https://www.engadget.com/2017-08-08-nist-new-password-guidel...
For instance, if you have a padlock with 3 dials on it, I can just try 000 through 999 and at some point I will find the correct solution. A smarter attack could be to try and watch you close the padlock. A more efficient brute force attack could be to try popular combinations first (e.g. 000, 123, 987).
Your question is not very specific as it doesn't contain the context of the attack, are we talking about cracking a user's password? Usually a simple first mitigation for bruteforce attacks is to limit the user's attempts (e.g. if you get your password wrong 3 times, you are locked out for 10 minutes). Another good practice is to make sure people's passwords are at the very least 8 characters long, then trying every attempt becomes quite difficult just because of the amount of possibilities.
Tackle it? As what? A site owner? A pen-tester? A black hat? A criminal?
> how much dangerous it can be
Very dangerous for sites with poor practices. Near zero dangerous for those with good practices.
What's your experience with Penetration Testing and Security Auditing? Sounds like you're just starting out. It's a well established industry filled with knowledgeable and enthusiastic people happy to share their knowledge.
Best start with some archives of DefCon talks and go from there.