#2FA Vulnerability

Every story tagged 2FA Vulnerability, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

3 stories · open in the command center

  • Security & PrivacyVulners1m

    CVE-2026-67337: better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is e... (CVSS 7.1)

    CVE-2026-67337 is a critical authentication bypass vulnerability in better-auth versions below 1.4.9 that allows attackers with valid primary credentials to bypass two-factor authentication when session.cookieCache is enabled, exposing sensitive authenticated routes to unauthorized access. This CVSS 7.1 vulnerability represents a significant security risk for any organization using affected versions, particularly those relying on 2FA for compliance and data protection. IT organizations must immediately assess their dependency inventory and remediation timeline to prevent account compromise and potential data breaches.

  • Security & PrivacyArs TechnicaDan Goodin2m

    Dashlane issues opaque advisory warning 20 encrypted vaults were stolen

    Password manager Dashlane disclosed that attackers obtained 20 encrypted user vaults through a brute-force attack on two-factor authentication, though the company's opaque advisory lacks critical technical details about attack methodology and initial compromise vector, leaving significant questions about the actual security controls and response transparency. The incident highlights risks in relying on third-party credential management solutions and exposes concerning gaps in Dashlane's communication with customers and security community—potentially damaging user trust and raising questions about incident response maturity. For IT organizations, this underscores the importance of vendor security posture evaluation, contractual incident disclosure requirements, and the need for defense-in-depth authentication strategies beyond password managers alone.

  • Security & PrivacyTechCrunchZack Whittaker2m

    Password manager Dashlane says hackers stole some customers’ password vaults

    Dashlane disclosed a breach affecting approximately 20 customers whose encrypted password vaults were stolen after attackers successfully brute-forced the company's two-factor authentication system, highlighting a critical vulnerability in a foundational security tool. While the stolen vaults remain encrypted and require knowledge of individual master passwords to access, this incident underscores the catastrophic business and security implications when password manager infrastructure is compromised, potentially exposing organizations to cascading credential theft similar to the 2022 LastPass breach. IT leaders must urgently reassess their password management security posture and evaluate the risk profile of their chosen solutions, as breaches of these centralized credential repositories can compromise entire enterprise security architectures.

Browse all tags