Categories: All

Man in the Cloud: Hackers Can Access Your Dropbox, Google Drive, OneDrive Files WITHOUT Password

SPR: Researchers have found a new way to hack into your cloud syncing accounts without any username or password by deploying a new “man in the cloud attack”. These attacks use “password tokens” and are harder to detect and control.
You must have read about the man-in-the-middle attacks that steal your data transiting between the two end points. Today, we are going to tell you about a new man in the cloud attack that allows the attacker to access your files in the cloud without passwords.
At the Black Hat security conference in Las Vegas, cyber security firm Imperva has published a new research that exploits a vulnerability in the design of cloud syncing services like Google, Box, OneDrive, and Dropbox.
This man in the cloud attack works by stealing the password token, a tiny file that is found in user’s devices. The password token saves the user from typing their password again and again. After obtaining this token using methods like phishing attack or a drive-by exploit, hackers can use it to access your account by fooling another new device. This man in the cloud attack could be used to steal/alter your files, and add ransomware or malware.
Amichai Shulman, CTO of Imperva, said that this type of man in the cloud attack can also affect businesses that are dependent on cloud-based services. He added that their research has revealed how easy it is for cybercriminals to hack cloud syncing accounts, and how difficult it’s to recover and detect such unauthorized authentications. He said, “recovery of the account from this type of compromise is not always feasible.”
Describing the man in the cloud attack, Shulman defended the cloud service providers and refrained himself from calling it a design flaw. He said that these services are secure, providing seamless file transfer, but it’s s trade-off between security and usability.
Even though many services offer 2-factor authentication, there isn’t any simple fix for the man in the cloud attack. These 2-factor notifications are delivered when an access is detected from a new computer or a new location, but people choose to ignore them. To themselves protect from these attacks, Imperva said that companies must invest more in monitoring and protecting data resources in the cloud.
Did you find this story helpful? Tell us in the comments below.
For more updates, subscribe to our newsletter.
spatsariya

Recent Posts

Vivo V80 India Launch Is Officially Teased With a Big Battery Upgrade

Vivo has officially teased the India launch of the Vivo V80, giving us a first…

7 minutes ago

Vivo V80 India Launch Is Officially Teased With a Big Battery Upgrade

Vivo has officially teased the India launch of the Vivo V80, giving us a first…

13 minutes ago

Grok 4.7 Is Cheap. Its Real Cost Depends on How Many Steps It Takes

SpaceXAI has launched Grok 4.7 with a pitch designed for teams that run AI agents…

1 hour ago

Claude Leads 26% of Anthropic’s AI R&D. Is Recursive AI Starting?

Anthropic has put a number on a transition that AI labs usually describe only in…

8 hours ago

Why Meta Stock Jumped 11% on Muse AI — Is the Rally Priced In?

Meta Platforms finished Monday at $741.25, up 11.43%, after investors found the consumer AI growth…

10 hours ago

Why Bitcoin Is Pumping Toward $87,000 — Is It a Bull Trap?

Bitcoin has gone from a shaky recovery to a full-blown momentum trade. At 8:14 p.m.…

11 hours ago