

- GOOGLE DRIVE SAVE AS PDF FILE OK TO OPEN AS VIRUS ZIP FILE
- GOOGLE DRIVE SAVE AS PDF FILE OK TO OPEN AS VIRUS DOWNLOAD
Problem: SD Card Files and Folders Become Shortcuts Recover Data and Format Drive to Convert Shortcut File into Original File
GOOGLE DRIVE SAVE AS PDF FILE OK TO OPEN AS VIRUS DOWNLOAD
GOOGLE DRIVE SAVE AS PDF FILE OK TO OPEN AS VIRUS ZIP FILE
When the 2.25 BG ZIP file containing the CVS file with Lumin PDF users’ information was leaked, anyone was able to access their names, email addresses, geo-locations, as well as the Google access token. That means that Lumin PDF operates from its own website rather than the platform that your file was stored on originally.

Once all permissions are granted, whether you try to open files from OneDrive, Dropbox, Gmail, or Google Drive, you are redirected to. If you allow these actions, you are asked to confirm your decision once more, and you are informed that Lumin PDF can associate you with your personal info on Google, see personal information, and view your email address. Finally, Lumin PDF needs to save files, create new files, view folders and their content, and make changes within folders, which includes deleting content. The tool also wants permission to view, create, edit, and delete configuration data on Google Drive. First, you are asked to allow the tool to see your files, download your files, as well see the names and email addresses of those who have access to those files. When you click it, you have to choose the right Google account, and then you are asked to enable certain permissions. When you choose to view a PDF file stored on Google Drive using Lumin PDF for the first time, you are informed that “ Lumin needs access to Google Drive to open file,” and you are introduced to the Connect To Google Drive button.

What are Google access tokens and how can they be exploited Can we trust these claims? Only time will tell. Therefore, according to Lumin, the Google Drive data breach could not have happened. So, was Lumin hiding a data breach? In fact, was there a data breach? According to Max Ferguson, the CEO of Lumin – who was approached by Cimpanu Catalin – the hackers behind the attack could not have exploited Google access tokens, which were included in the leaked document, because they were expired by the time the breach occurred.

ZDNet broke the news and reached out to both Lumin and Google, who, apparently, had launched their own investigations into the incident by that time. The insider – who also appears to be the hacker, who exploited a MongoDB database vulnerability to steal the data – claims to have reached out to Lumin on several different occasions within a period of five months to warn the company about the security flaw, but no response was received. According to a ZDNet report, an insider warned their researchers that data of 24.3 million Lumin users was leaked online, when it was shared as a CSV file via an underground hacking forum.
