OneAxiom confirmed that Dropbox accessed over 5,000 accounts over 17 days without requiring guessing a password, with no session requiring a password, and the vulnerability lived in how a partner's identity system verified that someone owned the email address they were registering.
Public source
Publisher name
Public post
Dropbox just confirmed something that should worry anyone who trusts a “sign in with X” button on a service they didn't build themselves. About 5,000 accounts were acces…
Company
OneAxiom
Your extended security team, built around your business.
- Industry
- Computer and Network Security
- Location
- Naples, US
- Company size
- 11–50 employees
About OneAxiom
OneAxiom is the MSSP that knows you by name. We build around your environment from day one with custom detection rules, a named team, and a relationship that doesn't reset every time you call. We bring the full stack. SIEM, EDR, and vulnerability management: licensed, configured, and run by us. Flat-rate, predictable pricing, so the bill doesn't spike when the network gets noisy. You'll meet your CX Manager, your TAM, and your SOC analysts before you sign. Not during onboarding, before. The team you meet in the vetting calls is the team that picks up the phone at 2am. How we deliver: 15-minute actual P1 response against a 30-minute SLA. 96% of alerts absorbed before they reach your team. 120 days of IT time given back to your team every year so you can focus on your security program, not noise triage. If cookie-cutter security doesn't cut it anymore, visit our website to learn how we build around your environment.
See moreLatest activity
Latest activity from OneAxiom
3 signals
Research & Knowledge
OneAxiom published a 2026 poll showing that 48% of security professionals ranked agentic AI as the top attack vector for the year ahead, ahead of phishing and ransomware.
Research & Knowledge
OneAxiom published an article in Behind Closed Ports discussing the denial rates of cyber insurance applications and the City of Hamilton case.
Discover more
Similar signals
Similar public activity from other companies.
Technology & Infrastructure
Swif.ai
Swif.ai reported that Dropbox trusted the matching email claim and signed users straight into their account without requiring a password prompt or step-up authentication.
Technology & Infrastructure
IRONSCALES
IRONSCALES experienced a composite authentication failure that passed through a real project-management vendor's link tracker before landing on a throwaway credential page.
Technology & Infrastructure
4Data Solutions
4Data Solutions reported that attackers could bypass a public API endpoint in under ten hours to obtain master admin credentials.
Technology & Infrastructure
OX Security
OX Security reported that attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.
Technology & Infrastructure
Maicro Machines Holdings LLC