Technologies
Back
Cybersecurity & Privacy

Security Week 2637: Dropbox hack via Lenovo ID

Habr
Advertisement468 × 90
Security Week 2637: Dropbox hack via Lenovo ID

Last week, it was revealed that several thousand Dropbox accounts were compromised between August 4 and 21. The breach was caused by a critical vulnerability in the Lenovo ID authentication system. A flaw on Lenovo's side allowed attackers to register accounts using arbitrary email addresses, which granted them access to existing Dropbox accounts linked to those same addresses. In response, Dropbox took immediate security measures, forcing a logout for all users who utilized Lenovo ID for authentication. Furthermore, the service implemented a mandatory requirement for users to enter a password directly for their Dropbox account, effectively disabling the vulnerable third-party login method. This incident highlights the significant risks associated with relying on unified identity systems for accessing critical cloud services.

This is a summary. Read the full article at the original source:

Habr
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250