
Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
THE SO WHAT
A Lenovo ID verification bug exposing 5,000+ Dropbox accounts is a reminder that your weakest SSO or OEM integration can become the front door. This week, inventory every third‑party identity bridge touching core data stores and verify who is actually enforcing MFA and session hygiene.
READ THE SOURCE
MORE FROM THE WIRE
Deep & Emerging TechCircular announces Ring 3 Pro and Slim at IFA with contactless payments and haptic alerts
Circular’s Ring 3 line adding contactless payments, haptics, and FDA‑cleared ECG turns wearables into regulated payment‑plus‑health endpoints. Anyone building health or fintech flows needs to treat rings and sensors as first‑class clients—with medical compliance and PSD2‑style constraints baked into design from day one.
Deep & Emerging TechStolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
Stolen Claude cookies jumping into corporate Gmail via ungoverned grants shows how SaaS‑to‑SaaS auth can bypass your IdP and MFA entirely. This week, audit OAuth scopes from AI tools into core apps and treat self‑serve, card‑billed AI accounts as shadow IT with direct access to your comms layer.
Deep & Emerging TechNvidia backs Spanish spinout IPronics in $125m Series B
Nvidia putting $125M into IPronics is another data point that reconfigurable photonics is moving from research to the AI infra roadmap. If you’re planning multi‑year training or inference capacity, start tracking non‑GPU accelerators in your cost and latency models now.
Deep & Emerging TechUVA’s Situational Awareness Bet Fueled Record Year Before Tumult
An AI‑focused hedge fund losing more than two‑thirds of $45B in a month is a reminder that model‑driven strategies can concentrate risk as fast as they compound returns. Any team leaning on AI for trading or allocation should be running stress tests on regime shifts, not just backtests on recent data.