Thomson Reuters reveals breach that exposed U.S. and Canadian court records

2026-09-03T14:51:41Z09b69fc4f59c30130f28fbd5e160391dddfe7899b57c632f95abffd8a8f41057
CVE-2026-62911AI securityMicrosoft ExchangeWindows VBSaccess controlauthentication bypasscourt recordsdata breachfreelance platformidentity theftmalware distributionmemory integrityprompt injectionsensitive personal informationthreat intelligenceunpatched internet-facing systemsvulnerability management

What happened

The feed covers a Thomson Reuters C-Track breach exposing court records and sensitive personal data, malware allegedly distributed to approximately 80,000 freelancers, AI-agent authorization and prompt-injection risks, vulnerability-management practices, Windows memory-integrity changes, and a critical Microsoft Exchange authentication-bypass vulnerability (CVE-2026-62911) affecting nearly 22,000 exposed servers. The Exchange issue presents the most immediate operational risk because it is critical, remotely exploitable over a network, and widely unpatched.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
09b69fc4f59c30130f28fbd5e160391dddfe7899b57c632f95abffd8a8f41057
Enrichment time
2026-09-03T14:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Thomson Reuters reveals breach that exposed U.S. and Canadian court records · Baitaphish