#accounttakeover

7 posts · Last used Sep 07

⚠️ #SW_ISAC_ADVISORY

There is a spate of #AccountTakeover underway.

Service providers may receive reports for accounts that have a display name beginning with "Hacked -" or linking to "t[.]me/HomeFucker5"

These accounts may be longstanding valid accounts that have been hijacked.

While investigating, consider

  1. deleting any offensive posts,
  2. freezing the account until the rightful owner can reclaim it,
  3. use of two-factor authentication for accounts shown to be at risk
45
2
105
2
🚨 Dropbox Hack / Data Breach: Lenovo ID Flaw Enabled Account Takeover A serious Dropbox security incident highlights a dangerous weakness in federated identity. Attackers allegedly registered Lenovo IDs using victims’ email addresses, then abused Dropbox SSO / OIDC federation** to authenticate against existing Dropbox accounts. The disturbing part: • No Dropbox password was required • Victims didn't necessarily have a Lenovo ID • The attack relied on email-based account matching • A rogue identity could become a trusted federated identity • Attackers could obtain a legitimate-looking Dropbox session This is essentially an account takeover through an identity-provider trust failure, not a traditional password compromise. The full technical breakdown covers the Dropbox hack, Lenovo ID vulnerability, OIDC attack chain, federated authentication flaw, affected users, Dropbox's remediation, and defensive recommendations: https://thecybersecguru.com/news/dropbox-breach-lenovo-id-account-takeover/ #Infosec #CyberSecurity #Dropbox #DropboxHack #DropboxBreach #DataBreach #AccountTakeover #Lenovo #LenovoID #OIDC #SSO #FederatedIdentity #IdentitySecurity #CloudSecurity
1
0
0
0
NPM account takeovers via expired maintainer domains You don't need to exploit npm to poison it. Buy the expired email domain behind a maintainer's account, reset the password, and the package is yours. We scanned 2.1 million packages, extracted 6.7 million maintainer emails, and found 675 expired domains leaving 2,843 packages open to takeover. Those packages sit under 257,000+ dependent repos and 93,000 downstream packages. One lapsed domain renewal, a supply chain full of blast radius. https://laburity.com/research-npm-account-takeovers/ #SupplyChainSecurity #npm #AccountTakeover #AppSec #Laburity
0
0
0
0
You've seen all posts