DEV Community

Cover image for Dropbox Accounts Breached via Lenovo Identity Provider SSO Flaw
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Dropbox Accounts Breached via Lenovo Identity Provider SSO Flaw

Summary

Dropbox confirmed that attackers accessed approximately 5,000 accounts by exploiting a flaw in Lenovo's email verification process to bypass authentication. The breach allowed unauthorized parties to view and download user files by linking fraudulent Lenovo IDs to existing Dropbox accounts.

Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)