Campaign team remains evasive The Hotmail and Dropbox accounts of US Presidential candidate Mitt Romney appear to have been hacked in an echo of a similar break-in suffered by vice-presidential hopeful Sarah Palin in 2008.So far there is no confirmation of the hack, first reported by a news site Gawker, but a statement made by Romney’s team offered credence to the possibility.“The proper authorities are investigating this crime and we will have no further comment on it,” read an otherwise evasive statement made by Romney campaign communications director, Gail Gitcho.Gawker said it had been contacted by an unnamed third-party who claimed to have broken into an old Hotmail mittromney@hotmail.com account supposedly not used after 2006 but now found to be active. The hacker claimed to have bypassed security by correctly answering the security reset question ‘what is your favourite pet?’, which also turned out to be the password for Romney’s Dropbox account.The email address accessed by the attacker came to his or her attention after the address was published in a story by the Wall Street Journal. “I have nothing to do with Anonymous and have never done something like this before,” said the hacker.What the hacker found in the accounts is not known and has not been leaked, unlike the contents of Sarah Palin’s gov.palin@yahoo.com account, the contents of which ended up on Wikileaks during her failed vice presidential campaign in 2008.David Kernell, the 20 year-old son of Memphis Democratic state representative, Mike Kernell was later sent to a half-way house jail for the hack, losing his appeal against a charge of evidence deletion earlier this year.Assuming the ‘hack’ actually happened and the email box contained sensitive content, the attack is still only mildly embarrassing as long as this remains unpublished. Romney was apparently still using an email address said to have been de-activated years ago and made the elementary mistake of using an easily-guessed password for Dropbox.However, the attack underlines the potential susceptibility of some webmail services to relatively simple password reset attacks where two-factor authentication is not in use. Related content news Google Chrome zero-day jumps onto CISA's known vulnerability list A serious security flaw in Google Chrome, which was discovered under active exploitation in the wild, is a new addition to the Cybersecurity and Infrastructure Agency’s Known Exploited vulnerabilities catalog. By Jon Gold Oct 03, 2023 3 mins Zero-day vulnerability Vulnerabilities Security brandpost The advantages and risks of large language models in the cloud Understanding the pros and cons of LLMs in the cloud is a step closer to optimized efficiency—but be mindful of security concerns along the way. By Daniel Prizmant, Senior Principal Researcher at Palo Alto Networks Oct 03, 2023 5 mins Cloud Security news Arm patches bugs in Mali GPUs that affect Android phones and Chromebooks The vulnerability with active exploitations allows local non-privileged users to access freed-up memory for staging new attacks. By Shweta Sharma Oct 03, 2023 3 mins Android Security Vulnerabilities news UK businesses face tightening cybersecurity budgets as incidents spike More than a quarter of UK organisations think their cybersecurity budget is inadequate to protect them from growing threats. By Michael Hill Oct 03, 2023 3 mins CSO and CISO Risk Management Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe