Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Dropbox has revealed details of a phishing attack to which it fell victim. In the attack, a threat actor was able to steal code from the company after gathering employee credentials to GitHub repositories.. The security breach took place in the middle of last month, with GitHub notifying Dropbox of suspicious account activity on October 14. The cloud storage company says that the code that was accessed "contained some credentials -- primarily, API keys -- used by Dropbox developers" but insists that "no one's content, passwords, or payment information was accessed", and that its core apps and infrastructure were unaffected. In a blog post that goes into some detail about the incident, Dropbox says: "In today's evolving threat landscape, people are inundated with messages and notifications, making phishing lures hard to detect. Threat actors have moved beyond simply harvesting usernames and passwords, to harvesting multi-factor authentication codes as well. In September, GitHub detailed one such phishing campaign, in which a threat actor accessed GitHub accounts by impersonating the code integration and delivery platform CircleCI. We recently learned that Dropbox was targeted by a similar campaign. . Dropbox encountered a serious cybersecurity incident, in which source code was compromised from GitHub through phishing tactics; however, essential systems remain intact.. Dropbox Security, GitHub Phishing Attack, Code Theft Risk, API Key Protection. . LinuxSecurity.com Team
Dropbox has uncovered 264 vulnerabilities, paying out US$319,300 in bounties, after a one-day bug hunt in Singapore that brought together hackers from 10 nations around the world. Hosted by bug bounty platform HackerOne, the live event saw 45 of its members from countries such as Japan, India, Australia, Hong Kong, and Sweden, and some as young as 19, galvanise in the city-state in an attempt to infiltrate Dropbox's targeted systems. . The cloud storage vendor days earlier had revealed parts of its "attack" scope, so HackerOne members already had identified and submitted dozens of potential bugs before the live event. According to a company spokesperson, the focus this time was on Dropbox and its recent acquisition of digital workflow platform, HelloSign. The link for this article located at ZDNet is no longer available. . Dropbox's bug hunt uncovered 264 vulnerabilities, rewarding hackers with $319,300 for their findings in Singapore.. dropbox, uncovered, vulnerabilities, paying, us$319, bounties, one-day. . Brittany Day
Over 13,000 iSCSI storage clusters are currently accessible via the internet after their respective owners forgot to enable authentication. . This misconfiguration has the risk of causing serious harm to devices' owners, as cyber-criminal groups could access these internet-accessible hard drives (storage disk arrays and NAS devices) to replace legitimate files with malware, insert backdoors inside backups, or steal company information stored on the unprotected devices. The link for this article located at ZDNet is no longer available. . More than 12,000 open SMB file shares can be found on the internet, posing a threat of unapproved access and possible information leaks.. iSCSI Access Risk, Storage Cluster Security, Internet Vulnerability. . LinuxSecurity.com Team
Cloud storage service provider Dropbox has acknowledged that a file containing private customer data was stolen from the Dropbox account of one of the company's employees and that the information was subsequently used to send out spam messages to users.. In mid-July, a number of Dropbox users complained that they were receiving spam at email addresses used exclusively to sign into the storage service. As it turns out, this was no coincidence The link for this article located at H Security is no longer available. . In mid-July, a number of Dropbox users complained that they were receiving spam at email addresses u. cloud, storage, service, provider, dropbox, acknowledged, containing, private, customer. . LinuxSecurity.com Team
Spammers are currently sending large volumes of spam to users of cloud storage service provider Dropbox. The H's associates at heise Security have so far received four different pieces of German-language spam at an email address used solely to register with Dropbox, and some of their readers have reported the same problem; similar reports can also be found on the Dropbox forums. In almost all cases, the spam is for suspicious-looking online casinos.. The link for this article located at H Security is no longer available. . Fraudsters prey on OneDrive users with questionable betting site advertisements. Check out the concerning testimonials from victims and analysts.. Dropbox Spam Attacks, Online Casino Fraud, Email Threats. . LinuxSecurity.com Team
Federal prosecutors who accuse file-sharing site Megaupload of being a hotbed of digital piracy say the site's customer files, presumably including perfectly legal ones, may be deleted starting Thursday. . "It is our understanding that the hosting companies may begin deleting the contents of the servers beginning as early as February 2, 2012," U.S. Attorney Neil H. MacBride said in a letter filed in federal court. The letter, submitted Friday in the Eastern District of Virginia, says that government investigators have finished executing search warrants at centers where Megaupload and MegaVideo files are stored. The link for this article located at CNN is no longer available. . Court alerts indicate possible removal of Dropbox's content in light of copyright concerns. Keep updated.. Megaupload Data Deletion, Digital Piracy Risks, Cloud Storage Legal Issues. . Dave Wreski
Popular cloud storage service Dropbox is misleading users into thinking it is more secure than it really is, says a security researcher and academic, who has asked for the FTC to investigate.. Dropbox has around 25 million users. It's often used as an escape hatch by owners of Apple's iPhone and iPad: the iOS slabs don't expose the device's local file system or provide the end user with a way of manipulating files. "Dropbox's customers face an increased risk of data breach and identity theft because their data is not encrypted according to industry best practices," says Christopher Soghoian, who filed the complaint. Soghoian is a researcher at the Center for Applied Cybersecurity Research at Indiana University. He explains that unlike other cloud services The link for this article located at The Register UK is no longer available. . Dropbox has around 25 million users. It's often used as an escape hatch by owners of Apple's iPhone . popular, cloud, storage, service, dropbox, misleading, users, thinking, secure. . LinuxSecurity.com Team
Google is pushing full steam ahead with their office strategy, and their hope is to convince a lot of individuals and businesses to trust Google enough to store their documents on Google's servers instead of their own computers, or servers under their control. The fact that unauthorized document access is a simple password guess or government "request" away already works against them. But the steady stream of minor security incidents we've seen (many very recently) can also hurt Google in the long run. Running applications for businesses is serious stuff, and Google needs to be diligent about security. . The link for this article located at TechCrunch is no longer available. . Google's security missteps can erode user trust, leading individuals and businesses to reconsider their cloud data storage options amid growing competition.. Google Security, Cloud Storage Risks, User Trust Issues, Data Privacy, Business Application Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.