The Containment Era is here. →Explore

Industry Category

Legal Services

Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.

163 threat reports
Page 7 of 14

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Legal Services Threat Reports

Showing 7384 / 163 reports
Critical Vulnerabilities in Progress ShareFile: Immediate Action Required
Impact· CRITICAL

Critical Vulnerabilities in Progress ShareFile: Immediate Action Required

In early 2026, two critical vulnerabilities were identified in Progress ShareFile's Storage Zones Controller (SZC), a component widely used for secure file sharing. The first, CVE-2026-2699, is an authentication bypass flaw that allows unauthenticated attackers to access restricted configuration pages. The second, CVE-2026-2701, enables remote code execution through malicious file uploads. Exploiting these vulnerabilities in sequence permits attackers to gain unauthorized access and execute arbitrary code on affected systems. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-progress-sharefile-flaws-can-be-chained-in-pre-auth-rce-attacks/?utm_source=openai)) The disclosure of these vulnerabilities underscores the persistent threat posed by sophisticated cyberattacks targeting enterprise file-sharing solutions. Organizations are urged to promptly apply the security updates provided by Progress to mitigate potential risks associated with these flaws. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-progress-sharefile-flaws-can-be-chained-in-pre-auth-rce-attacks/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical XSS and GhostScript RCE Vulnerabilities in Enterprise Document Processing Platform
Impact· CRITICAL

Critical XSS and GhostScript RCE Vulnerabilities in Enterprise Document Processing Platform

In 2026, a critical security assessment of an enterprise document processing platform revealed two severe vulnerabilities: an unauthenticated cross-site scripting (XSS) flaw and a GhostScript parameter injection leading to remote code execution (RCE). The XSS vulnerability allowed attackers to execute malicious scripts, bypassing HttpOnly cookie protections by exploiting an internal service endpoint that reflected session cookies in its response. This enabled full administrative access. Additionally, the GhostScript flaw permitted arbitrary command execution on the server by injecting parameters that disabled security features, leading to potential system compromise. ([praetorian.com](https://www.praetorian.com/blog/httponly-cookie-bypass-xss-ghostscript-rce/?utm_source=openai)) This incident underscores the persistent risks associated with XSS and RCE vulnerabilities, especially in applications handling sensitive data. It highlights the necessity for comprehensive security measures, including proper input validation, strict access controls, and regular security assessments to identify and mitigate such critical flaws.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
OpenAI Patches ChatGPT Data Exfiltration Vulnerability in 2026
Impact· HIGH

OpenAI Patches ChatGPT Data Exfiltration Vulnerability in 2026

In early 2026, a vulnerability in OpenAI's ChatGPT was discovered that allowed attackers to exfiltrate sensitive user data through malicious prompts. This flaw exploited a covert DNS-based communication channel within the AI's Linux runtime, bypassing existing security measures and enabling unauthorized data transmission without user consent. OpenAI addressed the issue on February 20, 2026, following responsible disclosure, and confirmed that there was no evidence of malicious exploitation. This incident underscores the evolving nature of AI security threats and the necessity for continuous vigilance and robust security frameworks to protect sensitive information processed by AI systems.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
European Commission's AWS Account Breach in 2026: A Wake-Up Call for Cloud Security
Impact· CRITICAL

European Commission's AWS Account Breach in 2026: A Wake-Up Call for Cloud Security

In March 2026, the European Commission, the executive body of the European Union, experienced a significant security breach when a threat actor gained unauthorized access to its Amazon Web Services (AWS) cloud environment. The attacker claimed to have exfiltrated over 350 GB of data, including multiple databases containing sensitive information about Commission employees and internal communications. The breach was promptly detected, and the Commission's cybersecurity incident response team initiated an investigation to assess the extent of the intrusion and mitigate potential damages. This incident underscores the escalating risks associated with cloud infrastructure security, especially for governmental organizations handling sensitive data. It highlights the necessity for robust cloud security measures, continuous monitoring, and rapid response capabilities to address emerging threats in the digital landscape.

4 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI-Driven Phishing Campaign Exploits Railway's Platform to Compromise Microsoft Cloud Accounts
Impact· HIGH

AI-Driven Phishing Campaign Exploits Railway's Platform to Compromise Microsoft Cloud Accounts

In March 2026, a sophisticated phishing campaign exploited AI-generated lures to compromise Microsoft cloud accounts across hundreds of organizations. Attackers utilized Railway's Platform as a Service to deploy credential harvesting infrastructure, creating unique phishing emails that bypassed traditional security measures. The campaign targeted various sectors, including construction, law, healthcare, and government, leveraging Microsoft's device authentication flow to obtain OAuth tokens valid for up to 90 days without requiring passwords or multifactor authentication. This incident underscores the escalating use of AI in cyberattacks, enabling threat actors to scale operations and evade detection more effectively. Organizations must enhance their security protocols to address AI-driven threats and implement robust monitoring systems to detect and mitigate such sophisticated phishing campaigns.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Insider Threat: North Carolina Tech Worker Convicted in $2.5M Data Extortion Case
Impact· HIGH

Insider Threat: North Carolina Tech Worker Convicted in $2.5M Data Extortion Case

In December 2023, Cameron Curry, a 25-year-old contract employee from North Carolina, exploited his access to a Washington D.C.-based technology company's sensitive data. Upon learning his contract would not be renewed, Curry stole confidential employee information and, under the alias "Loot," sent over 60 emails threatening to publish the data unless a $2.5 million ransom was paid. The company reported the extortion to the FBI on December 14, 2023, and subsequently paid the ransom in January 2024. Curry was arrested on January 24, 2024, after authorities traced the extortion communications and cryptocurrency transactions back to him. He pleaded guilty to felony extortion on September 27, 2024, and faces sentencing on January 28, 2025. This incident underscores the significant risks posed by insider threats, especially when employees or contractors have access to sensitive information. Organizations must implement robust access controls, monitor for unusual activities, and foster a culture of security awareness to mitigate such risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Claude Code's 2026 Security Flaw: A Wake-Up Call for Agentic AI
Impact· HIGH

Claude Code's 2026 Security Flaw: A Wake-Up Call for Agentic AI

In February 2026, a critical vulnerability (CVE-2026-24052) was identified in Claude Code, an agentic coding tool developed by Anthropic. The flaw involved insufficient URL validation in the trusted domain verification mechanism for WebFetch requests. Specifically, the application used the `startsWith()` function to validate trusted domains, allowing attackers to register subdomains that could bypass this validation. This vulnerability enabled automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration. Anthropic addressed this issue by releasing a patch in version 1.0.111. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-24052?utm_source=openai)) This incident underscores the growing security challenges associated with agentic AI systems, which operate autonomously and can interact with external resources. The exploitation of such vulnerabilities highlights the need for robust validation mechanisms and comprehensive security assessments in AI-driven tools to prevent unauthorized data access and exfiltration.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
UK's Companies House Security Flaw Exposes Business Data - 2026
Impact· HIGH

UK's Companies House Security Flaw Exposes Business Data - 2026

In March 2026, the UK's Companies House disclosed a significant security vulnerability in its WebFiling service, which had been present since October 2025. This flaw allowed authenticated users to access and potentially modify sensitive information of any registered company by exploiting a back-navigation loophole. The exposed data included directors' residential addresses, email addresses, and dates of birth. The agency has since rectified the issue, notified affected parties, and reported the incident to the Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC). This incident underscores the critical importance of rigorous security testing and prompt response to vulnerabilities in public sector digital services. The exposure of personal data over an extended period raises concerns about potential misuse and the necessity for enhanced monitoring and compliance measures to protect sensitive information.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
DigitalMint 2023 BlackCat Ransomware Insider Attack
Impact· CRITICAL

DigitalMint 2023 BlackCat Ransomware Insider Attack

In 2023, former employees of DigitalMint and Sygnia, cybersecurity firms specializing in ransomware incident response, exploited their positions to collaborate with the BlackCat (ALPHV) ransomware group. They conducted multiple ransomware attacks against U.S. organizations, including a medical device company that paid approximately $1.2 million in ransom. The perpetrators utilized their insider knowledge to infiltrate systems, encrypt data, and extort victims, sharing a portion of the ransoms with BlackCat administrators. This case underscores the critical risk posed by insider threats within cybersecurity firms. The incident highlights the necessity for robust internal controls and continuous monitoring to prevent such breaches. Organizations must remain vigilant against the evolving tactics of ransomware groups and the potential for trusted insiders to become malicious actors.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Microsoft Copilot's 2026 Reprompt Exploit: A Wake-Up Call for AI Security
Impact· HIGH

Microsoft Copilot's 2026 Reprompt Exploit: A Wake-Up Call for AI Security

In early 2026, a critical vulnerability known as the "Reprompt" exploit was discovered in Microsoft Copilot by Varonis Threat Labs. This flaw allowed attackers to embed a "q parameter" within phishing links, which, when clicked, silently activated Copilot to exfiltrate sensitive user data to attacker-controlled servers. Remarkably, this attack required no further user interaction beyond the initial click, effectively bypassing existing enterprise security controls. Microsoft promptly addressed and patched the vulnerability by January 13, 2026. ([windowscentral.com](https://www.windowscentral.com/artificial-intelligence/microsoft-copilot/copilot-ai-reprompt-exploit-detailed-2026?utm_source=openai)) The Reprompt exploit underscores the escalating sophistication of AI-targeted cyberattacks, highlighting the necessity for continuous vigilance and robust security measures in AI-integrated applications. As AI systems become more embedded in daily workflows, ensuring their security against such advanced threats is paramount.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
US Marshals Crypto Theft 2026: Insider Threat Exposed
Impact· HIGH

US Marshals Crypto Theft 2026: Insider Threat Exposed

In March 2026, the FBI arrested John Daghita on the Caribbean island of Saint Martin for allegedly stealing over $46 million in cryptocurrency from the U.S. Marshals Service (USMS). Daghita, son of Dean Daghita—president of Command Services & Support (CMDSS), a firm contracted by the USMS to manage seized digital assets—allegedly exploited his insider access to siphon funds from government-controlled wallets. The theft was uncovered by blockchain investigator ZachXBT, who traced the illicit transactions back to Daghita after he inadvertently exposed his control over the funds during a recorded Telegram dispute. This incident underscores the critical need for stringent oversight and security measures when managing sensitive digital assets, especially within government agencies. The breach highlights the vulnerabilities associated with insider threats and the importance of robust monitoring and auditing protocols to prevent unauthorized access and theft of digital currencies.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
LastPass Users Targeted in Sophisticated Phishing Attack
Impact· HIGH

LastPass Users Targeted in Sophisticated Phishing Attack

In early March 2026, LastPass users were targeted by a sophisticated phishing campaign. Attackers sent emails impersonating LastPass support, claiming unauthorized attempts to change users' account email addresses. These emails included links labeled 'report suspicious activity' and 'disconnect and lock vault,' directing recipients to a counterfeit LastPass login page designed to harvest credentials. The phishing emails often appeared as forwarded internal conversations to create a sense of urgency and legitimacy. LastPass confirmed that their systems remained uncompromised and emphasized that they would never request users' master passwords via email. This incident underscores the evolving tactics of cybercriminals who exploit trust in established brands to deceive users. The use of realistic email threads and urgent security alerts highlights the need for continuous vigilance and user education to recognize and resist such social engineering attacks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports