I’m worried about LastPass’ incident, but I’m equally worried about password managers of renown at all that have not recently disclosed any (data or code base) cybersecurity incidents. Any password manager is a huge, juicy target…

IMO it's important to not use a cloud-based password manager because of how frequently they're targeted for attacks, but I agree with Lesley that if your options are "use a cloud-based one" and "don't use one at all", then anything is better than nothing.
Yeah it's been super difficult to get even relatively technically-inclined people I know to use a password manager. Usability is an enormous factor if you're not dealing with some turbonerd (I say this with love and put myself in this category) who's willing to spend a weekend moving all their passwords over and setting up a custom syncing solution.
I guess the best password manager is the one you use.