Attackers allegedly registered Lenovo IDs using victims’ email addresses, then used Dropbox SSO / OIDC federation to authenticate as those users. The key failure was email-based account matching across a federated trust boundary. In other words: Email address ≠ proof of account ownership. Dropbox knew it since the first week of August yet notification emails were sent to all customers today
Not sure what
wp.meis but seems like a tracking redirect. This is the link to the actual article without the redirect tracking: https://thecybersecguru.com/news/dropbox-breach-lenovo-id-account-takeover/Nah. Just that its the sharing url mechanism of jetpack
Slop writeup, but from what I’ve gathered is Dropbox wasn’t checking
email_verified: trueand lenovo would let you otherwise have a fully functional account without a verified email


