View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Hackers accessed about 5,000 Dropbox accounts through Lenovo ID flaw

πŸ’₯ BREACHES & INCIDENTS

  • Hackers accessed about 5,000 Dropbox accounts through Lenovo ID flaw
    Hackers accessed about 5,000 Dropbox accounts through a Lenovo ID verification flaw.
    • Dropbox users with Lenovo-linked accounts and no Dropbox two-factor authentication were affected.
    • About 5,000 accounts were accessed between August 4 and August 21, 2026; fewer than one-third had files viewed or downloaded.
    • Attackers registered Lenovo IDs using victims’ email addresses without controlling their inboxes.
    • Dropbox accepted matching Lenovo SSO email claims and issued sessions without requiring a password or additional verification.
      πŸ“Ž Coverage: 9to5mac.com Β· πŸ‘ via @metacurity@infosec.exchange (+1)

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Phishing actors abuse Faronics Deploy to install ScreenConnect
    Phishing actors used Faronics Deploy to install ScreenConnect on victim endpoints.
    • Organizations using Faronics Deploy were targeted between July 21 and August 20, reaching more than 457 endpoints.
    • Attackers enrolled victim computers in attacker-controlled Faronics deployments and installed ConnectWise ScreenConnect for persistent remote access.
    • Invoice, tax-document, and business-file phishing lures directed victims to malicious download pages.
    • Victims were tricked into running a signed Faronics installer, often named β€œAdobe.exe,” disguised as an Adobe document, reader, or plugin update.
    • Faronics’ remote deployment then executed PowerShell scripts that used curl, mshta, or msiexec to download payloads and install ScreenConnect.
      πŸ“„ Source: huntress.com Β· πŸ“Ž Coverage: bleepingcomputer.com Β· πŸ‘ via BleepingComputer

πŸ“‹ ADVISORIES

  • FBI warns of OAuth consent phishing targeting high-profile users
    The FBI warned that OAuth consent phishing is giving attackers persistent access to victims’ accounts.
    • High-profile people, family members and acquaintances are being targeted through a commercial messaging application.
    • Microsoft and Google cloud accounts are being accessed, including email, files and other sensitive data.
    • Attackers impersonate government officials, journalists or public figures and lure victims with document-review or identity-verification requests.
    • Victims approve malicious OAuth applications through legitimate provider pages, granting access without revealing passwords.
    • OAuth tokens can preserve access after password changes and bypass multi-factor authentication.
      πŸ“„ Source: ic3.gov Β· πŸ“Ž Coverage: cyberscoop.com Β· πŸ‘ via CyberScoop

πŸ”“ CVEs & KEV

  • CVE-2026-73782 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 8.8 β€” Unauthenticated Format String Vulnerability leads to Remote Code Execution in...

  • CVE-2026-71981 β€” cypht-org cypht β€” CVSS 8.7 β€” Cypht before 2.12.2 PHP Object Injection RCE via back_query ParameterCypht before ...

  • CVE-2026-73781 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 8.4 β€” Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-B...

  • CVE-2026-73780 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 8.3 β€” Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authent...

  • CVE-2026-84370 β€” svg svgo β€” CVSS 8.2 β€” SVGO: removeScripts allows executable links through namespace and control-cha...

  • CVE-2026-73779 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 8.2 β€” Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unau...

  • CVE-2026-73778 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 8.1 β€” Credential Manager Vulnerability Allows Unauthorized Administrative AccessA v...

  • CVE-2026-73777 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 8.1 β€” Authorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-C...

  • CVE-2026-73776 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 7.9 β€” Authenticated Signature Verification Bypass Leading to Arbitrary Code Executi...

  • CVE-2026-73775 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 7.7 β€” Authenticated Sensitive Information Disclosure Vulnerabilities in AOS-CXVulne...

  • CVE-2026-73774 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 7.6 β€” Unauthenticated Buffer Overflow Vulnerability leads to Sensitive Information ...

  • CVE-2026-73773 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 7.5 β€” Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CXAn unauthentic...

  • CVE-2026-73772 β€” Hewlett Packard Enterprise (HPE) AOS-CX β€” CVSS 6.5 β€” Unauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in ...

  • CVE-2026-84369 β€” svg svgo β€” CVSS 6.1 β€” SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObje...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check