Thomson Reuters reveals breach that exposed U.S. and Canadian court records
2026-09-03T14:51:41Z•09b69fc4f59c30130f28fbd5e160391dddfe7899b57c632f95abffd8a8f41057
CVE-2026-62911AI securityMicrosoft ExchangeWindows VBSaccess controlauthentication bypasscourt recordsdata breachfreelance platformidentity theftmalware distributionmemory integrityprompt injectionsensitive personal informationthreat intelligenceunpatched internet-facing systemsvulnerability management
What happened
The feed covers a Thomson Reuters C-Track breach exposing court records and sensitive personal data, malware allegedly distributed to approximately 80,000 freelancers, AI-agent authorization and prompt-injection risks, vulnerability-management practices, Windows memory-integrity changes, and a critical Microsoft Exchange authentication-bypass vulnerability (CVE-2026-62911) affecting nearly 22,000 exposed servers. The Exchange issue presents the most immediate operational risk because it is critical, remotely exploitable over a network, and widely unpatched.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 09b69fc4f59c30130f28fbd5e160391dddfe7899b57c632f95abffd8a8f41057
- Enrichment time
- 2026-09-03T14:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.