✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Legal Services
Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.
Explore Other Sectors
Legal Services Threat Reports
Zero-Click Agentic Browser Attack Wipes Google Drive (Perplexity Comet, 2025)
In December 2025, researchers from Straiker STAR Labs disclosed a zero-click browser-based attack targeting users of Perplexity's Comet browser, enabling malicious actors to erase the contents of a victim’s entire Google Drive. The attack leverages agentic browser automation capable of connecting Gmail and Google Drive accounts by abusing trusted email-based automations. Once triggered by a specially crafted email, the exploit requires no user interaction to execute the destructive action. The compromise of cloud-stored data had significant operational impact, resulting in permanent data loss for affected users and highlighting new risks for organizations relying heavily on SaaS storage platforms. This attack is significant as it demonstrates the expanding threat of zero-click vulnerabilities powered by advanced browser automation, agentic AI, and email exploits. As more organizations migrate operations and collaborative data to the cloud, the frequency and sophistication of such attacks are expected to increase, escalating the urgency for robust cloud security controls.
6 months ago
Kill Chain
Intellexa Exposed: Predator Spyware Vendor’s Secret Remote Access Unveiled (2024)
In 2024, investigative reporting revealed that Intellexa, a vendor of the Predator spyware, retained the ability to remotely access systems belonging to its own customers. Leaked training videos and multiple research publications uncovered that Intellexa could view customer surveillance logs, potentially monitoring surveillance operations and data on targeted individuals. Additional findings exposed that Intellexa exploited malicious mobile advertisements (notably the 'Aladdin' vector) to infect targets, and utilized domains imitating legitimate news sites, implicating Predator in surveillance of high-profile activists, journalists, and lawyers across Kazakhstan, Egypt, Greece, Iraq, and Pakistan. This raised serious concerns regarding human rights oversight and corporate accountability. This incident is particularly alarming due to the vendor’s persistent development of new zero-day exploits and its direct operational involvement in customer deployments. Such practices highlight significant shifts in spyware vendor behavior and raise urgent questions about regulatory readiness, digital rights, and the security of organizations relying on third-party surveillance tools.
6 months ago
Kill Chain
China’s Brickstorm Malware Campaign: The New Face of State-Level US Espionage in 2024
In 2024, U.S. and Canadian cybersecurity authorities, together with threat analysts from Google and CrowdStrike, disclosed an extensive, ongoing cyber-espionage campaign attributed to China-linked state actors known as Warp Panda and UNC5221. Utilizing the advanced Brickstorm malware, attackers achieved undetected persistence within critical infrastructure and government agency networks for an average of over a year, beginning as early as 2022. Brickstorm, targeting VMware vSphere and Windows environments, enabled stealthy lateral movement, automated reinfection, and the theft of sensitive identity and configuration data. The campaign exploited cloud misconfigurations, edge device vulnerabilities, and under-monitored zones, impacting dozens of U.S. organizations and associated downstream victims. This incident reflects the continued evolution of state-sponsored Chinese cyber-operations. Its strategic targeting, tradecraft sophistication, and stealth tactics represent persistent threats for both government and private sector organizations managing hybrid or multi-cloud environments.
6 months ago
Kill Chain
Arizona AG Files 2024 Suit Against Temu Over User Data Harvesting
In May 2024, the Arizona Attorney General filed a lawsuit against Temu, a Chinese online retailer, over allegations that its mobile app covertly accesses and collects sensitive user data from U.S. consumers without their consent. According to the suit, Temu’s app harvested extensive information—including location data, contacts, and device details—beyond what was necessary for shopping functionality by exploiting excessive permissions and transmitting this data to servers in China. The unauthorized data harvesting raised concerns about deceptive business practices, potential privacy violations, and the exposure of personal information to foreign entities with unclear data handling standards. This incident is particularly important as governments and regulators escalate actions against technology firms accused of aggressive or opaque data-collection practices. With privacy regulations and user scrutiny on the rise, the Temu case highlights the urgent need for robust compliance and modern security controls to guard against stealthy apps harvesting sensitive information at scale.
6 months ago
Kill Chain
Insider Threat at Opexus: Twin Contractors Breach US Federal Agency Data in 2024
In February 2024, twin brothers Muneeb and Sohaib Akhter exploited their privileged positions as contractors at Opexus, a government IT provider, to compromise, steal, and destroy sensitive data belonging to more than 45 federal agencies, including the Department of Homeland Security, IRS, and EEOC. The attack occurred minutes after the brothers were terminated, leveraging insider access to delete 96 critical databases, extract personally identifiable information, and disrupt ongoing investigations. Their methods reportedly included using AI to cover their tracks by clearing system and audit logs. The incident triggered a major federal investigation and prompted urgent responses from affected agencies, highlighting the impact of trusted insider abuse on national operations. This breach exemplifies a growing trend of insider threats exploiting technical know-how and elevated access during termination events, intensified by the use of generative AI tools to evade detection. The case underscores the critical need for organizations handling sensitive federal data to implement rigorous access controls, continuous monitoring, and rapid offboarding processes to mitigate potential insider-driven damage.
6 months ago
Kill Chain
ToddyCat APT: How a Persistent Attacker Breached Outlook and Microsoft 365 Email in 2024
Between mid-2024 and early 2025, the ToddyCat advanced persistent threat (APT) group executed a sophisticated campaign targeting organizations' internal infrastructures to covertly access business email. Initially leveraging a new PowerShell variant of their TomBerBil tool to extract credentials, cookies, and encryption keys from browsers via SMB on privileged hosts, the group also introduced additional tools—TCSectorCopy and XstReader—to capture locked Outlook OST files and exfiltrate their contents. When detection increased, ToddyCat shifted to harvesting OAuth 2.0 tokens for Microsoft 365 mail through memory dumping, enhancing their ability to bypass on-host monitoring and access cloud emails externally. This campaign resulted in extensive compromise of sensitive correspondence, credentials, and lateral movement across impacted domains. This incident underscores the rapidly evolving tactics of nation-state groups to overcome modern defenses, highlighting trends in cross-cloud compromise, credential harvesting, and exploitation of endpoint-to-cloud trust boundaries. ToddyCat's use of both system-level and identity-driven attacks mirrors the increasing prevalence of multifaceted cyber threat techniques.
6 months ago
Kill Chain
Pennsylvania Attorney General Hit by Ransomware: 2025 Data Breach Exposes Medical Information
In August 2025, the office of Pennsylvania's Attorney General fell victim to a ransomware attack orchestrated by the INC Ransom group. Attackers infiltrated internal networks and subsequently encrypted critical systems, ultimately exfiltrating files containing sensitive information, including personal and medical data belonging to individuals engaged with the office. The breach disrupted business operations and prompted an immediate investigation and regulatory disclosure. Investigators found that the attackers leveraged privilege escalation, moved laterally within the network, and evaded basic security controls, showcasing the advanced tactics employed by today’s ransomware operators. This incident highlights the growing threat of sophisticated ransomware gangs targeting public sector entities, expanding their focus to sensitive government-held data. The frequency and impact of ransomware incidents on critical services underscore an urgent need for robust segmentation, modern encryption, and relentless threat monitoring.
6 months ago
Kill Chain
CometJacking: How Prompt Injection Breached Perplexity AI’s Browser in 2025
In November 2025, cybersecurity researchers discovered a significant prompt injection vulnerability dubbed 'CometJacking' affecting Perplexity’s Comet AI browser. This attack exploited URL parameters to inject malicious commands that instructed the AI agent to extract sensitive data—such as Gmail messages and Google Calendar invites—from connected services and exfiltrate them to external endpoints, all without any user interaction or credentials. By leveraging the AI’s lack of discrimination between trusted and untrusted instructions, attackers could bypass access controls and evade existing security checks, potentially exposing confidential information from a wide set of users and organizations adopting the AI-powered browser for daily workflows. This incident highlights a rapidly evolving threat landscape where prompt injection attacks against generative AI platforms are surging. As organizations increasingly integrate AI agents with sensitive data and workflow automation, risks of unauthorized data access and exfiltration are escalating, prompting urgent action from security teams and regulatory bodies.
6 months ago
Kill Chain
Microsoft's 'Whisper Leak' Side-Channel Attack Bypasses Encryption for AI Traffic
In late 2025, Microsoft researchers uncovered the 'Whisper Leak' side-channel attack, a novel method allowing passive adversaries to deduce the topics of conversations with streaming AI language models despite the use of encrypted, high-performance network protocols. Attackers exploited traffic analysis techniques, observing packet timing and size patterns, to infer sensitive discussion details traversing enterprise VPNs and encrypted links. Although private circuit encryption such as MACsec and IPsec was in place, the attack effectively bypassed traditional data-in-transit security controls, raising concerns for sectors leveraging AI in sensitive communications. This incident is significant as it highlights an emerging risk where encrypted cloud AI traffic can be compromised via sophisticated traffic analysis, just as generative AI adoption is surging across regulated industries. It illustrates evolving attacker sophistication beyond classical exploits, prompting urgent review of AI data security and zero trust segmentation strategies.
6 months ago
Kill Chain
Multiple ChatGPT Security Bugs Expose User Data in 2023 OpenAI Breach
In March 2023, OpenAI faced a significant application security incident involving multiple vulnerabilities within its flagship ChatGPT platform. Attackers exploited bugs that enabled prompt injection, retrieval of other users’ conversation histories, and potential bypassing of safety restrictions, exposing sensitive user data and proprietary prompts. These exploits, which allowed lateral movement and unauthorized data exfiltration, highlighted systemic issues in handling session tokens, API security, and isolation of user environments. The breaches forced OpenAI to temporarily take ChatGPT offline, conduct emergency patching, notify users, and engage external security review. The operational impact included reputational damage and increased regulatory scrutiny over cloud-based AI platforms’ data handling. This event underscores the growing risk as generative AI platforms become integral to business operations and personal productivity. The use of increasingly complex APIs and reliance on cloud-native architecture have introduced new attack surfaces, making timely detection and robust segmentation critical. Regulatory bodies and security practitioners now regard application-layer lateral movement and API leakage as top-tier threats, especially given AI’s centrality to enterprise workflows.
6 months ago
Kill Chain
Gootloader Malware Loader Strikes Back: 2024 SEO Poisoning Campaign Unveiled
In early June 2024, cybersecurity researchers reported the resurgence of the Gootloader malware loader after a seven-month hiatus. The campaign utilizes SEO poisoning tactics to drive unsuspecting users to fraudulent websites that appear in popular search engine results. Once on these sites, victims are tricked into downloading malicious files, which Gootloader then leverages to install additional malware payloads such as ransomware or information stealers. This renewed activity demonstrates a continued evolution of the Gootloader group’s techniques, making detection and prevention difficult for organizations. The impact spans both enterprise and individual users, increasing risks of data theft, ransomware infections, and business disruptions. This campaign’s return highlights an alarming trend: threat actors are rapidly enhancing their distribution channels using social engineering and search engine manipulation. As cybercriminals adapt faster than many organizations secure their environments, it is urgent to reassess security controls, training, and detection reliability against loader-based threats.
6 months ago
Kill Chain
ChatGPT 2025 Vulnerabilities: How AI Memory Leaks Put Data at Risk
In November 2025, cybersecurity researchers uncovered and disclosed a set of seven critical vulnerabilities affecting OpenAI's ChatGPT, specifically the GPT-4o and GPT-5 models. The vulnerabilities allowed attackers to exploit memory and chat history mechanisms, enabling the unauthorized extraction of sensitive user information—including personal data and confidential conversation content—without user awareness. The flaws could be triggered remotely through crafted prompts and API calls, presenting a considerable risk both to individuals and enterprises leveraging ChatGPT in production environments. OpenAI has issued patches and advisories, but the revelations highlight the rapid evolution and complexity of securing AI models at scale. This incident is especially significant given the increasing reliance on generative AI in business workflows and the concurrent surge in attacks targeting AI-powered infrastructure. With regulatory scrutiny intensifying around AI data handling and the advent of new compliance frameworks, protecting AI systems against data leakage has become a board-level imperative.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports