The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Legal Services
Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.
Explore Other Sectors
Legal Services Threat Reports
Expansion of Deepfake CSAM Lawsuit Targets xAI and Stability AI
In July 2026, a class-action lawsuit against xAI, the developer of the AI tool Grok, was expanded to include two additional plaintiffs. These individuals allege that Grok was used by acquaintances to generate nonconsensual deepfake child sexual abuse material (CSAM) based on their real photos. The lawsuit also names Stability AI as a defendant, claiming that its Stable Diffusion model facilitated the creation of such illicit content. The plaintiffs report significant emotional distress and a loss of control over the dissemination of these images. This incident underscores the urgent need for robust safeguards in AI technologies to prevent misuse, particularly in generating harmful content. It highlights the growing legal and ethical challenges companies face in ensuring their AI models are not exploited for creating nonconsensual and illegal material.
2 months ago
Kill Chain
DEBULL Exploits Microsoft Device-Code Flow in Recent Phishing Campaign
Between late June and early July 2026, a sophisticated phishing campaign leveraging the DEBULL tooling targeted Microsoft 365 accounts. Unlike traditional phishing methods, this campaign utilized collaboration-themed lures to direct users into the legitimate Microsoft device login experience. By exploiting the OAuth 2.0 Device Authorization Grant flow, attackers bypassed multi-factor authentication (MFA) and gained unauthorized access to victim accounts. The DEBULL platform, likely a phishing-as-a-service (PhaaS) offering, enabled threat actors to generate and poll device-code tokens, facilitating account takeovers without the need for password theft. This method allowed for persistent access, leading to potential data exfiltration and further exploitation within compromised environments. ([thehackernews.com](https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.html?utm_source=openai)) The emergence of DEBULL signifies a notable evolution in phishing tactics, emphasizing the shift towards abusing legitimate authentication processes to circumvent traditional security measures. This trend underscores the necessity for organizations to enhance their security protocols, particularly in monitoring and mitigating risks associated with OAuth flows and device code authentication mechanisms. ([thehackernews.com](https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.html?utm_source=openai))
2 months ago
Kill Chain
Understanding the 'WriteOut' Vulnerability in Writer AI Platform
In July 2026, a critical session isolation vulnerability, dubbed 'WriteOut,' was discovered in Writer, an enterprise generative AI platform. This flaw allowed attackers to hijack user sessions across different organizations by exploiting the platform's live preview feature. By sharing a malicious preview link, attackers could gain unauthorized access to sensitive data, including private chats, documents, and large language model credentials, without requiring prior access to the victim's organization. ([thehackernews.com](https://thehackernews.com/2026/07/writer-ai-flaw-could-let-agent-previews.html?utm_source=openai)) The 'WriteOut' vulnerability underscores the growing security challenges in AI platforms, particularly concerning tenant isolation and session management. As AI adoption accelerates, ensuring robust security measures to prevent cross-tenant data breaches becomes imperative for organizations relying on such technologies.
2 months ago
Kill Chain
Understanding the 2026 Microsoft Device Code Phishing Attack
In early 2026, a sophisticated phishing campaign exploited Microsoft's OAuth 2.0 Device Authorization Grant flow to compromise user accounts. Attackers initiated the device code authentication process and tricked victims into entering the provided code on Microsoft's legitimate login page, thereby granting unauthorized access without exposing credentials. This method allowed threat actors to bypass multi-factor authentication (MFA) and maintain persistent access to services like Outlook, OneDrive, and Teams by capturing access and refresh tokens. The campaign, active from April to mid-May 2026, targeted Microsoft 365 users through deceptive emails and malicious attachments, leading to significant data breaches and unauthorized account activities. The incident underscores a growing trend of attackers leveraging legitimate authentication mechanisms to bypass traditional security measures. The rise of device code phishing highlights the need for organizations to reassess their security protocols, especially concerning OAuth flows and MFA implementations. As phishing techniques become more sophisticated, continuous monitoring, user education, and the implementation of conditional access policies are crucial to mitigate such threats.
2 months ago
Kill Chain
Interpol Impersonation Ransomware Targets Small Businesses in 2026
In July 2026, a ransomware campaign targeted small businesses across multiple regions, including the US, Europe, Asia, and the Middle East. Attackers impersonated Interpol officials, sending phishing emails that claimed the recipient's organization was under investigation for suspicious activity. These emails urged recipients to download a password-protected archive from Proton Drive, purportedly containing evidence. Upon opening, the archive delivered a ransomware payload disguised as a video file, encrypting local systems and prompting victims to contact the attackers via the Tox messaging platform to negotiate payment. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/attackers-use-interpol-lure-target-small-businesses?utm_source=openai)) This incident underscores the increasing trend of cybercriminals leveraging social engineering tactics to exploit small businesses, which often lack dedicated cybersecurity resources. The campaign highlights the need for heightened awareness and robust security measures to defend against such deceptive attacks.
2 months ago
Kill Chain
ConsentFix and ClickFix: Unveiling the New Era of Microsoft 365 Account Hijacking
In July 2026, a sophisticated social engineering attack known as ConsentFix emerged, targeting Microsoft 365 users. This attack exploits users' habitual responses to familiar prompts by presenting a seemingly legitimate authentication process. Victims receive phishing lures that lead them to a fake Microsoft sign-in page, where they are instructed to drag a localhost callback link into their browser. This action inadvertently grants attackers OAuth tokens, enabling unauthorized access to the victim's Microsoft 365 account without requiring passwords or bypassing multi-factor authentication. The attack is particularly insidious as it leverages routine user behaviors, making it difficult to detect and prevent. The ConsentFix attack underscores the evolving nature of cyber threats that exploit user trust and routine actions. As attackers continue to refine their methods, it is imperative for organizations to enhance user education on recognizing sophisticated phishing attempts and to implement robust security measures that can detect and mitigate such deceptive tactics.
2 months ago
Kill Chain
ToddyCat's Umbrij Malware: A New Threat to Gmail Security
In June 2026, the advanced persistent threat group known as ToddyCat deployed a new malware tool named Umbrij to infiltrate corporate Gmail accounts. Utilizing a technique termed Shadow Token via Remote Debug (STRD), the attackers exploited active user sessions in Chromium-based browsers to obtain OAuth tokens, granting unauthorized access to Gmail and other Google services without requiring user credentials. This method allowed them to read emails, access calendars, and gather data from Google Drive, all while remaining undetected for extended periods. The emergence of Umbrij underscores a significant evolution in cyber-espionage tactics, highlighting the increasing sophistication of threat actors in bypassing traditional security measures. Organizations must reassess their security protocols, particularly concerning API access and browser session management, to mitigate such advanced threats.
2 months ago
Kill Chain
Massive 2026 Data Breach Exposes One Million Passport Records
In June 2026, a significant data breach exposed nearly one million passport records worldwide. The compromised data originated from an ID verification system used by cannabis dispensaries, where high-value credentials like passports were utilized for authentication. Attackers exploited vulnerabilities in this ancillary system, leading to the unauthorized disclosure of sensitive personal information. This incident underscores the critical need for robust security measures across all systems handling sensitive data, regardless of their primary function. It highlights the risks associated with using high-value credentials in less secure, ancillary systems and the potential for such breaches to have widespread implications.
3 months ago
Kill Chain
INC Ransomware's 2026 Surge: A Growing Threat to Sensitive Sectors
In early 2026, the INC ransomware group, a ransomware-as-a-service (RaaS) operation active since mid-2023, intensified its attacks across various sectors, notably healthcare, education, and government entities. Utilizing double extortion tactics, INC affiliates gained initial access through spear-phishing campaigns and exploitation of vulnerabilities in external services. Once inside, they conducted internal reconnaissance using tools like NETSCAN.EXE and AnyDesk.exe, exfiltrated sensitive data, and deployed ransomware to encrypt systems, pressuring victims into paying ransoms to prevent data leaks. ([explore.ontolocy.com](https://explore.ontolocy.com/intel/intrusion-sets/inc-ransomware-group/?utm_source=openai)) This surge in INC's activities underscores the evolving ransomware landscape, where groups leverage RaaS models to scale operations rapidly. The focus on sectors with sensitive data highlights the critical need for organizations to bolster defenses against such multifaceted threats.
3 months ago
Kill Chain
Understanding the 'SearchLeak' Vulnerability in Microsoft 365 Copilot (CVE-2026-42824)
In June 2026, a critical vulnerability known as 'SearchLeak' (CVE-2026-42824) was discovered in Microsoft 365 Copilot. This flaw allowed attackers to craft malicious links that, when accessed by a user, could exfiltrate sensitive data such as emails, meeting notes, and documents from OneDrive and SharePoint. The attack exploited a parameter-to-prompt injection (P2P) technique, enabling unauthorized data disclosure over the network. Microsoft promptly addressed the issue by releasing a patch to mitigate the vulnerability. The 'SearchLeak' incident underscores the evolving nature of AI-driven cyber threats, particularly those targeting large language model (LLM) systems integrated into enterprise environments. It highlights the necessity for organizations to implement robust security measures, including prompt isolation and output sanitization, to protect against sophisticated prompt-injection attacks.
3 months ago
Kill Chain
EvilTokens: The Phishing Service That Bypasses MFA Without Stealing Passwords
In early 2026, the EvilTokens Phishing-as-a-Service platform emerged, exploiting the OAuth 2.0 device authorization grant flow to compromise over 340 Microsoft 365 organizations across multiple countries within five weeks. This method bypasses traditional password theft by tricking users into completing legitimate multi-factor authentication (MFA) processes on genuine Microsoft login pages, thereby granting attackers access tokens without raising typical security alarms. The attackers then gain persistent access to corporate emails, files, and other sensitive resources, facilitating data exfiltration and business email compromise (BEC) attacks. This incident underscores the evolving sophistication of phishing techniques that render conventional MFA defenses insufficient. Organizations must reassess their security protocols to address these advanced threats, emphasizing the need for continuous monitoring and user education on emerging phishing tactics.
3 months ago
Kill Chain
Microsoft 365 Copilot 'SearchLeak' Vulnerability (CVE-2026-42824) Exposes Sensitive Data
In June 2026, a critical vulnerability chain known as 'SearchLeak' was discovered in Microsoft 365 Copilot Enterprise, identified as CVE-2026-42824. This exploit allowed attackers to steal sensitive data from users' mailboxes, OneDrive, and SharePoint accounts through specially crafted URLs. The attack combined a parameter-to-prompt injection, an HTML rendering race condition, and a content-security-policy bypass enabled by Bing server-side request forgery. Microsoft addressed this vulnerability at the beginning of June 2026, assigning it a critical severity rating. The 'SearchLeak' incident underscores the evolving nature of cyber threats targeting AI-integrated enterprise tools. It highlights the necessity for organizations to implement robust security measures, conduct regular vulnerability assessments, and stay informed about emerging attack vectors to protect sensitive data effectively.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports