Dropbox Confirms 5,000 Accounts Compromised via Lenovo Login

Dropbox's breach via Lenovo login highlights the growing threat of trust relationship attacks and the need for continuous vigilance.

By Central
The Dropbox-Lenovo incident compromised 5,000 accounts and underscores risks in third-party integrations.
Highlights
  • Dropbox confirmed 5,000 accounts were compromised through a flaw in Lenovo's email verification process.
  • Microsoft deployed server-side patches for nine cloud vulnerabilities without requiring customer action.
  • Project Watershed 250 provides free cybersecurity resources to Texas water utilities to defend against nation-state threats.

Dropbox has confirmed that approximately 5,000 user accounts were compromised in a campaign that exploited a flaw in Lenovo’s email verification process, highlighting how trust relationships between third-party services can create unexpected attack surfaces. Attackers registered Lenovo IDs using victims’ email addresses and then leveraged the integration to access their Dropbox accounts. While Dropbox responded by closing all unauthorized sessions and access, the incident underscores a growing class of credential-based attacks that target the connections between platforms rather than the platforms themselves. This breach, disclosed as part of a broader weekly roundup of developments across the cybersecurity landscape, arrives alongside significant patches, escalating ransomware trends, and new funding for AI-driven security startups.

Microsoft Patches Nine Cloud Vulnerabilities Without Customer Action

Microsoft has deployed server-side patches addressing nine vulnerabilities across its cloud portfolio, including Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language, and Discovery Studio. Because the fixes were applied directly to Microsoft’s infrastructure, no customer action was required. This approach reflects a growing industry shift toward remediating cloud vulnerabilities at the provider level, which reduces the operational burden on enterprise customers but also places greater responsibility on cloud vendors to detect and patch flaws before they are exploited. The breadth of affected services—spanning identity management, database, automation, AI, and analytics—illustrates the complexity of securing a sprawling cloud ecosystem where a single vulnerability can cascade across multiple product lines.

Project Watershed 250: Free Cybersecurity Resources for Texas Water Utilities

The White House and the Governor of Texas have launched Project Watershed 250, a federal-private sector initiative designed to provide water and wastewater utilities across the state with free cyber defense resources. The program explicitly aims to harden these critical infrastructure entities against cyberattacks originating from China, Iran, and other hostile foreign adversaries. Water utilities have become an increasingly attractive target for nation-state actors, as disruptions to water supply can cause widespread public health and economic damage. Project Watershed 250 represents a recognition that many municipal utilities lack the budget and expertise to deploy robust defensive measures on their own, and that proactive government intervention is necessary to close the security gap in essential services.

Minnesota County Pays $128,000 Ransom After January Attack

Winona County in Minnesota paid a ransom of $128,539.57 to restore services and protect personal information following a ransomware attack in January 2026. The county subsequently fell victim to a second ransomware incident in April, which was claimed by the InterLock gang. The group responsible for the January attack has not been publicly identified. The decision to pay the ransom, while controversial among security professionals, reflects the difficult calculus that local government leaders face when critical services are taken offline and sensitive citizen data is at risk. The recurrence of ransomware attacks on the same county within months suggests that remediation efforts following the first incident were insufficient to fully eradicate the attacker’s foothold or that multiple threat actors independently targeted the same vulnerable environment.

Exchange Server Exploit Published for CVE-2026-62911

Exploit code has been publicly released for CVE-2026-62911, a high-severity vulnerability in Microsoft Exchange Server that was patched in August. The Netherlands National Cyber Security Centre has issued a warning, and as of September 1, The Shadowserver Foundation observed over 21,000 servers that had not yet received the update. Exchange Server has historically been a prime target for attackers due to its widespread deployment in enterprise environments and its deep integration with email and calendaring functions. The availability of working exploit code dramatically increases the urgency for organizations to patch, as threat actors can now weaponize the vulnerability without having to develop their own exploit. The large number of unpatched servers indicates that many organizations are either unaware of the update, lack the resources to apply it promptly, or are running legacy versions that may not be eligible for the fix.

How Did Attackers Compromise Dropbox Accounts Through a Lenovo Login Integration?

The attack exploited an issue in Lenovo’s email verification process, which allowed threat actors to register Lenovo IDs using email addresses belonging to other individuals. Once they had control of a Lenovo ID associated with a victim’s email, the attackers then leveraged the integration between Lenovo’s login system and Dropbox to access the victim’s Dropbox account. This is not a direct breach of Dropbox’s authentication mechanisms but rather an abuse of the trust relationship between two platforms. Dropbox identified approximately 5,000 affected users, closed all unauthorized sessions, and revoked unauthorized access. The incident illustrates a broader vulnerability class: whenever a service allows authentication through a third-party provider, the security of that integration depends on the weakest link in the chain. A flaw in Lenovo’s verification flow became a vector for compromising Dropbox accounts, even though Dropbox itself had not been compromised.

Knight Office Phishing Kit Targets Microsoft 365 and Google Workspace

Security researchers at Huntress have identified a new adversary-in-the-middle (AitM) phishing kit called Knight Office that targets Microsoft 365 and Google Workspace users. Rather than simply capturing passwords, Knight Office relies on token theft—a technique that provides attackers with an already-authenticated session, effectively bypassing password requirements and multi-factor authentication (MFA) mechanisms. By intercepting session tokens during the authentication flow, the kit allows attackers to maintain persistent access to victim accounts even after passwords are changed. This represents an evolution in phishing tactics, shifting from credential harvesting to session hijacking, and it poses a significant challenge for organizations that have invested heavily in MFA as a compensating control.

Plex Urges Users to Update Media Server and Desktop Applications

Plex has announced the release of Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0, both containing patches for multiple security vulnerabilities. The company has urged users to update their instances as quickly as possible but has not yet disclosed specific technical details about the bugs, and CVEs have not been assigned. Plex’s user base includes a large number of home users and small businesses that may not have automated update mechanisms in place, making the company’s public call to action critical. The decision to withhold vulnerability details temporarily is a common practice that balances the need to give users time to patch against the risk of informing attackers before defenses are in place.

Guardio Reaches $1.1 Billion Valuation After $40 Million Funding Round

Guardio, a consumer cybersecurity company focused on protecting users from AI-driven scams that lead to identity theft, has reached a valuation of $1.1 billion following a $40 million funding round. The company’s approach addresses a fundamental shift in attacker behavior: rather than forcing their way into networks through technical exploits, today’s threat actors increasingly prefer to walk in using stolen credentials. This has driven demand for solutions that monitor the consumer attack surface—email accounts, social media, financial services—and alert users when their credentials have been compromised or when they are being targeted by sophisticated impersonation campaigns.

Coder’s Module Registry Compromised via Cloudflare Infrastructure

A threat actor successfully hacked Coder’s Cloudflare infrastructure, adding unauthorized IP addresses that hosted malicious code. The code was served through Coder’s module registry website to a subset of users over a short period. Users who downloaded the malicious payload were infected with a credential stealer. Coder, a platform for cloud development environments, has disclosed the incident and provided guidance to affected users. The compromise of a module registry or package repository is a well-established supply chain attack vector, and the fact that the attacker gained initial access through Cloudflare infrastructure—a widely trusted content delivery and security provider—adds an extra layer of concern for organizations that rely on edge security services as a critical part of their defensive architecture.

Russian National Charged With Delivering Malware to 80,000 Freelancers

Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, has been charged in the United States with exploiting the online message platform of a freelance employment company based in California. Between June 2016 and November 2017, Aktulaev allegedly delivered malware to approximately 80,000 freelance users. He was arrested in Cyprus last year, and the indictment—originally filed in 2021—was unsealed on Monday when Aktulaev appeared in court following extradition to the United States. The case highlights the vulnerability of freelance platforms, where workers often communicate with clients through built-in messaging systems that may lack robust security controls. The scale of the compromise—80,000 victims over 18 months—suggests a methodical, targeted campaign rather than opportunistic scatter-shot attacks.

Lasso Security Raises $30 Million for CPU-Based AI Guardrails

Israeli AI security company Lasso Security has raised $30 million in a funding round led by ClearSky, with participation from Entrée Capital, iAngels, Singtel Innov8, Mindset, and Swish Data. The company has announced LEAP, an AI guardrail that promises top-tier detection accuracy while running on CPUs rather than requiring expensive GPU infrastructure. This could significantly lower the barrier to entry for organizations that want to deploy AI security monitoring but have been constrained by hardware costs. The funding round signals continued investor confidence in the AI security market, which has grown rapidly as enterprises race to adopt generative AI tools while grappling with the novel risks they introduce, including data leakage, prompt injection, and model manipulation.

The developments of the past week collectively paint a picture of an increasingly interconnected threat landscape where the weakest link may not be a software vulnerability but a trust relationship between services, a misconfigured cloud platform, or a supply chain compromise. The Dropbox-Lenovo incident, the Knight Office phishing kit, and the Coder supply chain attack each demonstrate that attackers are methodically probing the seams where systems integrate. At the same time, the continued prevalence of unpatched Exchange servers, the recurrence of ransomware on a single county government, and the emergence of token-theft phishing kits show that many organizations are struggling to keep pace with the speed of adversary innovation. Investments in Guardio and Lasso Security reflect a market that recognizes these challenges and is placing its bets on AI-driven defenses and consumer-facing tools as part of the solution. For security practitioners, the lesson is that no integration is too small to vet, no patch is too routine to prioritize, and no user segment—whether freelancers, homeowners running a media server, or municipal employees—is too peripheral to include in the threat model.

Share This Article