✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Legal Services
Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.
Explore Other Sectors
Legal Services Threat Reports
Ernst & Young Data Breach Exposes Client Tax Information in 2026
In April 2026, Ernst & Young (EY) identified unauthorized access to a third-party IT service management platform used for client tax services. The breach occurred between March 28 and April 12, 2026, during which attackers downloaded documents containing personal and financial information used in tax filings. EY promptly secured the affected systems, notified federal law enforcement, and offered 24 months of identity monitoring services to impacted clients. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/?utm_source=openai)) This incident underscores the critical need for robust third-party risk management, especially as organizations increasingly rely on external platforms for sensitive operations. The breach highlights the importance of continuous monitoring and rapid response strategies to mitigate potential damages from such compromises.
1 day ago
Kill Chain
ACR Stealer's ClickFix Campaign: A Wake-Up Call for Cybersecurity
In mid-2026, the ACR Stealer malware exploited ClickFix social engineering tactics to infiltrate enterprise networks. By deceiving users into executing commands via fake verification prompts, attackers deployed two primary infection chains: one utilizing WebDAV and PowerShell scripts, and another employing mshta.exe with obfuscated PowerShell. Both methods aimed to exfiltrate browser-stored credentials, session tokens, and sensitive Microsoft 365 documents, including files from OneDrive and SharePoint. This incident underscores a significant shift towards sophisticated social engineering attacks that bypass traditional security measures. The reliance on user interaction highlights the critical need for enhanced user awareness and robust endpoint protection strategies to mitigate such threats.
1 day ago
Kill Chain
Critical Vulnerability in Claude Chrome Extension Exposes User Data
In July 2026, a critical vulnerability was discovered in Anthropic's Claude for Chrome browser extension. This flaw allowed malicious extensions to simulate user interactions, triggering predefined AI actions without user consent. Exploiting this, attackers could access connected services such as Gmail, Google Docs, Google Calendar, and Salesforce, leading to unauthorized data access and potential data exfiltration. The vulnerability stemmed from the extension's failure to verify the origin of click events, accepting synthetic events generated by other extensions as legitimate user actions. This incident underscores the growing risks associated with browser extensions and their integration with AI-powered services. As organizations increasingly adopt such tools to enhance productivity, ensuring robust security measures and thorough validation of user interactions becomes imperative to prevent unauthorized access and data breaches.
2 days ago
Kill Chain
Zoom Addresses Critical Windows Vulnerability CVE-2026-53412
In July 2026, Zoom addressed a critical vulnerability (CVE-2026-53412) in its Windows clients, including Zoom Desktop Client, Zoom VDI Client, and Zoom Meeting SDK. This flaw, stemming from improper input validation, could allow unauthenticated attackers to take over user accounts via network access. The vulnerability received a CVSS score of 9.8, indicating its severity. Users are urged to update to the latest versions to mitigate this risk. The incident underscores the importance of timely software updates and robust input validation practices. With the increasing reliance on virtual communication platforms, such vulnerabilities pose significant risks to user security and privacy. Organizations must remain vigilant and proactive in applying security patches to prevent potential exploits.
2 days ago
Kill Chain
Emerging Phishing Kits Bypass MFA to Compromise Microsoft 365 Accounts
In July 2026, cybersecurity researchers identified two sophisticated phishing kits, Jalisco and OmegaLord, targeting Microsoft 365 accounts. Jalisco employs device-code phishing by generating real-time OAuth device codes, tricking users into authorizing attacker-controlled devices. OmegaLord masquerades as a PDF reader to harvest login credentials and phone numbers, potentially intercepting MFA codes. Both methods effectively bypass multi-factor authentication, granting attackers unauthorized access to sensitive data stored in services like SharePoint and other SaaS platforms. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/?utm_source=openai)) This incident underscores the evolving nature of phishing attacks, highlighting the need for organizations to reassess and strengthen their authentication mechanisms. The emergence of such advanced phishing kits indicates a trend towards more sophisticated social engineering tactics capable of circumventing traditional security measures.
4 days ago
Kill Chain
Phishing Alert: LastPass and Bitwarden Users Targeted in July 2026
In July 2026, a sophisticated phishing campaign targeted users of LastPass and Bitwarden, two prominent password management services. Attackers sent emails from addresses like 'hello@lastpassnewsletter.com' and 'hello@bitwardennewsletter.com', falsely notifying recipients of updated security policies. These emails directed users to fraudulent websites impersonating DocuSign, prompting them to download malicious files purportedly compatible with both Windows and macOS systems. The domains used, such as 'lastpasscompliance[.]com' and 'bitwardencompliance[.]com', were flagged as malicious by security services. LastPass confirmed that its systems remained uncompromised and that the phishing emails did not originate from its infrastructure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/?utm_source=openai)) This incident underscores a growing trend of cybercriminals targeting password manager users through sophisticated phishing tactics. The use of legitimate-looking emails and websites to deceive users highlights the need for heightened vigilance and robust security measures. Organizations and individuals must remain alert to such evolving threats to safeguard sensitive information.
4 days ago
Kill Chain
Critical Zero-Day Vulnerability in Progress ShareFile: A Wake-Up Call for Cybersecurity
In July 2026, Progress Software identified a high-severity zero-day vulnerability in its ShareFile Storage Zone Controllers, affecting versions 5.x and 6.x. This path traversal flaw allowed authenticated administrative users to read arbitrary files, write malicious content to directories, and enumerate the server's filesystem layout. Upon discovery, Progress promptly released patched versions 5.12.5 and 6.0.2 to mitigate the issue. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/?utm_source=openai)) This incident underscores the critical importance of timely patch management and proactive vulnerability assessments. Organizations are reminded to regularly update their systems and monitor for emerging threats to safeguard sensitive data and maintain operational integrity.
4 days ago
Kill Chain
Critical Vulnerability in 'Claude for Chrome' Exposes User Data
In July 2026, security researchers identified a critical vulnerability in Anthropic's 'Claude for Chrome' extension, allowing malicious browser extensions to exploit Claude's automation capabilities. This flaw enables unauthorized access to sensitive user data, including Gmail, Google Docs, and Calendar, by triggering tasks without user consent. Despite previous mitigation efforts, the vulnerability persists in version 1.0.80, posing significant security risks to users. The incident underscores the growing threat of prompt injection attacks targeting AI-powered browser extensions. As AI tools become more integrated into daily workflows, ensuring robust security measures and user awareness is paramount to prevent unauthorized data access and maintain user trust.
4 days ago
Kill Chain
Forg365 PhaaS: A New Threat to Microsoft 365 Security
In July 2026, a new phishing-as-a-service (PhaaS) platform named Forg365 emerged, targeting Microsoft 365 accounts. Forg365 employs a combination of device code phishing, adversary-in-the-middle (AiTM) tactics, AI-assisted lure creation, and post-compromise mailbox operations. Distributed via Telegram, the service costs $400 per month or $3,800 annually. Attackers utilize legitimate email delivery services like Amazon SES and Twilio SendGrid to craft convincing phishing emails, leading victims to Forg365-controlled domains. The platform's operator panel offers features such as AI-generated phishing emails, campaign management, and a browser extension named ForgCookie, which maintains persistent access to compromised accounts by refreshing Microsoft single sign-on cookies. The emergence of Forg365 underscores the increasing sophistication and accessibility of phishing tools, enabling even low-skilled threat actors to execute complex attacks. This trend highlights the urgent need for organizations to enhance their email security measures, implement robust multi-factor authentication, and educate users about evolving phishing tactics to mitigate the risk of account compromise.
5 days ago
Kill Chain
MemGhost Attack: A New Threat to AI Assistant Security
In July 2026, cybersecurity researchers identified a novel attack vector named 'MemGhost,' which exploits AI assistants equipped with persistent memory. By sending a single, specially crafted email, attackers can implant false information into the assistant's memory without user detection. This manipulation allows the AI to provide altered responses in future interactions, potentially leading to misinformation or unauthorized actions. The attack leverages the assistant's ability to autonomously process emails and update its knowledge base, making it particularly insidious. The MemGhost attack underscores the emerging vulnerabilities associated with AI systems that maintain long-term user data. As AI assistants become more integrated into daily workflows, the potential for such memory poisoning attacks increases, highlighting the need for robust security measures to protect against unauthorized data manipulation.
5 days ago
Kill Chain
Insider Threats: Cybersecurity Experts Turned Cybercriminals
In 2023, three U.S. cybersecurity professionals—Ryan Goldberg, Kevin Martin, and Angelo Martino—exploited their insider knowledge to conduct ransomware attacks using the ALPHV/BlackCat variant. Operating between April and December, they targeted multiple organizations, including a medical device company, a pharmaceutical firm, and a drone manufacturer. The trio encrypted victims' data and demanded substantial cryptocurrency ransoms, successfully extorting approximately $1.2 million from one victim. Their actions culminated in guilty pleas and subsequent prison sentences of four years each. ([justice.gov](https://www.justice.gov/opa/pr/two-americans-who-attacked-multiple-us-victims-using-alphv-blackcat-ransomware-sentenced?utm_source=openai)) This case underscores a disturbing trend where trusted insiders leverage their positions for malicious gain, highlighting the critical need for robust internal security measures and continuous monitoring to detect and prevent such insider threats.
1 week ago
Kill Chain
Progress ShareFile SZC Vulnerabilities: A 2026 Security Wake-Up Call
In April 2026, critical vulnerabilities were discovered in Progress Software's ShareFile Storage Zones Controller (SZC), specifically CVE-2026-2699 and CVE-2026-2701. These flaws allowed unauthenticated attackers to access restricted configuration pages and execute arbitrary code on affected systems. Despite the release of patches in March 2026, by July 2026, credible external threats targeting unpatched SZC instances prompted Progress to advise customers to immediately shut down their servers to prevent potential data breaches. This incident underscores the persistent risks associated with unpatched software vulnerabilities, especially in widely used enterprise solutions. Organizations are reminded of the importance of timely patch management and proactive security measures to mitigate evolving cyber threats.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports