Attackers obtained encrypted password vaults from some Dashlane user accounts

2026-06-05T14:51:51Z718badb3280bdf6fe6df7f7956a87b62775db709f3e619c3869cf9150a7557e9
AI-misuseaccount-compromiseagentggai-agent-governanceanthropicbrute-forceciscodashlaneencrypted-vaultskeyless-car-theftlets-encryptmerkle-tree-certificatesmitre-attackopen-sourcepassword-managerpatch-tuesdaypost-quantumprivilege-escalationrelay-attacksastsd-wanvulnerability-managementzero-day

What happened

Collection of Help Net Security headlines (June 5, 2026): Dashlane disclosed a brute‑force attack that allowed a threat actor to access some customer accounts and copy encrypted password vaults (no evidence of internal system compromise). Let’s Encrypt announced work on Merkle Tree Certificates to add post‑quantum authentication at web scale (staging late‑2026, production target 2027). Cisco confirmed active exploitation of a Catalyst SD‑WAN privilege‑escalation 0‑day (CVE‑2026‑20245) with no patch available; exploitation requires netadmin privileges or chaining with CVE‑2026‑20182/CVE‑2026‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
718badb3280bdf6fe6df7f7956a87b62775db709f3e619c3869cf9150a7557e9
Enrichment time
2026-06-05T14:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Attackers obtained encrypted password vaults from some Dashlane user accounts · Baitaphish