Lenovo ID flaw let attackers access Dropbox accounts without passwords
Brief
Dropbox users are reporting unauthorized account access caused by a flaw in Lenovo’s email verification process that allowed attackers to create Lenovo IDs using victims’ email addresses and use them to sign in to associated Dropbox accounts. The number of affected users remains unknown, and neither Dropbox nor Lenovo has published a public advisory about …
The post Lenovo ID flaw let attackers access Dropbox accounts without passwords appeared first on CyberInsider .
