CISO Intelligence

CISO Intelligence

U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog

Source: Security Affairs  ·  Category: Government Advisory CISA added Microsoft Exchange Server CVE-2026-42897 (CVSS 8.1) to its Known Exploited Vulnerabilities catalog after threat actors began exploiting it. Law firms commonly run Exchange Server for email and calendaring; active exploitation creates immediate risk to firm communications and data. Patch immediately and

CISO Intelligence

No need to hack when it’s leaking: Dalbir Singh & Associates law firm edition

Source: DataBreaches.net  ·  Category: Ransomware & Breach Dalbir Singh & Associates (NY immigration law firm) exposed misconfigured Amazon S3 bucket containing sensitive client data; firm ignored responsible disclosure warnings and re-exposed data after remediation. Extortion attempts underway. Client notification obligations likely triggered under NY GBL §668 and NYDFS; regulatory reporting