✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Legal Services
Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.
Explore Other Sectors
Legal Services Threat Reports
Critical Vulnerabilities Discovered in SEPPmail Secure Email Gateway
In May 2026, multiple critical vulnerabilities were identified in SEPPmail Secure Email Gateway, an enterprise-grade email security solution. These flaws, including CVE-2026-2743 (CVSS score: 10.0) and CVE-2026-44128 (CVSS score: 9.3), allowed unauthenticated remote code execution and unauthorized access to email traffic. Exploitation could lead to complete system compromise, enabling attackers to read all mail traffic and potentially use the gateway as an entry point into internal networks. ([thehackernews.com](https://thehackernews.com/2026/05/seppmail-secure-e-mail-gateway.html?utm_source=openai)) This incident underscores the persistent threat posed by vulnerabilities in email security solutions, highlighting the necessity for organizations to promptly apply security patches and conduct regular vulnerability assessments to safeguard sensitive communications.
2 months ago
Kill Chain
Tycoon2FA's New Tactics: Device-Code Phishing in Microsoft 365
In May 2026, the Tycoon2FA phishing kit was observed employing device-code phishing attacks to compromise Microsoft 365 accounts. This method involves tricking users into entering a device authorization code on Microsoft's legitimate login page, thereby granting attackers access to the victim's data and services. Despite a prior international law enforcement operation in March 2026 that disrupted Tycoon2FA's infrastructure, the platform quickly resumed operations with enhanced obfuscation techniques to evade detection. The resurgence and evolution of Tycoon2FA underscore the persistent and adaptive nature of phishing threats. The adoption of device-code phishing highlights the need for organizations to implement robust security measures, including user education and advanced threat detection systems, to mitigate the risks associated with such sophisticated attacks.
2 months ago
Kill Chain
Critical Zero-Day Vulnerability in Microsoft Exchange Server: CVE-2026-42897
In May 2026, Microsoft disclosed a high-severity vulnerability (CVE-2026-42897) in Exchange Server, affecting versions 2016, 2019, and Subscription Edition. This cross-site scripting (XSS) flaw allows attackers to execute arbitrary JavaScript in the context of a user's browser by sending specially crafted emails, leading to potential spoofing attacks. Exploitation requires the recipient to open the email in Outlook Web Access (OWA) under specific conditions. Microsoft has confirmed active exploitation of this zero-day vulnerability in the wild. ([techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498/replies/4519822?utm_source=openai)) The urgency of this issue is underscored by the active exploitation of the vulnerability, highlighting the critical need for organizations to implement the provided mitigations promptly. The Exchange Emergency Mitigation Service (EEMS) offers automatic mitigation for affected on-premises servers, and administrators are advised to enable this service immediately to protect their systems. ([techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498/replies/4519822?utm_source=openai))
2 months ago
Kill Chain
Critical XSS Vulnerability CVE-2026-42897 Exploited in Microsoft Exchange Server
In May 2026, Microsoft disclosed a critical cross-site scripting (XSS) vulnerability, CVE-2026-42897, affecting on-premises versions of Exchange Server 2016, 2019, and Subscription Edition. This flaw allows unauthorized attackers to perform spoofing attacks over a network by sending specially crafted emails. When such an email is opened in Outlook Web Access (OWA) under certain conditions, arbitrary JavaScript can be executed in the user's browser context. Microsoft confirmed active exploitation of this vulnerability in the wild, prompting immediate mitigation measures. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/15/exchange-server-cve-2026-42897-exploited/?utm_source=openai)) The urgency of addressing CVE-2026-42897 is heightened by its active exploitation and the widespread use of affected Exchange Server versions. Organizations relying on on-premises email infrastructure are at significant risk, necessitating prompt application of Microsoft's recommended mitigations to prevent potential data breaches and maintain operational integrity. ([techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498/replies/4519822?utm_source=openai))
2 months ago
Kill Chain
ShinyHunters Breach Exposes 275 Million Canvas Users in 2026
In early May 2026, Instructure, the parent company of the Canvas learning management system, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers exploited vulnerabilities related to 'Free-For-Teacher' accounts, accessing personal information of approximately 275 million users across nearly 9,000 educational institutions worldwide. Compromised data included names, email addresses, student ID numbers, and private messages, though passwords and financial information were reportedly unaffected. The breach led to widespread disruptions, including the postponement of final exams in numerous colleges and universities. ([instructure.com](https://www.instructure.com/incident_update?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups targeting educational platforms. The timing, coinciding with critical academic periods, highlights the potential for significant operational disruptions. Educational institutions must prioritize robust cybersecurity measures to safeguard sensitive user data and ensure continuity of educational services.
2 months ago
Kill Chain
Former Government Contractors Convicted for Deleting Federal Databases
In February 2025, twin brothers Muneeb and Sohaib Akhter, both 34 and former federal contractors, were terminated from their positions after their prior felony convictions for unauthorized access to U.S. State Department systems were discovered. Immediately following their dismissal, they accessed their employer's systems without authorization, deleting approximately 96 government databases containing sensitive information, including investigative documents and Freedom of Information Act records. They also attempted to cover their tracks by seeking guidance from an AI assistant on clearing system logs and wiping company-issued laptops before returning them. This incident underscores the critical need for stringent access controls and monitoring mechanisms to prevent insider threats, especially from individuals with prior offenses. The case highlights the potential risks associated with rehiring individuals with a history of cyber offenses and the importance of comprehensive background checks and continuous monitoring to safeguard sensitive government data.
2 months ago
Kill Chain
Critical Vulnerability in Claude Chrome Extension Exposes User Data
In May 2026, a critical vulnerability was discovered in Anthropic's Claude AI Chrome extension, allowing any installed browser plugin to issue commands to the AI without user consent. This flaw enabled unauthorized actions such as accessing and exfiltrating sensitive data from Google Drive and GitHub repositories, effectively bypassing Chrome's extension security model. The vulnerability was reported to Anthropic on April 27, 2026, and a partial fix was released on May 6, 2026. However, researchers noted that the fix did not fully mitigate the issue, leaving some attack vectors open. This incident underscores the growing security challenges associated with integrating AI agents into web browsers, highlighting the need for robust security measures to prevent unauthorized access and data exfiltration.
2 months ago
Kill Chain
Critical Authentication Bypass Vulnerability in MOVEit Automation: CVE-2026-4670
In April 2026, Progress Software disclosed a critical authentication bypass vulnerability (CVE-2026-4670) in its MOVEit Automation managed file transfer application. This flaw allows unauthenticated remote attackers to gain unauthorized access to affected systems without user interaction. The vulnerability impacts MOVEit Automation versions prior to 2025.1.5, 2025.0.9, and 2024.1.8. Exploitation could lead to unauthorized access, administrative control, and potential data exposure. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/?utm_source=openai)) Given the widespread use of MOVEit Automation in enterprise environments, this vulnerability poses a significant risk. Organizations are urged to upgrade to the latest patched versions immediately to mitigate potential exploitation. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/?utm_source=openai))
2 months ago
Kill Chain
Progress Software Patches Critical MOVEit Automation Vulnerabilities
In April 2026, Progress Software identified and patched two critical vulnerabilities in MOVEit Automation, a managed file transfer solution widely used in enterprise environments. The most severe, CVE-2026-4670, is an authentication bypass flaw with a CVSS score of 9.8, allowing unauthenticated remote attackers to gain unauthorized access. The second, CVE-2026-5174, involves improper input validation that could lead to privilege escalation. Exploitation of these vulnerabilities could result in unauthorized access, administrative control, and potential data exposure. ([thehackernews.com](https://thehackernews.com/2026/05/progress-patches-critical-moveit.html?utm_source=openai)) This incident underscores the persistent threat posed by vulnerabilities in widely deployed enterprise software. Organizations are reminded of the importance of timely patch management and vigilant monitoring to mitigate risks associated with such critical flaws.
2 months ago
Kill Chain
Exploitation of Amazon SES in Phishing and BEC Attacks: A 2026 Analysis
In early 2026, cybercriminals exploited Amazon Simple Email Service (SES) to conduct sophisticated phishing and Business Email Compromise (BEC) attacks. By leveraging exposed AWS Identity and Access Management (IAM) access keys, attackers sent large volumes of phishing emails that passed standard authentication checks, such as SPF, DKIM, and DMARC. These emails often impersonated trusted services like DocuSign, leading recipients to malicious sites designed to harvest sensitive information. The abuse of Amazon's legitimate infrastructure allowed these phishing campaigns to evade traditional email security measures, resulting in significant data breaches and financial losses for targeted organizations. This incident underscores a growing trend where attackers exploit trusted cloud services to enhance the credibility and effectiveness of their phishing campaigns. The increasing sophistication of such attacks highlights the urgent need for organizations to implement robust security measures, including strict IAM policies, regular key rotation, and comprehensive employee training to recognize and respond to phishing attempts.
2 months ago
Kill Chain
French Government Agency Breach: 15-Year-Old Detained
In April 2026, the Agence Nationale des Titres Sécurisés (ANTS), responsible for issuing and managing France's official identity documents, detected unauthorized access to its systems. The breach, identified on April 15, led to the exposure of personal data—including full names, dates and places of birth, mailing and email addresses, and phone numbers—of approximately 11.7 million individuals. Shortly after, a hacker using the alias 'breach3d' advertised the sale of this data on a cybercriminal forum. French authorities have since detained a 15-year-old suspect believed to be behind the alias, facing charges related to unauthorized access and data exfiltration. This incident underscores the escalating threat posed by cybercriminals targeting government agencies to access vast amounts of sensitive personal information. The involvement of a minor highlights the accessibility of sophisticated hacking tools and the need for enhanced cybersecurity measures and public awareness to prevent such breaches and mitigate their potential impact on citizens.
2 months ago
Kill Chain
Insider Betrayal: Ransomware Negotiator Aids BlackCat Attacks
In April 2026, Angelo Martino, a former ransomware negotiator at DigitalMint, pleaded guilty to conspiring with the BlackCat/ALPHV ransomware group to extort U.S. companies. Martino exploited his trusted position by providing confidential client information, such as insurance policy limits and negotiation strategies, to the attackers. This insider collaboration enabled the ransomware group to maximize their ransom demands, resulting in over $75 million in payments from victims, including a nonprofit and a financial firm. Authorities have seized more than $10 million in assets from Martino, who faces up to 20 years in prison. This case underscores the critical importance of vetting and monitoring individuals in sensitive cybersecurity roles. The incident highlights the evolving tactics of ransomware groups, including the recruitment of insiders to enhance their extortion efforts. Organizations must remain vigilant against such threats and implement robust internal controls to safeguard against insider collusion.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports