Last week, it was revealed that several thousand Dropbox accounts were compromised between August 4 and 21. The breach was caused by a critical vulnerability in the Lenovo ID authentication system. A flaw on Lenovo's side allowed attackers to register accounts using arbitrary email addresses, which granted them access to existing Dropbox accounts linked to those same addresses. In response, Dropbox took immediate security measures, forcing a logout for all users who utilized Lenovo ID for authentication. Furthermore, the service implemented a mandatory requirement for users to enter a password directly for their Dropbox account, effectively disabling the vulnerable third-party login method. This incident highlights the significant risks associated with relying on unified identity systems for accessing critical cloud services.
This is a summary. Read the full article at the original source:
HabrRelated stories
Security researchers and tech reviewers from Gamers Nexus and Level1Techs have raised concerns regarding the privacy practices of LG televisions. Inve…
Microsoft has released its largest-ever patch bundle, addressing at least 974 security vulnerabilities across its Windows operating systems and softwa…
Microsoft's latest Patch Tuesday update has reached a staggering new record, addressing 974 Common Vulnerabilities and Exposures (CVEs). This massive…



