Bottom line: 5,000 Dropbox accounts were compromised due to a high-severity vulnerability in Lenovo's ID login system.
What's happening: Synopsys researcher Patrick McCarrick identified the vulnerability in February 2023, which has a CVSS score of 8.5. The vulnerability was discovered in Lenovo's ID login system, used to authenticate users across various Lenovo devices. A total of 5,000 Dropbox accounts were affected, including accounts linked to Lenovo ID.
What to do: Dropbox has updated its security measures and provided a patch for affected users to mitigate the issue. Security leaders should review their own Lenovo device authentication processes to ensure no similar vulnerabilities exist.