惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
Apple Machine Learning Research
Apple Machine Learning Research
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
M
MIT News - Artificial intelligence
腾讯CDC
B
Blog RSS Feed
H
Help Net Security
J
Java Code Geeks
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
博客园_首页
Last Week in AI
Last Week in AI
博客园 - 【当耐特】
博客园 - Franky
B
Blog
MongoDB | Blog
MongoDB | Blog
博客园 - 叶小钗
Martin Fowler
Martin Fowler

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day Critical Microsoft bug from 2024 under exploitation
LexisNexis Legal & Professional confirms data breach
Connor Jones Connor Jones · 2026-03-05 · via The Register - Security: Patches

Cyber-crime

LexisNexis confirms data breach at Legal & Professional arm, some customer records affected

Crooks claim 2 GB haul from AWS instance via React2Shell exploit

Data analytics giant LexisNexis has confirmed its Legal & Professional division suffered a data breach days after the Fulcrumsec cybercrime crew claimed responsibility for the hack.

Following an investigation, LexisNexis told The Register the matter is now contained, and that neither its products nor its services were ever compromised, although the company was forced to bring in a third-party digital forensics crew to manage the cleanup.

A spokesperson said only "a limited number of servers" were accessed, and the data stored on them was "mostly legacy, deprecated data from prior to 2020."

This included customer names, user IDs, business contact information, products used, customer surveys with respondent IP addresses, and support tickets.

"The impacted information did not contain Social Security numbers, driver's license numbers, or any other sensitive personally identifiable information; credit card, bank accounts, or any other financial information; active passwords; or customer search queries, customer client or matter information, or customer contracts," the spokesperson added.

"We take our responsibility to safeguard customer information extremely seriously and have informed impacted current and previous customers of this matter. We are continuing to investigate and have implemented containment and remediation steps, in coordination with our expert cybersecurity forensic firm."

LexisNexis did not comment on the scale of the breach, although Fulcrumsec offered its take on this amid efforts to publicly shame the company.

Per the criminals' listing, which claims to contain a little more than 2 GB of company data, Fulcrumsec reckons it exfiltrated the files from a LexisNexis AWS instance by exploiting a vulnerable React container - specifically, an unpatched React2Shell vulnerability.

The listing claims the data dump includes 400,000 cloud user profiles, complete with personally identifiable information (PII) points, including names, emails, and phone numbers. This is unverified. It also claims more than 118 appeared to belong to US government staff, including federal judges, DoJ attorneys, SEC staff, and court clerks.

Among the other files are 17 VPC databases and more than 430 VPC database tables, 536 Redshift tables, 3.9 million database records, and 53 secrets swiped from AWS Secrets Manager, Fulcrumsec claims.

The cyber crew alleges it leaked more than 21,000 customer account records belonging to government agencies, insurance companies, law firms, and universities.

Further, it claims more than 300,000 records included in the dump pertain to customer contracts, revealing which products individual organizations pay for, the associated renewal dates, and pricing tiers.

"This is the complete commercial relationship database," Fulcrumsec wrote. "If you wanted to know exactly what Gibson Dunn pays for Lexis Advance, or what the SEC subscribes to, or which Newsdesk package the Ellen MacArthur Foundation uses – it is all here."

As always, criminals' assertions should be taken with a pitch of salt. ®