<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Saas on CuraSec</title><link>https://curasec.metacog.co.kr/tags/saas/</link><description>Recent content in Saas on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/saas/index.xml" rel="self" type="application/rss+xml"/><item><title>Dropbox accounts breached via Lenovo email verification flaw</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-dropbox-accounts-breached-through-lenovo-email-verification/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-dropbox-accounts-breached-through-lenovo-email-verification/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> The flaw is on Lenovo&amp;rsquo;s side, not patchable by your team, but audit all corporate Dropbox accounts for unauthorized access and disable any Lenovo-linked authentication integrations in your Dropbox admin console.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Dropbox accounts are actively compromised — review Dropbox audit logs for anomalous sign-ins tied to Lenovo ID authentication since the earliest affected date and sweep for any corporate accounts flagged by Dropbox&amp;rsquo;s warning.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm this week whether your organization uses Dropbox accounts linked to Lenovo credentials, request Dropbox&amp;rsquo;s breach notification details, and assess whether customer or regulatory disclosure obligations are triggered.&lt;/li>
&lt;/ul></description></item><item><title>RingCentral breach exposes 1.6M accounts via ShinyHunters</title><link>https://curasec.metacog.co.kr/insights/2026-08-14-ringcentral-data-breach-exposed-info-of-1-6-million-accounts/</link><pubDate>Fri, 14 Aug 2026 11:54:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-14-ringcentral-data-breach-exposed-info-of-1-6-million-accounts/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> ShinyHunters claimed this breach in July; no IOCs or TTPs published yet, so no detection action is possible — file for actor-tracking context.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If RingCentral is in your vendor stack, confirm scope with your account rep, request their incident report, and assess whether affected data triggers customer or regulatory notification obligations.&lt;/li>
&lt;/ul></description></item></channel></rss>