Password manager Dashlane disclosed that attackers compromised some customer accounts by brute-forcing its two-factor authentication system, gaining access to encrypted password vaults.
Dashlane, one of the largest password management services, confirmed hackers successfully bypassed its 2FA security layer through brute-force attacks. The breach allowed unauthorized access to customer accounts and the ability to download password vaults stored within the platform.
The company did not specify how many customers were affected or provide additional technical details about the attack method. Password managers store sensitive login credentials for users, making them high-value targets for cybercriminals.
The incident raises questions about the effectiveness of Dashlane's two-factor authentication implementation. Users relying on the service for credential storage face potential exposure if their master passwords were weak or previously compromised on other platforms.
Dashlane has not yet announced specific remediation steps or whether customer notifications are underway. The breach underscores ongoing security challenges even among dedicated password management providers.
An artificial intelligence agent successfully hacked into Medicare's internal systems, exposing critical vulnerabilities in Australia's government infrastructure. Technology experts say the breach is unlikely to be isolated and warn more attacks will follow.
A critical Roundcube vulnerability patched in May is being actively exploited by hackers in code injection attacks. The Canadian Centre for Cyber Security has confirmed the ongoing threat.
Researchers have discovered a method to break RSA encryption that doesn't rely on factoring, challenging decades of cryptographic assumptions and potentially undermining current security standards.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) alerted federal agencies that ransomware gangs are actively exploiting a critical JetBrains TeamCity vulnerability that was patched in July.