. If you use the same device for work, the malware could also put your employer’s accounts at risk.
How to protect yourself (do this):
- Be suspicious if a recruiter asks you to download software, run code, or install a browser extension before you have verified the company.
- Use a separate test computer or protected virtual environment for take-home coding projects when possible.
- Search for the recruiter, company domain, and job posting outside the message thread before opening files.
- If you already opened a suspicious interview file, change important passwords from a different clean device.
Published: 2026-09-21
Source: The Hacker News
2) A fake LastPass Authenticator download tried to steal people’s saved passwords

What happened (plain English): LastPass and Delphos Labs found fake GitHub pages pretending to offer LastPass Authenticator. People searching online for the app could land on the fake page instead of the real download source. The fake installer used a powerful Windows driver to shut down security tools before running a password-stealing program. This kind of program can look for saved browser passwords, wallet files, and active app sessions. LastPass said its own systems and customer vaults were not breached. The scammers were abusing the LastPass name to make the fake download look trustworthy.
Why it matters to you: This scam is extra frustrating because it targets people who are trying to be safer. Someone might think, “I’m installing an authenticator app to protect my accounts,” but the fake installer could steal the very passwords they want to protect. A scammer could then try to log in to email, banking, shopping, or social accounts. If you have crypto-wallet files or saved payment sessions on the same computer, those could also be at risk.
How to protect yourself (do this):
- Download authenticator apps only from the official app store or the company’s official website.
- Do not trust a GitHub page just because it uses a familiar logo or shows up high in search results.
- If you ran the fake installer, change passwords from another device and review account activity.
- Avoid saving your most important passwords only in the browser; use a trusted password manager with strong account protection.
Published: 2026-09-17
Source: LastPass
3) Fake Cloudflare checks on hacked websites pushed password-stealing malware

What happened (plain English): Researchers found hacked business websites showing fake Cloudflare verification screens. These screens looked like the familiar “prove you are human” checks people see online. But instead of only asking visitors to click a box, the fake page told them to copy and run a Windows command. That command installed malware called Psychedelic Stealer. The malware was built to steal browser passwords, account tokens, cryptocurrency-wallet data, and information about the computer. The scary part is that the visitor could be on a real website, but the website had been quietly hacked.
Why it matters to you: Most people have learned to trust common verification screens, so scammers are copying that look. A fake page might tell you that you must paste a command to continue reading an article, downloading a file, or opening a business page. If you follow those instructions, you could install malware yourself without realizing it. That malware could then steal logins for email, banking, work tools, or social media.
How to protect yourself (do this):
- Never paste a command into Windows Run, Terminal, or PowerShell because a website tells you to.
- Real verification pages may ask you to click a box, but they should not ask you to run computer commands.
- Close the page if a website suddenly gives unusual computer instructions.
- If you pasted a command, disconnect from the internet and get help before logging into important accounts again.
Published: 2026-09-24
Source: The Hacker News
Grandma’s Firewall

This week’s simple rule:
If a website, recruiter, or download page asks you to install something or paste a command to continue, stop. Real help does not need you to secretly run computer instructions.
Two scripts you can steal:
- I’m not going to run commands from a website. Send me the official company page and I’ll check it myself.
- I only install apps from the official app store or the company’s real website. I’m closing this page.
