Severity Daily

IT and AI security incidents, checked against the primary source

Tag: Greenberg Traurig

  • In three of today’s eight stories, the fix on offer covers less than the flaw does

    In three of today’s eight stories, the fix on offer covers less than the flaw does

    The most consequential thing on the site today is not the 10.0. It is a three-day federal clock that runs out on Sunday. CISA added two of the three exploited MikroTik RouterOS flaws to the Known Exploited Vulnerabilities catalog on September 10, due September 13, and left off the SSH authentication bypass that CERT Polska puts first in the chain. Exploitation is confirmed by a national CERT, all three flaws are closed by the same RouterOS releases, and Shadowserver counts at least 122,500 MikroTik devices with SSH reachable per 24-hour scan window. An agency that upgrades is fine. An agency that works the catalog as a queue — patch what is listed, ticket what carries a due date — finishes Sunday compliant and still reachable through the door the catalog does not name.

    The biggest-sounding story is GitLab’s, and it ranks second. An unauthenticated arbitrary file read in the repository commits API, scored 10.0, is as bad as a number gets, and the research published on September 11 describes reaching configuration files, credentials, tokens, and SSH keys. But nobody has confirmed exploitation — watchTowr reports probes, and probing is not exploitation — and the 10.0 is GitLab’s own, with NVD returning no record at all as of early this morning. Recompute the vector without the integrity impact the advisory’s own description does not describe, and it is an 8.6. What is not in dispute is the work: self-managed operators have a critical to install, and some of them cannot.

    That last clause is the day’s thread, and it runs through three of the eight stories. GitLab names installations from 18.7 as affected and ships no 18.x build in the release, so a shop sitting on 18.7 through 18.11 is inside the affected range and outside the branch that got the fix — a major-version migration, not a patch. CISA put two more JFrog Artifactory flaws on KEV with a September 25 deadline, and on the 7.133 branch their fixes are seventeen patch releases apart: an administrator who took 7.133.11 in July to close CVE-2026-42016 is still exposed to CVE-2026-42018 today, and a version check that stops at 7.133.11 reports the box clean. And CISA’s MikroTik entries cover two links of a three-link chain. In each case the fix on offer covers less than the flaw does, and in each case you see it only by reading two documents side by side.

    The other four are disclosure stories, and what they share is an absence. Florida’s motor vehicle agency confirmed that DAVID, its law enforcement driver database, was breached through credentials a Plant City police employee stored on a personal device, and named no number; every figure in circulation — 200,000 records, Social Security numbers, and dates of birth — belongs to ShinyHunters. Nutex Health’s stolen data has been published online, and the company filed that under Item 8.01 with its materiality assessment unchanged, no count and no dates. Conduent settled the class action over its January 2025 breach with no dollar figure, also under Item 8.01, having filed the incident itself under Item 1.05. Greenberg Traurig told Vermont and California regulators that Social Security numbers were in scope on September 8 and September 9, then publicly called the exposure limited on September 10. Furthest from an action item, Anthropic’s misuse report describes one actor working through roughly thirty AI companies in about four days, swapping in each victim’s own API keys as it went — a billing and attribution problem as much as a security one.

    Open tonight. CVE-2026-67276, the MikroTik bypass, still carries no exploit-add date and may yet be added; worth re-checking before Sunday. CISA’s alert for September 11 is titled as one catalog addition while two records carry that day’s exploit-add date, and cisa.gov returns 403 to automated fetching, so the count could not be reconciled. GitLab has said nothing about the 18.x case. The distillation claim circulating in coverage of the Anthropic report — seven named Chinese labs, industrial scale — does not appear in the document we read. And four organizations described a breach today without producing a number. Nutex says its review will take several weeks.

  • Greenberg Traurig filed breach notices naming Social Security numbers in two states before publicly calling the exposure limited

    Greenberg Traurig filed breach notices naming Social Security numbers in two states before publicly calling the exposure limited

    Greenberg Traurig told two state regulators about a breach involving Social Security numbers on September 8 and September 9, 2026, days before it publicly characterized the incident as limited — and the filings, not the firm, are where the concrete facts are.

    What happened

    Greenberg Traurig, LLP, an international law firm with more than 3,200 attorneys, has reported a data breach to at least two state attorneys general. The filings are dated September 8, 2026 in Vermont and September 9, 2026 in California. The California entry gives a breach date of August 26, 2026.

    Those are the dates that matter for anyone tracking this, and they run in that order: the incident on August 26, the Vermont notification on September 8, the California notification on September 9, and the firm’s public statement on September 10. Nothing here is fresh as of this afternoon; what is new is that the regulatory record became legible this week.

    The Vermont Attorney General’s security breach notice database lists Greenberg Traurig, LLP with a report date of September 8, 2026, 10 Vermont residents affected, and the data element involved recorded as “Social Security Numbers.” Vermont does not publish the underlying consumer notice on the portal; it makes them available on request.

    The California Attorney General’s breach list carries the entry as “Greenberg Traurig, LLP (“GT”)” with a breach date of 08/26/2026 and a reported date of 09/09/2026. California’s threshold for appearing on that list is a notice sent to more than 500 California residents, so the California filing establishes a floor of 500 people in that state alone. A sample consumer notice is posted alongside the entry as a PDF; it could not be parsed by automated fetching, and its contents are therefore not reported here.

    Separately, on September 10, 2026, the firm made a public statement. It was given to Reuters and reached us through a secondary brief rather than from the firm directly, so it is reported here as relayed, not as read at first hand: the firm is described as saying that “an unauthorized actor” accessed documents and posted them on the dark web, that its “firm systems were not compromised or breached,” and that a “limited number of documents” and a “small number of affected clients” were involved. We could not read Reuters’ report or a statement on the firm’s own site.

    What the filings settle and what they do not

    Two things are established by primary record. First, Social Security numbers are in scope — that is Vermont’s own categorization on its portal, not a characterization by anyone reporting on the incident. Second, the population is not trivially small: California’s 500-resident threshold is a floor for one state, and ten Vermonters were notified in a state of roughly 650,000 people.

    Almost everything else is open. No total count of affected individuals appears in either filing. No discovery date is published. Neither portal states how the data was taken. And the firm’s own characterization — systems not compromised, documents nonetheless accessed and posted — points at some path that the firm has not described in anything we could read. A vendor, a third-party platform, a service the firm uses, an individual account: those are the ordinary candidates, and we are not going to pick one. It is worth being explicit that “our systems were not breached” and “client documents were taken and published” are not contradictory statements. They are, together, an incomplete one.

    We are also not going to attach an attacker to this. Ransomware leak-site trackers list the firm, and a claimed group name is circulating. No named victim, regulator, or filing we read attributes the incident to anyone, and this publication does not state attribution as fact.

    Why it matters

    The most useful thing about this incident is the order in which it became public. The firm’s public statement landed on September 10. The Vermont filing predates it by two days and the California filing by one, and the filings carry harder information than the statement does — a data element, a resident count, a breach date. A reader who followed only the coverage learned that the exposure was “limited.” A reader who checked two state portals learned that Social Security numbers were involved and that more than 500 Californians were notified.

    That gap is structural, not a criticism of any particular firm. A public statement is written to characterize; a state breach filing is written to satisfy a statutory disclosure form with fields for dates, counts, and data categories. The form is the part that does not compress. State attorney general portals are among the few primary sources in this field that are searchable, dated, and free, and they are checked far less often than vendor advisories are.

    The second thing worth drawing out is what a law firm’s breach means downstream, because it is not the firm’s own risk that is interesting. A firm of this size holds other organizations’ material — deal documents, litigation files, privileged communications, regulatory correspondence, and the personal data of its clients’ employees and customers. “A small number of affected clients” can be an accurate description of a compromise that is large for each of the clients involved. The unit of harm is not the law firm; it is the client whose file was in the set. Companies that received no notification because they are not the firm’s clients may still have people in those documents — opposing parties, witnesses, employees named in a matter.

    The third is the Social Security number detail, which changes what a reasonable response looks like. Document exposure without identifiers is a confidentiality problem. Document exposure with Social Security numbers is an identity-theft problem with a much longer tail, because the identifier does not rotate. Vermont’s portal records that element for this incident, which means the notification letters in at least one state told people their Social Security number was involved.

    What to do

    There is nothing to patch. The actions here are about finding out whether you are in scope.

    If your organization uses Greenberg Traurig, ask the firm directly whether your matters are in the affected set rather than waiting to be told. The firm has described the number of affected clients as small; that is a reason to ask, not a reason to assume you are outside it. Ask specifically what categories of your data were in the exposed documents, and whether any of your employees’ or customers’ personal data was in them.

    If you receive a notification letter, it will say which of your data elements were involved. Where a Social Security number is named, a credit freeze at all three bureaus is the response that actually matters, and it is free.

    If you maintain a third-party risk register, outside counsel belongs in it. Law firms are frequently omitted from vendor inventories because they are engaged by the legal department rather than procurement, and they routinely hold more sensitive material than the SaaS vendors that do get tracked. This incident is a reasonable prompt to check whether your register has one.

    If you monitor breaches as a practice, add the California and Vermont portals to what you check. Both carried this incident before it was widely reported, and both carry incidents that are never reported at all.

    Sourcing note

    The Vermont Attorney General’s security breach notice listing and the California Attorney General’s data breach list were both read directly. Vermont is the source for the September 8, 2026 report date, the count of 10 Vermont residents, and the “Social Security Numbers” data element. California is the source for the entry name “Greenberg Traurig, LLP (“GT”),” the August 26, 2026 breach date, and the September 9, 2026 reported date, and for the fact that a sample consumer notice is posted. That notice is a PDF and could not be parsed by automated fetching, so nothing from its text is reported here — it is the document most likely to answer the open questions below, and it is publicly available to anyone who can open it.

    The firm’s public statement of September 10, 2026 was not read at first hand. It was given to Reuters, and reached this story through a secondary brief summarizing that report. The quoted fragments — “an unauthorized actor,” “firm systems were not compromised or breached,” “limited number of documents,” “small number of affected clients” — are therefore reported as relayed and should be treated as weaker than the filing data above. Neither Reuters’ report nor a statement on the firm’s own website was reachable. The figure of more than 3,200 attorneys is the firm’s generally published size and is not drawn from any filing.

    Unresolved: the total number of individuals affected across all states, the discovery date, the mechanism by which documents were obtained given the firm’s statement that its systems were not compromised, whether any client organizations have been named, and whether additional state filings exist beyond Vermont and California. No attribution is asserted. Leak-site listings and claimed actor names were not treated as evidence and are not repeated here.