Find notable cyber news and cases, enriched with sources, timelines, and signals.

Lenovo ID email verification account-takeover security flaw

Vulnerability
First reported
Last updated
Happening score
H score 51
1 unique sources, 1 articles

Summary

Hide ▲

A Lenovo ID email verification flaw let attackers register a Lenovo ID using a victim's email address and log into linked Dropbox accounts without the password. The weakness affected Dropbox users who relied on Lenovo Identity Provider Services for authentication, with accesses occurring between August 4 and 21. Dropbox and Lenovo mitigated the risk, and Dropbox now expires Lenovo-authenticated sessions and requires the Dropbox password for Lenovo ID authentication.

Related Happenings

Dropbox hit by cyberattack

Incident
H score17 First: 02.09.2026 15:30 Last: 02.09.2026 15:30 Sources 1

How related: The attacker then used the fraudulent Lenovo ID to access the Dropbox account registered under the same email address without needing the login password.

About this happening: Dropbox confirmed an unauthorized account access incident that let an attacker log into affected users’ accounts without the password, creating takeover risk. The access p...

ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations

Campaign
H score34 First: 29.07.2026 20:54 Last: 29.07.2026 20:54 Sources 1

About this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...

KDDI Corporation hit by network compromise

Incident
H score92 First: 24.06.2026 15:45 Last: 24.06.2026 15:45 Sources 1

About this happening: KDDI Corporation confirmed an email-system breach that exposed customer credentials across six Japanese ISPs, putting account access at risk. The intrusion was detecte...

Latest development: 08.07.2026 14:24

Attackers breached the KDDI email platform used by five Japanese ISPs on May 16 after exploiting a zero-day vulnerability in third-party software, exposing email addresses and passwords across the affected service providers.

Meta AI-powered support tools abused in Instagram account recovery flow

Security Tool/Service
H score26 First: 02.06.2026 18:47 Last: 02.06.2026 18:47 Sources 1

About this happening: Instagram accounts were hijacked after attackers abused Meta’s AI-powered support tools to pass recovery checks and change the recovery email, creating a direct failure in...

Phishing-resistant authentication to block post-breach credential abuse and relay attacks

Defensive Guidance
H score41 First: 09.04.2026 17:02 Last: 09.04.2026 17:02 Sources 1

About this happening: Phishing-resistant authentication is being emphasized as the control that can stop post-breach account takeover when exposed email records fuel credential stuffing, AiTM...

Timeline

  1. 02.09.2026 15:30 2 articles · 1h ago

    Fraudulent Lenovo IDs let attackers access Dropbox accounts

    Initial Disclosure

    Dropbox warned some users that an unauthorized party exploited an issue in Lenovo's email verification process to register fraudulent Lenovo IDs and then log into Dropbox accounts tied to the same email address without the Dropbox password. Dropbox said its authentication stack used Lenovo Identity Provider Services, and Lenovo said the issue involved a legacy integration between Lenovo ID and Dropbox that could improperly authenticate certain Dropbox accounts. Some users saw suspicious Dropbox sign-in notifications about two weeks earlier and changed their password and enabled two-factor authentication, while Dropbox and Lenovo mitigated the risk by expiring Lenovo-authenticated sessions and requiring the Dropbox password for Lenovo ID authentication.

    Show sources