Dashlane confirms limited vault access following brute-force attack
An unknown threat actor attempted to bypass two-factor authentication and add new devices to existing user accounts.
2 min read
Cybersecurity Help is a global vulnerability intelligence provider. We monitor vulnerabilities in software from 60,000+ vendors and help customers prevent potential data breaches by addressing them proactively.
Request DemoAn unknown threat actor attempted to bypass two-factor authentication and add new devices to existing user accounts.
2 min readThe campaign begins with weaponized xHTML files that deliver a malicious RAR archive exploiting a WinRAR vulnerability (CVE-2025-8088).
3 min readThe attack is designed to steal developer credentials and CI/CD secrets during package installation.
4 min readThe campaign mainly targets organizations in government, research, education, technology, and financial services.
2 min readThe Marimo flaw was exploited for the initial compromise and AWS credential theft.
3 min read