Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks

The Solicitors Regulation Authority (SRA), the regulatory body for the UK's legal sector, issued a warning notice on August 17, reminding solicitors and law firms of their obligations regarding the safe and responsible use of artificial intelligence. The SRA highlighted two primary areas of concern: AI-generated "hallucinations" in legal work and court submissions, and the potential for data leaks involving confidential client information.
The SRA stated that it has observed instances of AI hallucinations, with both solicitors self-reporting issues and senior members of the judiciary reporting potential breaches of the SRA's Code of Conduct. These hallucinations involve AI systems producing false or inaccurate information, including non-existent case law authorities. The regulator emphasized that presenting such false material to the court could lead to serious consequences, including potential contempt of court.
Another significant concern is the entry of confidential client data into public AI tools. The SRA noted that this practice raises serious data protection and confidentiality issues. It warned that using both free and paid-for AI systems without appropriate contractual, technical, and organizational safeguards could breach client confidentiality. The SRA stressed that client information must always remain within a secure environment.
The regulator underscored that solicitors and regulated individuals remain fully accountable for any AI output. Firms are expected to implement effective governance structures, systems, and controls to manage AI-related risks. The SRA also clarified that those supervising junior or unauthorized colleagues could be held responsible if false citations are presented to the court.
The SRA's approach to regulation is outcomes-based, meaning it sets the expected standards but does not dictate specific methods for achieving them. The warning notice provided a comprehensive list of considerations for the legal profession, emphasizing the need for appropriate human oversight, informed professional judgment, and a risk-based approach to ensure compliance with regulatory and legal obligations.
The SRA cautioned that these incidents can result in poor client outcomes, slow down case progression, and damage public trust in the legal profession. The Law Society of England and Wales affirmed that solicitors have a duty to use AI and other technologies responsibly to act in their clients' best interests, and called for continued clear guidance from the SRA as AI use evolves.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed