<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Third-Party-Breach on CuraSec</title><link>https://curasec.metacog.co.kr/tags/third-party-breach/</link><description>Recent content in Third-Party-Breach on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/third-party-breach/index.xml" rel="self" type="application/rss+xml"/><item><title>Dropbox accounts breached via Lenovo email verification flaw</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-dropbox-accounts-breached-through-lenovo-email-verification/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-dropbox-accounts-breached-through-lenovo-email-verification/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> The flaw is on Lenovo&amp;rsquo;s side, not patchable by your team, but audit all corporate Dropbox accounts for unauthorized access and disable any Lenovo-linked authentication integrations in your Dropbox admin console.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Dropbox accounts are actively compromised — review Dropbox audit logs for anomalous sign-ins tied to Lenovo ID authentication since the earliest affected date and sweep for any corporate accounts flagged by Dropbox&amp;rsquo;s warning.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm this week whether your organization uses Dropbox accounts linked to Lenovo credentials, request Dropbox&amp;rsquo;s breach notification details, and assess whether customer or regulatory disclosure obligations are triggered.&lt;/li>
&lt;/ul></description></item><item><title>Pokémon Center breach via CEVA Logistics exposes customer data</title><link>https://curasec.metacog.co.kr/insights/2026-08-18-pok-mon-center-data-breach-exposes-customer-info-cancels-som/</link><pubDate>Tue, 18 Aug 2026 11:37:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-18-pok-mon-center-data-breach-exposes-customer-info-cancels-som/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A logistics vendor breach affecting Pokémon Center customers in UK and Germany illustrates supply-chain data exposure risk; useful as a reference case if your organization relies on CEVA Logistics or similar third-party fulfillment providers for customer data handling.&lt;/li>
&lt;/ul></description></item></channel></rss>