Dropbox Trusted the Wrong Email. About 5,000 Accounts Were Opened.

A Lenovo email-verification flaw opened about 5,000 Dropbox accounts through passwordless sign-in. The incident exposes the risk of weak identity binding.

A Lenovo email-verification flaw opened about 5,000 Dropbox accounts through passwordless sign-in. The incident exposes the risk of weak identity binding.

Infostealers are stealing active Claude sessions, bypassing the need to defeat passwords or multi-factor authentication.

The login pages were real. The QR codes were real. The device-linking requests were real. That did not make them safe. Google Threat Intelligence Group has documented three suspected Russian cyber-espionage clusters that repeatedly turn legitimate authentication features into initial-access…

A password-reset email is meant to be the point where an identity system proves that the person changing a credential controls the account. A critical Keycloak flaw allowed an unauthenticated attacker to bypass that step and set a new password…

Passkeys remove the shared secret that makes password phishing possible, but they do not make a compromised endpoint trustworthy. Palo Alto Networks Unit 42 has demonstrated three attacks against Google Password Manager’s synchronised passkeys in Chrome on TPM-equipped Windows systems.…

France says one hijacked Tchap account exposed public-room content associated with 73,467 officials. Private encrypted histories were not reported compromised.