Threat actors are targeting popular password manager, KeePass, to spread malware and extract sensitive credentials. The attacks involve tampered download links and trojanized versions of KeePass which mimic legitimate software but executes malicious code in the background. Thousands of global users, particularly in financial services, healthcare, and government sectors, may already be compromised. The malware can harvest not just KeePass data, but also browser-based passwords, authentication cookies, and cryptocurrency wallet credentials.

IT Worker Accuses Feds Of Malware Trial Evidence ‘Ambush’
A former IT worker, accused of infecting his Ohio-based employer’s computer system with malware, is seeking a retrial, alleging that the prosecution withheld critical evidence.