logo

Severe flaws in E2EE cloud storage platforms used by millions

ID: 9f85c851-7089-5484-b950-ab488c47fa2a

STIX ID: report--9f85c851-7089-5484-b950-ab488c47fa2a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-10-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers at ETH Zurich reported multiple serious cryptographic and protocol flaws across five end-to-end encrypted cloud storage services (Sync, pCloud, Icedrive, Seafile, Tresorit) that, under a realistic 'compromised server' threat model, can allow a malicious server to inject files, tamper with or reorder file chunks, replace or overwrite key material, and in some cases decrypt shared content; the issues affect millions of users, vendor responses vary (Tresorit fared relatively better) and no active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.