Cybernews reports that more than 200,000 law firms and legal teams around the world could have their sensitive client documents compromised through a phishing vulnerability in vLex's Vincent AI assistant, which could be exploited through concealed HTML code.
Hidden text could be embedded in documents uploaded to vLex to facilitate indirect prompt injection and remote code execution to trigger fake screen overlays that lure targets into providing their login credentials, an analysis from PromptArmor researchers showed.
Attackers could also lure the Vincent AI model into supplying illicit JavaScript found in HTML elements or Markdown hyperlinks, allowing zero-click data theft, session takeovers, forced file downloads, and cryptomining every time that chat is opened, according to PromptArmor co-founder and Managing Director Shankar Krishnan.
While vLex has already been informed about the security weakness, organizations have been urged to ensure proper labeling of untrusted documents, bolster visibility permission configurations, and prohibit document uploads from unverified sources.
Ransomware, Phishing, Threat Management, Threat Intelligence
Over 200K law firms threatened by Vincent AI phishing flaw
(Adobe Stock Images)
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
