LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
cloud

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

Cloud storage biz severs old integration and urges victims to reset credentials

zeroday.news ·

Dropbox has confirmed that approximately 5,000 user accounts were compromised due to an exploit involving a legacy login integration with Lenovo. The cloud storage provider stated that attackers leveraged an issue within Lenovo's email verification process to gain unauthorized access to these accounts.

According to Dropbox, the vulnerability allowed attackers to register Lenovo IDs using the email addresses of existing Dropbox users. This then granted them access to the corresponding Dropbox storage accounts without requiring a separate Dropbox password. The company did not elaborate on why this integration bypassed the need for a Dropbox password.

The compromise period spanned from August 4 to August 21. Dropbox indicated that files belonging to fewer than one-third of the affected users were accessed during this time. One affected user, Jameson Lopp, co-founder of Casa, reported that attackers attempted to access a single file named "IMPORTANT.rtf" from his account, which had been locally encrypted prior to being uploaded to Dropbox.

Dropbox confirmed that none of the compromised accounts had two-factor authentication (2FA) enabled. Following the discovery of the breach, Dropbox immediately terminated all active sessions logged in via Lenovo IDs and completely severed the integration link between the affected accounts and Lenovo.

Affected users received an email from Dropbox advising them to change their Dropbox passwords, update their personal email passwords, and activate 2FA on their accounts.

Lenovo has stated that its own customers were not affected by this incident and that its investigation into the matter is ongoing.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

vulnerability

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

ransomware

Ransomware protection for MSPs: A 6-point checklist for faster recovery

Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]

ai

Your AI chats could be used in court

What you tell an AI chatbot could come back to haunt you in court. The Washington Post found chat histories already used in 12 legal cases.

vulnerability

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and