Lenovo ID flaw let attackers access Dropbox accounts without passwords
Dropbox users are reporting unauthorized account access caused by a flaw in Lenovo’s email verification process that allowed attackers to create Lenovo IDs using victims’ email addresses and use them to sign in to associated Dropbox accounts. The number of affected users remains unknown, and neither Dropbox nor Lenovo has published a public advisory about … The post Lenovo ID flaw let attackers access Dropbox accounts without passwords appeared first on CyberInsider.
A vulnerability in Lenovo's email verification process allowed attackers to create a Lenovo ID using a victim's email address, granting unauthorized access to associated Dropbox accounts without passwords.
Read the full article
This is a curated summary. The complete article is available at Cyber Insider.
