I have a lot of Login-Attacks so the accounts are locked out very often. But the main problem is that this puts a lot of weight into the requests on my webserver.
So is it possible that TML supports wp_login_failed or another action to ban attacking IPs forever?