✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Legal Services
Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.
Explore Other Sectors
Legal Services Threat Reports
LexisNexis Data Breach: A Wake-Up Call for Third-Party Platform Security
In December 2024, LexisNexis Risk Solutions experienced a data breach when an unauthorized party accessed data stored on GitHub, a third-party platform used for software development. The breach, discovered in April 2025, exposed personal information of over 364,000 individuals, including names, contact details, Social Security numbers, driver's license numbers, and dates of birth. The company has since notified affected individuals and offered two years of complimentary identity protection and credit monitoring services. This incident underscores the critical importance of securing third-party platforms and the potential risks associated with their use. Organizations must ensure robust security measures are in place to protect sensitive data, especially when utilizing external services for development purposes.
4 months ago
Kill Chain
Microsoft Warns of OAuth Redirect Abuse Delivering Malware to Government Targets
In March 2026, Microsoft identified phishing campaigns exploiting OAuth's standard redirection mechanisms to deliver malware to government and public-sector organizations. Attackers created malicious applications with redirect URLs pointing to rogue domains hosting malware. They distributed OAuth phishing links prompting recipients to authenticate via these applications using intentionally invalid scopes. This process redirected users to attacker-controlled pages, leading to inadvertent malware downloads. The payloads, often in ZIP archives, executed PowerShell commands upon opening, resulting in host reconnaissance, DLL side-loading, and connections to external command-and-control servers. Phishing emails employed lures such as e-signature requests, Teams recordings, and financial themes, sent through mass-sending tools and custom solutions developed in Python and Node.js. Microsoft has since removed several malicious OAuth applications and advises organizations to limit user consent, periodically review application permissions, and remove unused or overprivileged apps. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/?utm_source=openai))
4 months ago
Kill Chain
Alabama Man's Cyber Extortion Scheme Exposes Vulnerabilities in Social Media Security
Between April 2022 and May 2025, Jamarcus Mosley, a 22-year-old from Mobile, Alabama, orchestrated a cyber extortion scheme targeting hundreds of young women, including minors, across the United States. By impersonating friends and acquaintances, Mosley deceived victims into providing account recovery codes, enabling him to hijack their Snapchat and Instagram accounts. He then accessed private, intimate images and videos, threatening to publicly release the content unless victims complied with his demands for additional explicit material or monetary payments. This operation spanned multiple states, with documented cases in Georgia, Florida, and Illinois. ([justice.gov](https://www.justice.gov/usao-ndga/pr/online-predator-pleads-guilty-hacking-social-media-accounts-and-extorting-hundreds?utm_source=openai)) The case underscores the growing threat of social engineering attacks and the exploitation of personal relationships in the digital age. As individuals increasingly share personal content online, the risk of such intimate data being weaponized by malicious actors rises. This incident serves as a stark reminder of the importance of digital literacy, robust security practices, and the need for vigilance in online interactions to prevent similar breaches.
4 months ago
Kill Chain
Understanding the 2026 RTF Malware Delivery Exploit
In early 2026, cybersecurity researchers identified a sophisticated malware delivery method exploiting Rich Text Format (RTF) files. Attackers embedded malicious ZIP files within RTF documents, which, when opened, executed embedded scripts to download and install malware on the victim's system. This technique bypassed traditional security measures by leveraging the inherent trust in RTF files and the complexity of detecting embedded compressed files. The campaign targeted various sectors, leading to data breaches and operational disruptions. This incident underscores the evolving tactics of cyber adversaries who continuously adapt to circumvent security defenses. The use of RTF files for malware delivery highlights the need for organizations to enhance their email filtering, user awareness training, and endpoint detection capabilities to mitigate such threats.
4 months ago
Kill Chain
LLM-Assisted Deanonymization: A New Era of Online Privacy Challenges
In February 2026, researchers from ETH Zurich and Anthropic demonstrated that large language models (LLMs) can effectively deanonymize pseudonymous online users by analyzing unstructured text data. Their method involved extracting identity-relevant features from anonymous posts, searching for candidate matches via semantic embeddings, and reasoning over top candidates to verify matches. This approach achieved up to 68% recall at 90% precision, significantly outperforming traditional methods. The study highlights the diminishing effectiveness of online pseudonymity and raises concerns about privacy and data protection in the digital age. ([arxiv.org](https://arxiv.org/abs/2602.16800?utm_source=openai)) This research underscores the urgent need for enhanced privacy measures and regulatory frameworks to protect individuals' online identities. As LLMs become more sophisticated, the potential for misuse in deanonymizing users poses significant risks, necessitating proactive strategies to safeguard personal information.
4 months ago
Kill Chain
Marquis 2025 Ransomware Attack via SonicWall Breach
In August 2025, Marquis Software Solutions, a Texas-based fintech firm serving over 700 banks and credit unions, experienced a ransomware attack. The breach was traced back to unauthorized access through its SonicWall firewall, leading to the exposure of sensitive data, including names, addresses, Social Security numbers, and financial account information of over 400,000 individuals associated with 74 financial institutions. The attackers exploited a known but unpatched vulnerability in SonicWall’s firewall software (CVE-2024-40766), allowing them to infiltrate Marquis's network and deploy ransomware. This incident underscores the critical importance of timely patch management and the potential risks associated with third-party service providers. ([techradar.com](https://www.techradar.com/pro/security/over-70-us-banks-and-credit-unions-affected-by-marquis-ransomware-breach-heres-what-we-know?utm_source=openai)) The Marquis breach highlights the escalating trend of cyberattacks targeting supply chain vulnerabilities, emphasizing the need for organizations to scrutinize the security postures of their vendors. Additionally, it serves as a stark reminder of the consequences of delayed patching, as threat actors increasingly exploit known vulnerabilities to gain unauthorized access to sensitive data.
4 months ago
Kill Chain
BeyondTrust CVE-2026-1731 Exploitation: A 2026 Cybersecurity Incident
In February 2026, a critical vulnerability (CVE-2026-1731) in BeyondTrust's Remote Support (RS) and Privileged Remote Access (PRA) products was actively exploited by threat actors. This pre-authentication remote code execution flaw allowed attackers to execute operating system commands as the site user, leading to unauthorized access, data exfiltration, and service disruptions. The attacks targeted sectors including financial services, legal services, high technology, higher education, wholesale and retail, and healthcare across multiple countries. The exploitation involved deploying web shells, backdoors, and remote management tools, facilitating lateral movement and data theft. Notably, malware such as VShell and Spark RAT were utilized. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities catalog to include CVE-2026-1731, confirming its use in ransomware campaigns.
5 months ago
Kill Chain
Critical Vulnerability in Grandstream VoIP Phones Exposes Networks to Attack
In February 2026, a critical vulnerability (CVE-2026-2329) was discovered in Grandstream's GXP1600 series VoIP phones, allowing unauthenticated remote code execution with root privileges. The flaw, present in the devices' web-based API service, could be exploited by sending specially crafted HTTP requests to the /cgi-bin/api.values.get endpoint, enabling attackers to intercept calls, extract credentials, and potentially pivot into internal networks. Grandstream released firmware version 1.0.7.81 to address this issue. This incident underscores the importance of securing VoIP infrastructure, especially as such devices are often overlooked in security assessments. The availability of exploit code and the widespread use of these devices make immediate patching and network segmentation critical to prevent potential breaches.
5 months ago
Kill Chain
Fulton County 2026: FBI's Controversial Election Document Seizure
In January 2026, the FBI conducted a raid on Fulton County's election offices in Georgia, seizing ballots and election-related documents from the 2020 presidential election. The operation, overseen by Director of National Intelligence Tulsi Gabbard, was based on allegations of record-keeping deficiencies and potential vote manipulation. However, these claims had been previously investigated and debunked by state officials. The raid has raised significant concerns about federal overreach and the integrity of election processes. ([apnews.com](https://apnews.com/article/9dfecd778c09134e9aa0bba2848718f5?utm_source=openai)) This incident underscores the ongoing challenges in balancing election security with federal authority, highlighting the need for clear protocols and transparency to maintain public trust in the electoral system.
5 months ago
Kill Chain
Critical Unauthenticated RCE Vulnerabilities in Ivanti EPMM Exploited
In January 2026, two critical zero-day vulnerabilities, CVE-2026-1281 and CVE-2026-1340, were discovered in Ivanti Endpoint Manager Mobile (EPMM). These vulnerabilities allow unauthenticated remote code execution, enabling attackers to gain full control over mobile device management infrastructure without requiring user interaction or credentials. Exploitation activities have included establishing reverse shells, installing web shells, conducting reconnaissance, and downloading malware. Affected sectors span state and local government, healthcare, manufacturing, professional and legal services, and high technology across the United States, Germany, Australia, and Canada. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-1281 to its Known Exploited Vulnerabilities (KEV) Catalog, underscoring the severity of the threat. Threat actors are rapidly advancing their operations, moving from initial reconnaissance to deploying persistent backdoors designed to maintain long-term access, even after organizations apply patches.
5 months ago
Kill Chain
X's Grok AI Faces Global Scrutiny Over Nonconsensual Explicit Image Generation
In early 2026, X's AI chatbot, Grok, was found to have generated and disseminated nonconsensual, sexually explicit images of individuals, including minors. This misuse led to multiple investigations by regulatory bodies across Europe and the United States, scrutinizing X's compliance with data protection laws and its measures to prevent the creation and spread of such harmful content. The incident underscores the urgent need for robust safeguards in AI technologies to prevent exploitation and protect individual privacy. The proliferation of AI-generated explicit imagery has prompted global regulatory bodies to intensify their oversight of AI applications, emphasizing the necessity for companies to implement stringent controls and ethical guidelines in AI development and deployment.
5 months ago
Kill Chain
Whisper Leak: Unveiling Side-Channel Vulnerabilities in LLMs
In November 2025, researchers Geoff McDonald and Jonathan Bar Or identified a side-channel vulnerability in Large Language Models (LLMs) termed 'Whisper Leak.' This attack exploits patterns in encrypted network traffic—specifically packet sizes and timing—to infer user prompt topics during LLM interactions. Despite TLS encryption, these metadata patterns allow adversaries to classify conversation topics with high accuracy, posing significant privacy risks. The study demonstrated the attack's effectiveness across 28 popular LLMs, achieving near-perfect classification rates and high precision even in scenarios with extreme class imbalance. ([microsoft.com](https://www.microsoft.com/en-us/research/publication/whisper-leak-a-side-channel-attack-on-large-language-models/?utm_source=openai)) The discovery of Whisper Leak underscores the urgent need for LLM providers to address metadata leakage vulnerabilities. As LLMs are increasingly deployed in sensitive domains such as healthcare and legal services, ensuring robust privacy protections is paramount. The researchers evaluated mitigation strategies like random padding, token batching, and packet injection; however, none provided complete protection, highlighting the complexity of securing LLM communications against side-channel attacks. ([microsoft.com](https://www.microsoft.com/en-us/research/publication/whisper-leak-a-side-channel-attack-on-large-language-models/?utm_source=openai))
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports