π₯ BREACHES & INCIDENTS
- Hackers accessed about 5,000 Dropbox accounts through Lenovo ID flaw
Hackers accessed about 5,000 Dropbox accounts through a Lenovo ID verification flaw.- Dropbox users with Lenovo-linked accounts and no Dropbox two-factor authentication were affected.
- About 5,000 accounts were accessed between August 4 and August 21, 2026; fewer than one-third had files viewed or downloaded.
- Attackers registered Lenovo IDs using victimsβ email addresses without controlling their inboxes.
- Dropbox accepted matching Lenovo SSO email claims and issued sessions without requiring a password or additional verification.
π Coverage: 9to5mac.com Β· π via @metacurity@infosec.exchange (+1)
π΅οΈ RESEARCH & DEEP DIVES
- Phishing actors abuse Faronics Deploy to install ScreenConnect
Phishing actors used Faronics Deploy to install ScreenConnect on victim endpoints.- Organizations using Faronics Deploy were targeted between July 21 and August 20, reaching more than 457 endpoints.
- Attackers enrolled victim computers in attacker-controlled Faronics deployments and installed ConnectWise ScreenConnect for persistent remote access.
- Invoice, tax-document, and business-file phishing lures directed victims to malicious download pages.
- Victims were tricked into running a signed Faronics installer, often named βAdobe.exe,β disguised as an Adobe document, reader, or plugin update.
- Faronicsβ remote deployment then executed PowerShell scripts that used curl, mshta, or msiexec to download payloads and install ScreenConnect.
π Source: huntress.com Β· π Coverage: bleepingcomputer.com Β· π via BleepingComputer
π ADVISORIES
- FBI warns of OAuth consent phishing targeting high-profile users
The FBI warned that OAuth consent phishing is giving attackers persistent access to victimsβ accounts.- High-profile people, family members and acquaintances are being targeted through a commercial messaging application.
- Microsoft and Google cloud accounts are being accessed, including email, files and other sensitive data.
- Attackers impersonate government officials, journalists or public figures and lure victims with document-review or identity-verification requests.
- Victims approve malicious OAuth applications through legitimate provider pages, granting access without revealing passwords.
- OAuth tokens can preserve access after password changes and bypass multi-factor authentication.
π Source: ic3.gov Β· π Coverage: cyberscoop.com Β· π via CyberScoop
π CVEs & KEV
-
CVE-2026-73782 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 8.8 β Unauthenticated Format String Vulnerability leads to Remote Code Execution in...
-
CVE-2026-71981 β cypht-org cypht β CVSS 8.7 β Cypht before 2.12.2 PHP Object Injection RCE via back_query ParameterCypht before ...
-
CVE-2026-73781 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 8.4 β Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-B...
-
CVE-2026-73780 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 8.3 β Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authent...
-
CVE-2026-84370 β svg svgo β CVSS 8.2 β SVGO: removeScripts allows executable links through namespace and control-cha...
-
CVE-2026-73779 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 8.2 β Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unau...
-
CVE-2026-73778 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 8.1 β Credential Manager Vulnerability Allows Unauthorized Administrative AccessA v...
-
CVE-2026-73777 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 8.1 β Authorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-C...
-
CVE-2026-73776 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 7.9 β Authenticated Signature Verification Bypass Leading to Arbitrary Code Executi...
-
CVE-2026-73775 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 7.7 β Authenticated Sensitive Information Disclosure Vulnerabilities in AOS-CXVulne...
-
CVE-2026-73774 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 7.6 β Unauthenticated Buffer Overflow Vulnerability leads to Sensitive Information ...
-
CVE-2026-73773 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 7.5 β Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CXAn unauthentic...
-
CVE-2026-73772 β Hewlett Packard Enterprise (HPE) AOS-CX β CVSS 6.5 β Unauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in ...
-
CVE-2026-84369 β svg svgo β CVSS 6.1 β SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObje...