The Containment Era is here. →Explore

Industry Category

Legal Services

Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.

162 threat reports
Page 5 of 14

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Legal Services Threat Reports

Showing 4960 / 162 reports
Critical Vulnerabilities Discovered in SEPPmail Secure Email Gateway
Impact· CRITICAL

Critical Vulnerabilities Discovered in SEPPmail Secure Email Gateway

In May 2026, multiple critical vulnerabilities were identified in SEPPmail Secure Email Gateway, an enterprise-grade email security solution. These flaws, including CVE-2026-2743 (CVSS score: 10.0) and CVE-2026-44128 (CVSS score: 9.3), allowed unauthenticated remote code execution and unauthorized access to email traffic. Exploitation could lead to complete system compromise, enabling attackers to read all mail traffic and potentially use the gateway as an entry point into internal networks. ([thehackernews.com](https://thehackernews.com/2026/05/seppmail-secure-e-mail-gateway.html?utm_source=openai)) This incident underscores the persistent threat posed by vulnerabilities in email security solutions, highlighting the necessity for organizations to promptly apply security patches and conduct regular vulnerability assessments to safeguard sensitive communications.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Tycoon2FA's New Tactics: Device-Code Phishing in Microsoft 365
Impact· HIGH

Tycoon2FA's New Tactics: Device-Code Phishing in Microsoft 365

In May 2026, the Tycoon2FA phishing kit was observed employing device-code phishing attacks to compromise Microsoft 365 accounts. This method involves tricking users into entering a device authorization code on Microsoft's legitimate login page, thereby granting attackers access to the victim's data and services. Despite a prior international law enforcement operation in March 2026 that disrupted Tycoon2FA's infrastructure, the platform quickly resumed operations with enhanced obfuscation techniques to evade detection. The resurgence and evolution of Tycoon2FA underscore the persistent and adaptive nature of phishing threats. The adoption of device-code phishing highlights the need for organizations to implement robust security measures, including user education and advanced threat detection systems, to mitigate the risks associated with such sophisticated attacks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Zero-Day Vulnerability in Microsoft Exchange Server: CVE-2026-42897
Impact· MEDIUM

Critical Zero-Day Vulnerability in Microsoft Exchange Server: CVE-2026-42897

In May 2026, Microsoft disclosed a high-severity vulnerability (CVE-2026-42897) in Exchange Server, affecting versions 2016, 2019, and Subscription Edition. This cross-site scripting (XSS) flaw allows attackers to execute arbitrary JavaScript in the context of a user's browser by sending specially crafted emails, leading to potential spoofing attacks. Exploitation requires the recipient to open the email in Outlook Web Access (OWA) under specific conditions. Microsoft has confirmed active exploitation of this zero-day vulnerability in the wild. ([techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498/replies/4519822?utm_source=openai)) The urgency of this issue is underscored by the active exploitation of the vulnerability, highlighting the critical need for organizations to implement the provided mitigations promptly. The Exchange Emergency Mitigation Service (EEMS) offers automatic mitigation for affected on-premises servers, and administrators are advised to enable this service immediately to protect their systems. ([techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498/replies/4519822?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical XSS Vulnerability CVE-2026-42897 Exploited in Microsoft Exchange Server
Impact· MEDIUM

Critical XSS Vulnerability CVE-2026-42897 Exploited in Microsoft Exchange Server

In May 2026, Microsoft disclosed a critical cross-site scripting (XSS) vulnerability, CVE-2026-42897, affecting on-premises versions of Exchange Server 2016, 2019, and Subscription Edition. This flaw allows unauthorized attackers to perform spoofing attacks over a network by sending specially crafted emails. When such an email is opened in Outlook Web Access (OWA) under certain conditions, arbitrary JavaScript can be executed in the user's browser context. Microsoft confirmed active exploitation of this vulnerability in the wild, prompting immediate mitigation measures. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/15/exchange-server-cve-2026-42897-exploited/?utm_source=openai)) The urgency of addressing CVE-2026-42897 is heightened by its active exploitation and the widespread use of affected Exchange Server versions. Organizations relying on on-premises email infrastructure are at significant risk, necessitating prompt application of Microsoft's recommended mitigations to prevent potential data breaches and maintain operational integrity. ([techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498/replies/4519822?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShinyHunters Breach Exposes 275 Million Canvas Users in 2026
Impact· HIGH

ShinyHunters Breach Exposes 275 Million Canvas Users in 2026

In early May 2026, Instructure, the parent company of the Canvas learning management system, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers exploited vulnerabilities related to 'Free-For-Teacher' accounts, accessing personal information of approximately 275 million users across nearly 9,000 educational institutions worldwide. Compromised data included names, email addresses, student ID numbers, and private messages, though passwords and financial information were reportedly unaffected. The breach led to widespread disruptions, including the postponement of final exams in numerous colleges and universities. ([instructure.com](https://www.instructure.com/incident_update?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups targeting educational platforms. The timing, coinciding with critical academic periods, highlights the potential for significant operational disruptions. Educational institutions must prioritize robust cybersecurity measures to safeguard sensitive user data and ensure continuity of educational services.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Former Government Contractors Convicted for Deleting Federal Databases
Impact· HIGH

Former Government Contractors Convicted for Deleting Federal Databases

In February 2025, twin brothers Muneeb and Sohaib Akhter, both 34 and former federal contractors, were terminated from their positions after their prior felony convictions for unauthorized access to U.S. State Department systems were discovered. Immediately following their dismissal, they accessed their employer's systems without authorization, deleting approximately 96 government databases containing sensitive information, including investigative documents and Freedom of Information Act records. They also attempted to cover their tracks by seeking guidance from an AI assistant on clearing system logs and wiping company-issued laptops before returning them. This incident underscores the critical need for stringent access controls and monitoring mechanisms to prevent insider threats, especially from individuals with prior offenses. The case highlights the potential risks associated with rehiring individuals with a history of cyber offenses and the importance of comprehensive background checks and continuous monitoring to safeguard sensitive government data.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Claude Chrome Extension Exposes User Data
Impact· HIGH

Critical Vulnerability in Claude Chrome Extension Exposes User Data

In May 2026, a critical vulnerability was discovered in Anthropic's Claude AI Chrome extension, allowing any installed browser plugin to issue commands to the AI without user consent. This flaw enabled unauthorized actions such as accessing and exfiltrating sensitive data from Google Drive and GitHub repositories, effectively bypassing Chrome's extension security model. The vulnerability was reported to Anthropic on April 27, 2026, and a partial fix was released on May 6, 2026. However, researchers noted that the fix did not fully mitigate the issue, leaving some attack vectors open. This incident underscores the growing security challenges associated with integrating AI agents into web browsers, highlighting the need for robust security measures to prevent unauthorized access and data exfiltration.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Authentication Bypass Vulnerability in MOVEit Automation: CVE-2026-4670
Impact· CRITICAL

Critical Authentication Bypass Vulnerability in MOVEit Automation: CVE-2026-4670

In April 2026, Progress Software disclosed a critical authentication bypass vulnerability (CVE-2026-4670) in its MOVEit Automation managed file transfer application. This flaw allows unauthenticated remote attackers to gain unauthorized access to affected systems without user interaction. The vulnerability impacts MOVEit Automation versions prior to 2025.1.5, 2025.0.9, and 2024.1.8. Exploitation could lead to unauthorized access, administrative control, and potential data exposure. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/?utm_source=openai)) Given the widespread use of MOVEit Automation in enterprise environments, this vulnerability poses a significant risk. Organizations are urged to upgrade to the latest patched versions immediately to mitigate potential exploitation. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Progress Software Patches Critical MOVEit Automation Vulnerabilities
Impact· CRITICAL

Progress Software Patches Critical MOVEit Automation Vulnerabilities

In April 2026, Progress Software identified and patched two critical vulnerabilities in MOVEit Automation, a managed file transfer solution widely used in enterprise environments. The most severe, CVE-2026-4670, is an authentication bypass flaw with a CVSS score of 9.8, allowing unauthenticated remote attackers to gain unauthorized access. The second, CVE-2026-5174, involves improper input validation that could lead to privilege escalation. Exploitation of these vulnerabilities could result in unauthorized access, administrative control, and potential data exposure. ([thehackernews.com](https://thehackernews.com/2026/05/progress-patches-critical-moveit.html?utm_source=openai)) This incident underscores the persistent threat posed by vulnerabilities in widely deployed enterprise software. Organizations are reminded of the importance of timely patch management and vigilant monitoring to mitigate risks associated with such critical flaws.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Exploitation of Amazon SES in Phishing and BEC Attacks: A 2026 Analysis
Impact· HIGH

Exploitation of Amazon SES in Phishing and BEC Attacks: A 2026 Analysis

In early 2026, cybercriminals exploited Amazon Simple Email Service (SES) to conduct sophisticated phishing and Business Email Compromise (BEC) attacks. By leveraging exposed AWS Identity and Access Management (IAM) access keys, attackers sent large volumes of phishing emails that passed standard authentication checks, such as SPF, DKIM, and DMARC. These emails often impersonated trusted services like DocuSign, leading recipients to malicious sites designed to harvest sensitive information. The abuse of Amazon's legitimate infrastructure allowed these phishing campaigns to evade traditional email security measures, resulting in significant data breaches and financial losses for targeted organizations. This incident underscores a growing trend where attackers exploit trusted cloud services to enhance the credibility and effectiveness of their phishing campaigns. The increasing sophistication of such attacks highlights the urgent need for organizations to implement robust security measures, including strict IAM policies, regular key rotation, and comprehensive employee training to recognize and respond to phishing attempts.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
French Government Agency Breach: 15-Year-Old Detained
Impact· HIGH

French Government Agency Breach: 15-Year-Old Detained

In April 2026, the Agence Nationale des Titres Sécurisés (ANTS), responsible for issuing and managing France's official identity documents, detected unauthorized access to its systems. The breach, identified on April 15, led to the exposure of personal data—including full names, dates and places of birth, mailing and email addresses, and phone numbers—of approximately 11.7 million individuals. Shortly after, a hacker using the alias 'breach3d' advertised the sale of this data on a cybercriminal forum. French authorities have since detained a 15-year-old suspect believed to be behind the alias, facing charges related to unauthorized access and data exfiltration. This incident underscores the escalating threat posed by cybercriminals targeting government agencies to access vast amounts of sensitive personal information. The involvement of a minor highlights the accessibility of sophisticated hacking tools and the need for enhanced cybersecurity measures and public awareness to prevent such breaches and mitigate their potential impact on citizens.

2 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Insider Betrayal: Ransomware Negotiator Aids BlackCat Attacks
Impact· HIGH

Insider Betrayal: Ransomware Negotiator Aids BlackCat Attacks

In April 2026, Angelo Martino, a former ransomware negotiator at DigitalMint, pleaded guilty to conspiring with the BlackCat/ALPHV ransomware group to extort U.S. companies. Martino exploited his trusted position by providing confidential client information, such as insurance policy limits and negotiation strategies, to the attackers. This insider collaboration enabled the ransomware group to maximize their ransom demands, resulting in over $75 million in payments from victims, including a nonprofit and a financial firm. Authorities have seized more than $10 million in assets from Martino, who faces up to 20 years in prison. This case underscores the critical importance of vetting and monitoring individuals in sensitive cybersecurity roles. The incident highlights the evolving tactics of ransomware groups, including the recruitment of insiders to enhance their extortion efforts. Organizations must remain vigilant against such threats and implement robust internal controls to safeguard against insider collusion.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports