✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Legal Services
Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.
Explore Other Sectors
Legal Services Threat Reports
Critical Zero-Day Vulnerability in Progress ShareFile: A Wake-Up Call for Cybersecurity
In July 2026, Progress Software identified a high-severity zero-day vulnerability in its ShareFile Storage Zone Controllers, affecting versions 5.x and 6.x. This path traversal flaw allowed authenticated administrative users to read arbitrary files, write malicious content to directories, and enumerate the server's filesystem layout. Upon discovery, Progress promptly released patched versions 5.12.5 and 6.0.2 to mitigate the issue. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/?utm_source=openai)) This incident underscores the critical importance of timely patch management and proactive vulnerability assessments. Organizations are reminded to regularly update their systems and monitor for emerging threats to safeguard sensitive data and maintain operational integrity.
1 week ago
Kill Chain
Critical Vulnerability in 'Claude for Chrome' Exposes User Data
In July 2026, security researchers identified a critical vulnerability in Anthropic's 'Claude for Chrome' extension, allowing malicious browser extensions to exploit Claude's automation capabilities. This flaw enables unauthorized access to sensitive user data, including Gmail, Google Docs, and Calendar, by triggering tasks without user consent. Despite previous mitigation efforts, the vulnerability persists in version 1.0.80, posing significant security risks to users. The incident underscores the growing threat of prompt injection attacks targeting AI-powered browser extensions. As AI tools become more integrated into daily workflows, ensuring robust security measures and user awareness is paramount to prevent unauthorized data access and maintain user trust.
1 week ago
Kill Chain
Forg365 PhaaS: A New Threat to Microsoft 365 Security
In July 2026, a new phishing-as-a-service (PhaaS) platform named Forg365 emerged, targeting Microsoft 365 accounts. Forg365 employs a combination of device code phishing, adversary-in-the-middle (AiTM) tactics, AI-assisted lure creation, and post-compromise mailbox operations. Distributed via Telegram, the service costs $400 per month or $3,800 annually. Attackers utilize legitimate email delivery services like Amazon SES and Twilio SendGrid to craft convincing phishing emails, leading victims to Forg365-controlled domains. The platform's operator panel offers features such as AI-generated phishing emails, campaign management, and a browser extension named ForgCookie, which maintains persistent access to compromised accounts by refreshing Microsoft single sign-on cookies. The emergence of Forg365 underscores the increasing sophistication and accessibility of phishing tools, enabling even low-skilled threat actors to execute complex attacks. This trend highlights the urgent need for organizations to enhance their email security measures, implement robust multi-factor authentication, and educate users about evolving phishing tactics to mitigate the risk of account compromise.
1 week ago
Kill Chain
MemGhost Attack: A New Threat to AI Assistant Security
In July 2026, cybersecurity researchers identified a novel attack vector named 'MemGhost,' which exploits AI assistants equipped with persistent memory. By sending a single, specially crafted email, attackers can implant false information into the assistant's memory without user detection. This manipulation allows the AI to provide altered responses in future interactions, potentially leading to misinformation or unauthorized actions. The attack leverages the assistant's ability to autonomously process emails and update its knowledge base, making it particularly insidious. The MemGhost attack underscores the emerging vulnerabilities associated with AI systems that maintain long-term user data. As AI assistants become more integrated into daily workflows, the potential for such memory poisoning attacks increases, highlighting the need for robust security measures to protect against unauthorized data manipulation.
1 week ago
Kill Chain
Insider Threats: Cybersecurity Experts Turned Cybercriminals
In 2023, three U.S. cybersecurity professionals—Ryan Goldberg, Kevin Martin, and Angelo Martino—exploited their insider knowledge to conduct ransomware attacks using the ALPHV/BlackCat variant. Operating between April and December, they targeted multiple organizations, including a medical device company, a pharmaceutical firm, and a drone manufacturer. The trio encrypted victims' data and demanded substantial cryptocurrency ransoms, successfully extorting approximately $1.2 million from one victim. Their actions culminated in guilty pleas and subsequent prison sentences of four years each. ([justice.gov](https://www.justice.gov/opa/pr/two-americans-who-attacked-multiple-us-victims-using-alphv-blackcat-ransomware-sentenced?utm_source=openai)) This case underscores a disturbing trend where trusted insiders leverage their positions for malicious gain, highlighting the critical need for robust internal security measures and continuous monitoring to detect and prevent such insider threats.
2 weeks ago
Kill Chain
Progress ShareFile SZC Vulnerabilities: A 2026 Security Wake-Up Call
In April 2026, critical vulnerabilities were discovered in Progress Software's ShareFile Storage Zones Controller (SZC), specifically CVE-2026-2699 and CVE-2026-2701. These flaws allowed unauthenticated attackers to access restricted configuration pages and execute arbitrary code on affected systems. Despite the release of patches in March 2026, by July 2026, credible external threats targeting unpatched SZC instances prompted Progress to advise customers to immediately shut down their servers to prevent potential data breaches. This incident underscores the persistent risks associated with unpatched software vulnerabilities, especially in widely used enterprise solutions. Organizations are reminded of the importance of timely patch management and proactive security measures to mitigate evolving cyber threats.
2 weeks ago
Kill Chain
Urgent Advisory: Progress ShareFile Security Threat Necessitates Immediate Action
In July 2026, Progress Software identified a critical security threat affecting ShareFile Storage Zone Controllers, leading to an immediate advisory for customers to shut down their Windows servers running these controllers. This precautionary measure was taken to prevent potential unauthorized access and data breaches. The company is collaborating with internal and external security experts to investigate the threat and has temporarily disabled access to affected accounts as a safeguard. This incident underscores the persistent vulnerabilities in file transfer solutions, reminiscent of previous exploits targeting similar systems. Organizations are urged to remain vigilant, apply security patches promptly, and monitor for any signs of compromise to mitigate the risk of data breaches and maintain operational integrity.
2 weeks ago
Kill Chain
Cybersecurity Professional Sentenced for Aiding Ransomware Attacks
In July 2026, Angelo Martino, a 41-year-old former ransomware negotiator from Florida, was sentenced to 70 months in prison for conspiring with the BlackCat ransomware group. Between April and November 2023, Martino exploited his position by leaking confidential information from five U.S. companies he was hired to protect, including cyber insurance limits and internal negotiation strategies. This betrayal enabled BlackCat to extort over $75 million from victims, including a nonprofit ($26.8M) and a financial firm ($25.6M). Additionally, Martino directly assisted in deploying ransomware attacks, demanding over $16 million and personally laundering $1.2 million in Bitcoin. Authorities seized more than $10 million in assets from him, including cryptocurrency, vehicles, and property. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/florida-man-pleads-guilty-after-leaking-victims-insurance-details-to-blackcat-hackers?utm_source=openai)) This case underscores the critical importance of trust and integrity within the cybersecurity industry. The exploitation of insider knowledge for malicious purposes highlights the need for stringent vetting processes and continuous monitoring of individuals in sensitive roles. Organizations must remain vigilant against both external threats and potential internal vulnerabilities to safeguard their operations and data.
2 weeks ago
Kill Chain
Forg365: AI-Driven Phishing Platform Targets Microsoft 365 Accounts
In July 2026, a new phishing-as-a-service (PhaaS) platform named Forg365 emerged, targeting Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code phishing techniques with AI-assisted lure generation. The platform offers a browser extension that maintains access to compromised accounts without re-authentication. Researchers at ZeroBEC identified features in Forg365 similar to those in other PhaaS platforms like Kali365 and Sneaky2FA, indicating a sophisticated operation capable of blending malicious activities into regular email traffic. The integration of AI in Forg365's dashboard allows attackers to craft and refine phishing emails efficiently, reducing the cost and complexity of developing custom phishing content. This advancement underscores the evolving threat landscape, where AI is increasingly leveraged to enhance the effectiveness and accessibility of cyberattacks, posing significant challenges to traditional security measures.
2 weeks ago
Kill Chain
Understanding and Mitigating System Prompt Leakage in AI Applications
In July 2026, AWS Security highlighted the persistent issue of system prompt leakage in generative AI applications. System prompts, which guide the behavior of large language models (LLMs), often contain sensitive information such as role definitions, behavioral guidelines, and API responses. Threat actors can exploit vulnerabilities to extract these prompts, potentially exposing proprietary data and compromising application integrity. Despite various mitigation strategies, complete remediation remains elusive due to inherent limitations in current AI systems. This underscores the need for continuous vigilance and adaptive security measures in AI deployments. The increasing prevalence of system prompt leakage incidents, as noted in the 2025 OWASP LLM Top 10, reflects a broader trend of sophisticated attacks targeting AI systems. Organizations must prioritize robust security frameworks to safeguard against evolving threats in the AI landscape.
2 weeks ago
Kill Chain
Expansion of Deepfake CSAM Lawsuit Targets xAI and Stability AI
In July 2026, a class-action lawsuit against xAI, the developer of the AI tool Grok, was expanded to include two additional plaintiffs. These individuals allege that Grok was used by acquaintances to generate nonconsensual deepfake child sexual abuse material (CSAM) based on their real photos. The lawsuit also names Stability AI as a defendant, claiming that its Stable Diffusion model facilitated the creation of such illicit content. The plaintiffs report significant emotional distress and a loss of control over the dissemination of these images. This incident underscores the urgent need for robust safeguards in AI technologies to prevent misuse, particularly in generating harmful content. It highlights the growing legal and ethical challenges companies face in ensuring their AI models are not exploited for creating nonconsensual and illegal material.
2 weeks ago
Kill Chain
DEBULL Exploits Microsoft Device-Code Flow in Recent Phishing Campaign
Between late June and early July 2026, a sophisticated phishing campaign leveraging the DEBULL tooling targeted Microsoft 365 accounts. Unlike traditional phishing methods, this campaign utilized collaboration-themed lures to direct users into the legitimate Microsoft device login experience. By exploiting the OAuth 2.0 Device Authorization Grant flow, attackers bypassed multi-factor authentication (MFA) and gained unauthorized access to victim accounts. The DEBULL platform, likely a phishing-as-a-service (PhaaS) offering, enabled threat actors to generate and poll device-code tokens, facilitating account takeovers without the need for password theft. This method allowed for persistent access, leading to potential data exfiltration and further exploitation within compromised environments. ([thehackernews.com](https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.html?utm_source=openai)) The emergence of DEBULL signifies a notable evolution in phishing tactics, emphasizing the shift towards abusing legitimate authentication processes to circumvent traditional security measures. This trend underscores the necessity for organizations to enhance their security protocols, particularly in monitoring and mitigating risks associated with OAuth flows and device code authentication mechanisms. ([thehackernews.com](https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.html?utm_source=openai))
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports