ZeroHour

Search: “cloud compromise”

75 stories

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

Dropbox warned about 5,000 users that attackers abused a legacy Lenovo ID login integration to access accounts and files between August 4 and 21.

Attackers exploited an integration allowing Dropbox access via Lenovo IDs, registering Lenovo IDs with Dropbox users' email addresses due to a flaw in Lenovo's email verification process. The compromise lasted from August 4 to 21; attackers accessed files belonging to fewer than a third of the roughly 5,000 affected users, none of whom had 2FA enabled. Bitcoin security company Casa co-founder Jameson Lopp reported attackers attempted to access one locally encrypted file. Dropbox expired all Lenovo ID sessions, severed the integration link, and urged affected users to reset passwords and enable 2FA while Lenovo's investigation continues.

The Register · Security · 14d agoData breach in the wild

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

TechCrunch's 2026 roundup covers SSA data exposure, Iranian water-utility attacks, Klue breach hitting ~200 firms, and Meta AI chatbot account hijacks.

TechCrunch's mid-year roundup highlights a whistleblower claim that DOGE uploaded a live Social Security database copy to an unsecured third-party server, which House Democrats called potentially the largest US breach in history. CISA reported Iranian hackers targeted over 100 US water providers over the summer, while Russian-linked attacks hit Polish, Swedish, and Norwegian energy and water infrastructure. Market research firm Klue was breached via a stale 2022 pilot credential, exposing cloud keys of ~200 customers including Jamf, HackerOne, and LastPass to extortion gang Icarus. Separately, tens of thousands of Instagram accounts were hijacked by abusing Meta's AI chatbot to trigger password resets to attacker-controlled emails.

TechCrunch · Security · 1d agoData breach in the wild