✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Legal Services
Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.
Explore Other Sectors
Legal Services Threat Reports
New CSS Attacks Expose Webmail Vulnerabilities: Protect Your Accounts
In August 2026, PortSwigger researcher Gareth Heyes unveiled a series of CSS-based attacks capable of breaching webmail defenses across platforms like Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. These techniques exploit vulnerabilities in HTML and CSS handling within webmail interfaces, allowing attackers to capture passwords, hijack third-party accounts, leak tokens, and manipulate AI tools that process emails. The research, presented at Black Hat USA 2026, demonstrated proof-of-concept attacks without evidence of malicious exploitation. Some providers have since addressed specific vulnerabilities, but others remain unpatched. This incident underscores the evolving nature of web-based threats, highlighting the need for continuous vigilance and proactive security measures. As attackers develop more sophisticated methods to exploit webmail platforms, organizations must prioritize regular security assessments and updates to protect sensitive user information.
2 days ago
Kill Chain
Swiss Government SharePoint Breach 2026: Exploiting CVE-2026-56164
In late July 2026, the Swiss Federal Office for Information Technology and Telecommunication (BIT) detected unauthorized access to its Microsoft SharePoint servers, compromising approximately 200 user accounts. The breach was identified on July 28, following unusual activity on the servers. BIT responded by blocking external internet access to SharePoint, patching vulnerabilities, and resetting affected account passwords. The attackers likely exploited SharePoint vulnerabilities disclosed and patched by Microsoft in mid-July, specifically CVE-2026-56164 and CVE-2026-50522. Investigations are ongoing, with no evidence of data theft beyond compromised login credentials. This incident underscores the critical importance of timely patch management and vigilant monitoring of enterprise applications. The exploitation of known vulnerabilities shortly after disclosure highlights the need for organizations to proactively address security updates to prevent unauthorized access and potential data breaches.
3 days ago
Kill Chain
Unveiling CSS Email Attacks: Insights from Black Hat 2026
In August 2026, at Black Hat USA, security researcher Gareth Heyes unveiled a series of novel attack techniques exploiting Cascading Style Sheets (CSS) within HTML emails. These methods enable attackers to compromise email accounts by bypassing traditional security measures, such as CSS sanitization and Content Security Policies, using only CSS and HTML. The attacks can lead to unauthorized data exfiltration, user tracking, and full account takeovers without the need for JavaScript or malicious attachments. ([portswigger.net](https://portswigger.net/research/talks?talkid=34&utm_source=openai)) This research highlights a significant shift in email-based attack vectors, emphasizing the need for enhanced security measures in webmail platforms. As attackers continue to innovate, organizations must adapt their defenses to address these emerging threats.
4 days ago
Kill Chain
Poison Claude: Unveiling Unauthorized Access to AI Models
In August 2026, cybersecurity researchers uncovered 'Poison Claude,' a clandestine service offering unauthorized access to Anthropic's Claude AI models at discounted rates. This operation exploited vulnerabilities to provide illicit access to models such as Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. Notably, the operator of Poison Claude had the capability to monitor and record every prompt submitted by users, leading to significant data privacy concerns and potential intellectual property theft. This incident underscores the escalating risks associated with unauthorized AI model access and the exploitation of AI systems for malicious purposes. It highlights the urgent need for robust security measures and vigilant monitoring to prevent such breaches, especially as AI technologies become increasingly integrated into critical business operations.
4 days ago
Kill Chain
ExfilSquad Ransomware Group Breaches UK Police Database in 2026
In late July 2026, the ExfilSquad ransomware group claimed responsibility for a cyberattack targeting the U.K.'s Police National Legal Database (PNLD). The attackers allege they exfiltrated approximately 135,000 contact records, including full names, organizations, and email addresses of police officers, staff, criminal justice professionals, and government partners. Additionally, data from users of the 'Ask the Police' platform who submitted inquiries were compromised. The PNLD has confirmed the breach and is collaborating with cybersecurity experts and the National Crime Agency (NCA) to investigate the incident. No evidence suggests that passwords or other security credentials were compromised, and the PNLD does not store confidential information related to victims, witnesses, or offenders. ([cypro.co.uk](https://cypro.co.uk/insights/cyber-bulletins/exfilsquad-ransomware-claims-microsoft-data-breach/?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups like ExfilSquad, who continue to target public sector entities. The breach highlights the critical need for robust cybersecurity measures, including multi-factor authentication and continuous monitoring, to protect sensitive information and maintain public trust.
6 days ago
Kill Chain
HollowFrame and Matryoshka: Unveiling a Sophisticated Spear-Phishing Attack on a Law Firm
In July 2026, a sophisticated cyberattack targeted an undisclosed law firm using a previously undocumented Go-based loader named HollowFrame and a Rust-based backdoor called Matryoshka. The attack commenced with a spear-phishing email containing a link to an encrypted archive, which, when executed, initiated a multi-stage infection chain. This sequence involved privilege escalation, disabling Microsoft Defender protections, and downloading additional payloads. HollowFrame utilized DLL side-loading techniques to deploy Matryoshka, enabling persistent remote command execution, Active Directory reconnaissance, file transfers, and deployment of further malicious tools. These capabilities facilitated credential theft, lateral movement within the network, and potential broader domain compromise. This incident underscores the evolving threat landscape where attackers employ multi-stage, modular malware frameworks to infiltrate organizations. The use of spear-phishing as an initial vector highlights the critical need for robust email security measures and user awareness training to mitigate such sophisticated attacks.
1 week ago
Kill Chain
Ernst & Young's 2026 Data Breach: A Supply Chain Attack by ShinyHunters
In April 2026, Ernst & Young (EY) detected unauthorized access to a third-party IT service management platform used for client tax services. The breach occurred between March 28 and April 12, 2026, during which attackers downloaded multiple documents containing personal and financial information related to client tax filings. EY secured its systems, removed unauthorized access, and notified federal law enforcement. Affected clients were offered 24 months of identity monitoring and restoration services through Experian. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/?utm_source=openai)) On July 27, 2026, the ShinyHunters extortion gang claimed responsibility for the breach, alleging they obtained EY credentials via a supply-chain attack. They threatened to release the stolen data if EY did not contact them by July 31, 2026. EY has not confirmed ShinyHunters' involvement. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/?utm_source=openai))
1 week ago
Kill Chain
ESAFENET CDG 3 Default Password Exploitation in 2026
In July 2026, security researchers observed increased scanning activity targeting ESAFENET's CDG 3 Document Management System, specifically exploiting default administrative credentials. ESAFENET, a company specializing in secure document management and data leakage prevention, has previously faced vulnerabilities such as SQL Injection and Cross-Site Scripting. The current scans focus on the 'secadmin' account with the default password 'Est@Spc820', which, despite meeting complexity requirements, is widely known and documented in exploit scripts. This exploitation could grant unauthorized access to sensitive documents and administrative functions, posing significant security risks. The resurgence of attacks leveraging default credentials underscores the critical need for organizations to change default passwords upon deployment. This incident highlights the ongoing threat posed by default credentials and the importance of proactive security measures to prevent unauthorized access.
2 weeks ago
Kill Chain
Illinois Man Sentenced for Hacking 750 Women's Snapchat Accounts
Between May 2020 and February 2021, Kyle Svara, a 26-year-old from Illinois, orchestrated a phishing campaign targeting over 4,500 women by impersonating a Snap Inc. representative. Utilizing anonymized phone numbers, he deceived victims into providing their Snapchat access codes, successfully compromising approximately 517 accounts to steal nude or semi-nude photos. Svara further secured these accounts by activating two-factor authentication, effectively locking out the rightful owners. The stolen images were subsequently traded or sold online. In July 2026, Svara was sentenced to 76 months in prison and three years of supervised release for his actions. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/man-gets-six-years-for-hacking-750-womens-snapchat-accounts/?utm_source=openai)) This incident underscores the persistent threat of social engineering attacks and the critical importance of user education on recognizing and resisting phishing attempts. The case also highlights the necessity for robust security measures and vigilant monitoring to protect personal data from unauthorized access and exploitation.
2 weeks ago
Kill Chain
Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts
In July 2026, cybersecurity firm ReliaQuest identified a campaign where attackers compromised Wi-Fi devices in hotels and conference centers to hijack DNS settings. This manipulation redirected users attempting to access legitimate Microsoft 365 login pages to attacker-controlled phishing sites, leading to credential theft. The campaign, active since at least June 2026, affected various sectors, including financial services, healthcare, and retail, across multiple countries such as the U.S., India, and Saudi Arabia. The attackers exploited weakly protected management interfaces or unpatched vulnerabilities in Wi-Fi gateways to gain administrative access and alter DNS configurations. This method allowed them to intercept sensitive business information and communications without direct access to the victims' devices. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/?utm_source=openai)) This incident underscores the evolving tactics of threat actors, who are increasingly targeting network infrastructure to bypass traditional endpoint security measures. The use of DNS hijacking to facilitate adversary-in-the-middle attacks highlights the need for organizations to secure all network devices, including those in transient environments like hotels and conference centers. Implementing robust security practices, such as using always-on, full-tunnel VPNs and encrypted DNS, is crucial to mitigate such threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/?utm_source=openai))
2 weeks ago
Kill Chain
Critical Vulnerability in Adobe Chrome Extension: CVE-2026-48294
In June 2026, a critical vulnerability (CVE-2026-48294) was discovered in the Adobe Acrobat PDF Extension for Chrome, affecting versions up to 26.5.2.2. This Universal Cross-Site Scripting (UXSS) flaw allowed attackers to bypass the browser's same-origin policy, enabling unauthorized access to users' session data across different web origins. Exploitation required user interaction, such as visiting a maliciously crafted URL or interacting with a compromised web page. The vulnerability posed a significant risk to user confidentiality, as it could expose sensitive information from authenticated sessions. The discovery of this vulnerability underscores the ongoing challenges in securing browser extensions, which often have elevated privileges and can interact with various web pages. It highlights the importance of rigorous security assessments and prompt patching of extensions to prevent potential data breaches and maintain user trust.
2 weeks ago
Kill Chain
Critical Vulnerability in Adobe Acrobat Chrome Extension Exposes User Data
In June 2026, a critical vulnerability (CVE-2026-48294) was identified in the Adobe Acrobat PDF Extension for Chrome, affecting versions up to 26.5.2.2. This Universal Cross-Site Scripting (UXSS) flaw allowed attackers to bypass the browser's same-origin policy, enabling unauthorized access to users' session data across different web origins. Exploitation required user interaction, such as visiting a maliciously crafted URL or interacting with a compromised webpage. The vulnerability was promptly patched by Adobe following its disclosure. The incident underscores the persistent risks associated with browser extensions, especially those with extensive user bases like Adobe Acrobat's, which boasts over 314 million users. It highlights the importance of regular security assessments and prompt patching to mitigate potential data breaches stemming from such vulnerabilities.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports