Cryptocurrency prices are highly volatile. All content is for reference only and is not investment advice. Trading involves risk of total loss.

Full disclaimer
Back to News
SourceDecrypt

Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw

Attackers reportedly registered Lenovo IDs using victims’ email addresses, allowing them to sign into existing Dropbox accounts without their passwords.
Disclaimer: The views above are the author's only and do not represent 711BTC. Nothing here constitutes investment advice.

Related

06-20 03:29

Zodiac released a security incident report stating that the ERC-1271 verification flaw allowed attackers to bypass module authentication.

According to Mars Finance, the Zodiac team released a security incident analysis report affecting the Zodiac Roles Modifier, disclosing that the root cause of the vulnerability lies in a flaw in the ERC-1271 transaction signature verification logic: the system only judges the validity of the signature based on the returned "magic value" without verifying whether the call itself was successful, which may disguise a failed verification as a valid signature and bypass the module authentication mechanism.

08-17 22:35

Kraken Parent Payward Joins Glasswing, Gets Access to Claude Mythos to Hunt Security Flaws

Payward is joining Project Glasswing, Anthropic’s program for giving vetted organizations access to its powerful cybersecurity AI.

07-03 13:42Important

Gnosis Pay Security Incident Recap: Vulnerability stemmed from a flaw in signature verification logic; fix completed.

According to Foresight News , Gnosis Pay released a post-incident report on June 1st, disclosing that the root cause of the vulnerability was a flaw in the ERC-1271 signature verification logic within the Zodiac module: the system only reads the contract's return result and does not check whether the call was actually executed successfully. Attackers exploited this flaw to deploy a contract that intentionally failed but still returned a "valid" status, forged authorization, and then withdrew funds from accounts not owned by them. This vulnerability was introduced with Zodiac code version 3.4.0 in October 2023 and was patched on June 5th. The report shows that attackers withdrew approximately $1.5 million from 5,281 wallets, including approximately $641,000 in GNO, approximately $453,000 in EURE, and approximately $399,000 in USDC.e; another approximately $300,000 is locked in inaccessible accounts, and the team is exploring recovery methods. Gnosis Pay stated that it will expand its security team, introduce external audits, broaden the scope of smart contract audits, and has completed a complete product rebuild (v2) to improve its security response capabilities.

06-25 11:08

Providing dedicated accounts for AI is a stopgap measure, not a fundamental solution; security sandbox experts criticize Anthropic for undermining accountability.

According to Beating's monitoring, Kenton Varda, a security sandbox expert and chief architect at Cloudflare, criticized Anthropic's agent identity model, pointing out that directly assigning dedicated accounts to AI not only fails to adapt to massive task scales but also undermines human accountability mechanisms. Varda believes that while the new security architecture attempts to solve the problem of credential overreach in multi-person collaboration, it has fatal flaws in its underlying design. Agents cannot be held accountable under the law or administration; all operational permissions must, and can only, originate from actual, living people. If AI is given independent, dedicated accounts, when it performs destructive operations such as deleting databases, the system logs will only record that the AI performed the operation, failing to assign responsibility to the actual employee who issued the instruction, thus rendering the human accountability mechanism completely ineffective. Addressing the configuration fatigue caused by configuring independent permission packages, Varda advocates for a capability-based security model. The system should not grant AI global or default permissions but rather dynamically transfer permissions as "capabilities." For example, when an employee sends a link to a specific document to the AI in a conversation, the system automatically creates a temporary read-only reference to that document using the employee's credentials and passes it to the AI. This capability model not only ensures that any AI action can be traced back to the specific initiator, but also prevents employees with lower privileges from passing database credentials they do not possess to the AI, thus preventing unauthorized access at the underlying level.

08-17 13:31

Hackers Are Abusing a macOS Screen Sharing Flaw to Secretly Mine Monero

The Dutch cyber agency says attackers exploited an authentication flaw in macOS Screen Sharing to gain root access and plant Monero miners, with public proof-of-concept code now circulating.

09-09 23:02

Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider

The hardware wallet maker said a fake security alert claimed a hardware flaw could expose users’ recovery phrases.