CuraSec

tag: Third-Party-Breach · 2 items

2026-09-02 · BleepingComputer · source ↗ #third-party-breach#identity#saas
  • Engineer — Plan: The flaw is on Lenovo’s side, not patchable by your team, but audit all corporate Dropbox accounts for unauthorized access and disable any Lenovo-linked authentication integrations in your Dropbox admin console.
  • SOC/IR — Act: Dropbox accounts are actively compromised — review Dropbox audit logs for anomalous sign-ins tied to Lenovo ID authentication since the earliest affected date and sweep for any corporate accounts flagged by Dropbox’s warning.
  • Leader — Act: Confirm this week whether your organization uses Dropbox accounts linked to Lenovo credentials, request Dropbox’s breach notification details, and assess whether customer or regulatory disclosure obligations are triggered.
2026-08-18 · BleepingComputer · source ↗ #third-party-breach#logistics#data-breach
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: A logistics vendor breach affecting Pokémon Center customers in UK and Germany illustrates supply-chain data exposure risk; useful as a reference case if your organization relies on CEVA Logistics or similar third-party fulfillment providers for customer data handling.