{"id":98027,"date":"2026-06-06T07:00:00","date_gmt":"2026-06-06T04:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=98027"},"modified":"2026-06-06T09:05:58","modified_gmt":"2026-06-06T06:05:58","slug":"dashlane-users-hit-by-breach-trezor-safe-7-chip-flaw-found-and-more-cybersecurity-news","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/dashlane-users-hit-by-breach-trezor-safe-7-chip-flaw-found-and-more-cybersecurity-news\/","title":{"rendered":"Dashlane Users Hit by Breach, Trezor Safe 7 Chip Flaw Found, and More Cybersecurity News"},"content":{"rendered":"<p>We\u2019ve compiled the week\u2019s most important cybersecurity news.<\/p>\n<ul class=\"wp-block-list\">\n<li>Hackers breached users of the Dashlane password manager.<\/li>\n<li>A flaw was found in the Trezor Safe 7 wallet\u2019s security chip.<\/li>\n<li>China-linked hackers targeted Europe.<\/li>\n<li>Fraudsters convinced Meta\u2019s AI support to reassign rare Instagram accounts.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">Hackers breached Dashlane password manager users<\/h2>\n<p>Attackers bypassed two-factor authentication (2FA) and downloaded encrypted vaults containing user credentials from Dashlane accounts, the password manager\u2019s developer <a href=\"https:\/\/support.dashlane.com\/hc\/en-us\/articles\/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts?7194ef805fa2d04b0f7e8c9521f97343\">said<\/a>.<\/p>\n<p>The campaign <a href=\"https:\/\/status.dashlane.com\/pages\/incident\/5aabcb89fccc4b04d3774443\/6a1c519ceac9dc05ffa1f526\">began<\/a> on May 31, 2026, and targeted <span data-descr=\"application programming interface\" class=\"old_tooltip\">API<\/span> endpoints for new device registration. The hackers brute-forced six-digit one-time codes sent to victims via email or generated by authenticator apps.<\/p>\n<p>Although Dashlane\u2019s automated security systems flagged the anomaly and began temporarily locking targeted accounts, the attackers managed to guess valid codes for a small number of victims. After passing 2FA, they authorized their own devices on user profiles, triggering the app to automatically download full copies of the encrypted vaults.<\/p>\n<p>The company said \u201cfewer than 20 users\u201d were affected. Dashlane\u2019s internal infrastructure and servers were not compromised. The company implemented additional verification layers and blocking of suspicious traffic.<\/p>\n<p>Experts emphasized that the stolen password databases remain inaccessible without the victim\u2019s master password. Thanks to <a href=\"https:\/\/forklog.com\/en\/news\/what-is-a-zero-knowledge-proof\">ZKP<\/a> architecture and strong encryption, the data are protected from quick cracking.<\/p>\n<p>Because the vaults now physically reside on the attackers\u2019 servers, they can use unlimited computing power for local cracking. The situation largely mirrors the <a href=\"https:\/\/forklog.com\/en\/news\/lastpass-breach-victims-lose-4-4m-in-a-day\">incident<\/a> with LastPass in 2022.<\/p>\n<h2 class=\"wp-block-heading\">Flaw found in Trezor Safe 7 wallet\u2019s security chip<\/h2>\n<p>Security chip developer Tropic Square <a href=\"https:\/\/tropicsquare.com\/blogs\/potential-bypass-of-firmware-verification-by-laser-fault-injection\">disclosed<\/a> a vulnerability in its TROPIC01 product, used in the Trezor Safe 7 hardware crypto wallet.<\/p>\n<p>The issue was discovered by Ledger Donjon\u2019s security research team during an independent audit. The specialists executed a successful <span data-descr=\"a hardware attack method in which a focused laser beam affects the chip die and induces faults in its operation\" class=\"old_tooltip\">Laser Fault Injection<\/span> attack. In lab conditions, the method allowed them to bypass firmware signature verification and extract some secret data protected by the chip.<\/p>\n<p>Based on Donjon\u2019s report, Tropic Square identified a complex exploitation method to extract another secret. It affects TROPIC01 functions related to the PIN code.\u00a0<\/p>\n<p>As Trezor representatives explained in an email to ForkLog, even with the additional finding, compromising the chip alone is insufficient to access the Trezor Safe 7 PIN. Moreover, users\u2019 private keys and seed phrases are not stored on TROPIC01. To execute the exploit, an attacker would need full physical access to the victim\u2019s wallet, expensive specialized equipment and expert knowledge.<\/p>\n<p>Trezor said users do not need to take any action, as the wallet\u2019s design fully mitigates the risk in practice.<\/p>\n<h2 class=\"wp-block-heading\">China-linked hackers target Europe<\/h2>\n<p>Since March 2026, the pace of attacks by the China-linked group TA4922 has reached unprecedented levels, with the geography expanding to include organizations in Europe, according to <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/ta4922-suspected-chinese-crime-group-going-global\">Proofpoint<\/a>.<\/p>\n<p>The group had previously focused solely on East Asia, but recent campaigns shifted to commercial and government organizations in Germany, Italy, the UK and South Africa.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/img-85820a4f316615f4-6290268700650645.webp\" alt=\"image\" class=\"wp-image-281134\"\/><figcaption class=\"wp-element-caption\">Number of TA4922 attacks by country. Source: Proofpoint.<\/figcaption><\/figure>\n<p>For initial compromise, the hackers use high-quality localized phishing lures mimicking payroll notifications, tax audits, VAT returns and HR messages. In addition to email, they reach out via WhatsApp, LINE and Microsoft Teams.<\/p>\n<p>In recent attacks they deployed a previously unknown remote-access trojan, Atlas. The backdoor supports a wide range of espionage features:<\/p>\n<ul class=\"wp-block-list\">\n<li>full system reconnaissance and fingerprinting;<\/li>\n<li>targeted file exfiltration;<\/li>\n<li>keylogging and screenshot capture;<\/li>\n<li>audio and video recording via the victim\u2019s peripherals;<\/li>\n<li>remote power control of the system.<\/li>\n<\/ul>\n<p>Atlas also includes sandbox-evasion mechanisms: it checks registry keys and usernames for signs of Microsoft Defender Application Guard and the CExecSvc service.<\/p>\n<p>The group\u2019s toolkit further includes a new loader, RomulusLoader, to stealthily launch remote administration tools such as AnyDesk and China-popular SyncFuture. Researchers also observed a Python installer, SilentRunLoader, aimed at stealing Google Chrome session cookies and passwords.<\/p>\n<p>Proofpoint believes TA4922 leverages large language models (LLMs) to accelerate development, citing an abundance of specific comments and structural patterns in the code characteristic of AI.<\/p>\n<h2 class=\"wp-block-heading\">Scammers exploited Meta\u2019s AI support to seize rare Instagram accounts<\/h2>\n<p>Some Instagram users lost access to their pages due to a critical vulnerability in the architecture of Meta\u2019s AI support, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/instagram-users-locked-out-after-meta-ai-abused-to-steal-accounts\/\">BleepingComputer<\/a> reports.<\/p>\n<p>Attackers industrialized the bypass of platform safeguards, including two-factor authentication (2FA), by manipulating the AI assistant.<\/p>\n<p>An attacker initiated the standard password-recovery protocol, claiming the page had been hacked. When Instagram\u2019s automated system requested video identity verification, the hackers used a deepfake produced after obtaining images of the victim.<\/p>\n<p>According to media reports, the attackers also enabled a VPN to mimic the victim\u2019s usual geolocation, helping them bypass server-side security checks. The attacker then forced a change of the account\u2019s linked email and reset the password.<\/p>\n<p>Compromised accounts included unique short handles like @hey, @korn, @e and @f, as well as app researcher Jane Manchun Wong\u2019s profile and a page previously used by the White House team during the Obama administration. Such rare digital assets can fetch tens of thousands of dollars on the black market.\u00a0<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">my instagram (@ korn) was stolen overnight via the Meta AI exploit and was subsequently disabled.<\/p>\n<p>it was Meta Verified, facial scan verified, and had 0 TOS violations.<\/p>\n<p>the account is the sole source of my income.<\/p>\n<p>i spent 6 hours trying to get human support and meta&#8217;s support\u2026 <a href=\"https:\/\/t.co\/k5x846H8AG\">pic.twitter.com\/k5x846H8AG<\/a><\/p>\n<p>\u2014 korn (@kornbuilds) <a href=\"https:\/\/x.com\/kornbuilds\/status\/2061508020715053381?ref_src=twsrc%5Etfw\">June 1, 2026<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.x.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Victims complained they could not regain access due to a lack of human support. The owner of @korn said he spent more than six hours talking to a chatbot that sent him four non-working links in a row.<\/p>\n<p>Meta\u2019s VP of communications Andy Stone <a href=\"https:\/\/x.com\/wongmjane\/status\/2061680602018140419\">said<\/a> that \u201cthe issue has been resolved and the security of affected accounts ensured,\u201d without elaborating.<\/p>\n<h2 class=\"wp-block-heading\">Minecraft infostealer infected 116,000 users<\/h2>\n<p>McAfee <a href=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/weedhack-minecraft-malware-as-a-service-campaign-research\/\">identified<\/a> a large WeedHack campaign that affected more than 116,000 Minecraft users.<\/p>\n<p>Researchers say the malware spreads via trojanized mods and clients promoted through SEO poisoning in search queries and on YouTube.<\/p>\n<p>WeedHack operates as <a href=\"https:\/\/forklog.com\/en\/news\/a-subscription-to-crime-how-rented-hacking-software-imperils-web3\">CaaS<\/a> and, in its free base version, steals Minecraft session IDs, browser passwords, crypto wallet data, and Telegram and Discord accounts. A premium version at $5 per month provides full remote access to the victim\u2019s PC.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/img-414eee785ee80fd5-6290269771618234.webp\" alt=\"image\" class=\"wp-image-281135\"\/><figcaption class=\"wp-element-caption\">WeedHack malware site. Source: McAfee.<\/figcaption><\/figure>\n<p>In addition, according to <a href=\"https:\/\/haveibeenpwned.com\/Breach\/AtlasMenu\">Have I Been Pwned<\/a>, data on 64,000 users of the Atlas Menu cheat service for Grand Theft Auto V leaked online in late May. Stolen information includes email addresses, logins, passwords and IP addresses. The hacker posted the database on GitHub.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>Researchers <a href=\"https:\/\/forklog.com\/en\/news\/researchers-develop-adaptive-ai-worm\">created<\/a> an adaptive AI worm.<\/li>\n<li>Aave <a href=\"https:\/\/forklog.com\/en\/news\/aave-tightens-listing-standards-following-293-million-rseth-incident\">tightened listings<\/a> after the $293 million rsETH incident.<\/li>\n<li>A white-hat hacker <a href=\"https:\/\/forklog.com\/en\/news\/white-hat-hacker-unlocks-2-million-in-2016-smart-contract\">unlocked<\/a> $2 million in a 2016 smart contract.<\/li>\n<li>The FBI <a href=\"https:\/\/forklog.com\/en\/news\/fbi-uncovers-scam-network-seizes-8-billion-in-bitcoin\">uncovered<\/a> a network of scam centers and seized $8 billion in bitcoin.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">What to read this weekend?<\/h2>\n<p>At ForkLog\u2019s request, Roman Korolev, author of the Telegram channel \u201c<a href=\"https:\/\/t.me\/empire_dekadanz\">Dark Culturology<\/a>,\u201d examines how the apocalyptic prophets of a \u201cdigital concentration camp\u201d went from the margins to the mainstream.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We\u2019ve compiled the week\u2019s most important cybersecurity news.<\/p>\n","protected":false},"author":1,"featured_media":98028,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"Dashlane breach, Trezor chip flaw, China-linked attacks, Instagram AI exploit.","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-98027","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"14","promo_type":"1","layout_type":"1","short_excerpt":"Dashlane breach, Trezor chip flaw, China-linked attacks, Instagram AI exploit.","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/98027","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=98027"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/98027\/revisions"}],"predecessor-version":[{"id":98029,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/98027\/revisions\/98029"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/98028"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=98027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=98027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=98027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}