🔓 Dropbox breached via Lenovo SSO gap
Between August 4–21, attackers accessed Dropbox accounts without passwords: they registered Lenovo IDs under victims' email addresses — Lenovo skipped email verification, and Dropbox never asked users to confirm the new login link. According to 9to5Mac, no files were accessed; all affected sessions have since been invalidated and the flaw patched.
Post #3599
2.01K

- ❤ 7
- 👍 1