Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded
2026-06-02T07:24:07Z•8f9cc686ee139d7e2444a26d9abcd0e57979ae07fa4090c407e7a0b2600247c1
2fa-bypassactive-exploitationbotnet-takedownbrute-forcecredential-theftdashlaneespionageforticlient-emsgogsmalicious-packagemarimonpmnugetpan-osphishingrcesupply-chainvpn-auth-bypasswordpressworm
What happened
A wave of high-impact incidents and active exploit campaigns was reported, centered on supply-chain compromise, credential theft, and active exploitation of enterprise infrastructure. Key items include Dashlane disclosing a brute-force attack that resulted in encrypted vault downloads for fewer than 20 personal users (attacker attempting 2FA bypass); the Miasma supply-chain campaign (a Mini Shai‑Hulud variant) compromising @redhat-cloud-services npm packages to deploy a credential‑stealing, self‑propagating worm; malicious npm/nuget packages stealing OpenAI/Claude tokens and other secrets (cod
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 8f9cc686ee139d7e2444a26d9abcd0e57979ae07fa4090c407e7a0b2600247c1
- Enrichment time
- 2026-06-02T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.