Someone just uploaded a password-hacking tool called iDict on GitHub. The tool promises to use all the good old brute force techniques to crack iCloud passwords. 
The tool's developers also claim they can bypass Apple's two-factor authentication restrictions, which are supposedly preventing brute force attacks.
iDict 's capabilities are limited by the size of the dictionary it uses to guess your passwords. It uses a list of 500 words but this can be changed by someone with the necessary knowledge. The passwords are in a txt file located in the path iDict-master\files\wordlist.txt
All of the passwords it uses meet the requirements for iCloud. So check the tool and if you see your password, change it immediately. You should also enable two-factor authentication on all of your accounts as an added security measure.
The tool and installation instructions are available on GitHub.
