Dashlane password manager users locked out by brute force attacks
2026-06-01T19:23:30Z•3ec04ef44cd76c7ebce4a6d0707814665f0ac6305bd590a200eb4a149bdd4ef1
active-exploitationauthentication-bypassbotnetchatgpt-abusecifswitchcommand-and-controldashlanedata-breachddos-as-a-serviceglobalprotectmalwaremfa-outagemicrosoftnetlogonphishingprivilege-escalationrcevpnwordpresswp-maps-pro
What happened
Multiple high-risk security events and active attacks reported: threat actors are actively exploiting a recently patched critical Windows Netlogon RCE, and Palo Alto GlobalProtect authentication-bypass (CVE-2026-0257) is being exploited in the wild. A new Linux local privilege-escalation bug dubbed “CIFSwitch” can yield root on multiple distributions. Nearly 2,000 WordPress sites were infected with malware that hides C2 payloads in Steam Community profile comments, and a vulnerable WP Maps Pro plugin is being exploited to create rogue admin accounts. Dashlane users experienced brute-force lock
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 3ec04ef44cd76c7ebce4a6d0707814665f0ac6305bd590a200eb4a149bdd4ef1
- Enrichment time
- 2026-06-01T19:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.