Skip to content
The Nexus
SECURITYJun 4 · 20:02 UTCARS TECHNICADan Goodin

Dashlane explains how attackers managed to download encrypted password vaults

Dashlane reported that attackers used a brute force attack on its device enrollment API to download encrypted password vaults from fewer than 20 users before automated security systems locked out the accounts. The attack involved generating valid tokens to register new devices on targeted accounts.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this