Cybernews reports that more than 200,000 law firms and legal teams around the world could have their sensitive client documents compromised through a phishing vulnerability in vLex's Vincent AI assistant, which could be exploited through concealed HTML code. Hidden text could be embedded in documents uploaded to vLex to facilitate indirect prompt injection and remote code execution to trigger fake screen overlays that lure targets into providing their login credentials, an analysis from PromptArmor researchers showed. Attackers could also lure the Vincent AI model into supplying illicit JavaScript found in HTML elements or Markdown hyperlinks, allowing zero-click data theft, session takeovers, forced file downloads, and cryptomining every time that chat is opened, according to PromptArmor co-founder and Managing Director Shankar Krishnan. While vLex has already been informed about the security weakness, organizations have been urged to ensure proper labeling of untrusted documents, bolster visibility permission configurations, and prohibit document uploads from unverified sources.
Ransomware, Phishing, Threat Management, Threat Intelligence

(Adobe Stock Images)
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Related

Toll of Coupang breach exceeds 30M, authorities report
More than 30 million accounts with names, emails, and other personal details were noted by South Korean police to have been impacted by the December breach at the leading South Korean e-commerce firm Coupang, which had downplayed the incident to have only affected 3,000 accounts following an internal investigation that showed its former employee to have discarded data from most of the accounts that had been accessed, reports Korea JoongAng Daily.

Massive HaxorSEO backlink marketplace examined
Newly identified SEO poisoning marketplace HaxorSEO, also known as HxSEO, has been offering over a thousand backlinks to legitimate web domains compromised with a webshell that boosts the websites' search rankings, reports Infosecurity Magazine.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
