Full-Time
Posted on 6/13/2026
Legal, government, and business intelligence platform
$118.3k - $219.8k/yr
No H1B Sponsorship
Horsham, PA, USA
Hybrid
Hybrid near Horsham, PA; home-based options are available in New Jersey or the Northeastern U.S.
US Citizenship, US Top Secret Clearance Required
Bachelor's, MBA, JD
| , |
See people who can refer or advise you
LexisNexis Legal & Professional provides legal, government, business, and high-tech information through subscription-based access to a vast repository of licensed news publications and corporate data. Its offerings, such as Nexis AI, enable advanced research, intelligence gathering, and automatic document summarization for professionals in law firms, corporations, government agencies, and academic institutions. The platform works by delivering curated information and insights from millions of companies and publications via a search and analysis interface, helping users find accurate information quickly. The company differentiates itself with a long history of service, a broad, licensed data library across multiple sectors, and AI-powered tools that streamline research and decision-making. Its goal is to help clients make informed decisions, achieve a competitive advantage, and boost efficiency by providing trusted information and tailored analytics.
Company Size
5,001-10,000
Company Stage
Growth Equity (Non-Venture Capital)
Total Funding
$30M
Headquarters
New York City, New York
Founded
1973
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Parental Leave
Tuition Reimbursement
Hybrid Work Options
Privacy advocates call on Maryland to investigate data brokers. NPR | By Jude Joffe-Block Published August 20, 2026 at 4:00 AM CDT Maryland has passed some of the strictest data privacy provisions in the country. But privacy and civil rights advocates say commercial data brokers are violating state law by collecting and selling Marylanders' geolocation data, as well as selling information to federal immigration authorities. A coalition of privacy and civil rights groups filed a consumer complaint Wednesday that calls on the state attorney general to investigate specific companies and take enforcement action against them. The complaint comes as U.S. Immigration and Customs Enforcement has been ramping up its use of commercially-available personal data and surveillance tools to track and deport immigrants as well as monitor protesters. Two of the named data brokers, Penlink and Thomson Reuters, denied the allegations and told NPR they were in compliance with the law. The complaint alleges Penlink, Thomson Reuters, Motorola, Insight LPR, LexisNexis, Flock Safety and others, are collecting and selling personal information and location data on Maryland residents to law enforcement customers in violation of state privacy law. Penlink sells cell phone location data through its Webloc program, while the other companies sell car location data captured by license plate readers. Several of the named companies have contracts with ICE, including Penlink. Thomson Reuters and LexisNexis provide data tools to ICE that contain a wide range of personal information from public records and proprietary data sources. The complaint also names ThunderCat Technology, which has a contract with Homeland Security Investigations, which is part of ICE, to provide the agency with individual taxpayer identification numbers (ITIN) data. The complaint calls on Maryland Attorney General Anthony G. Brown to "use the full force" of the state's strong privacy laws, "and take immediate action to rein in agencies' use of commercially purchased data that enables mass surveillance of Americans without judicial, legislative, or public oversight." Georgetown University Law Center's Technology Law Clinic authored the consumer complaint on behalf of We Are CASA, which advocates for working class, Black, Latino, Indigenous and immigrant rights, and 11 other organizations that focus on privacy and civil rights, including the Center for Democracy & Technology and the Electronic Privacy Information Center. "Through our direct services programming, we have witnessed parents worried about updating their address with state agencies, individuals increasingly cautious about engaging with any institution that collects personal data, even if they meet the program's eligibility requirements," said George Escobar, the executive director of We Are CASA in a statement. "Ensuring a more equitable Maryland for all starts with an investigation of these data companies and strict enforcement of our values as laid out in state law," the statement continued. A statement provided to NPR by Thomson Reuters reads, "We are confident that we are in compliance with all applicable laws and regulations governing our business and operations." The company specifies on its website that the license plate recognition product it offers, "is not capable of tracking real time locations of a vehicle; it provides access to ad hoc images collected randomly." Penlink also denied that it was violating state law. "The allegations against Penlink in the complaint are false, as Penlink does not process or sell precise location data of Marylanders in accordance with Maryland privacy law," reads a company statement provided to NPR. "Penlink complies with applicable U.S. privacy laws and data-broker regulations, and we will continue to update our practices as data and privacy laws evolve." Maryland's law defines "precise geolocation data" as "information derived from technology that can precisely and accurately identify, within a radius of 1,750 feet, the specific location of a consumer, a mobile device, or a vehicle." The complaint alleges that Penlink's products are being used by Maryland agencies. Penlink did not respond to NPR's questions about Baltimore County Police Department's contract for Webloc, which was previously reported by Citizen Lab, or a proposed contract upgrade with Maryland State Police for Penlink's PRX product. State records proposing that contract list "geolocation information" as part of the tool's capabilities. None of the other named companies responded to NPR's request for comment by deadline. Multiple emails to Flock Safety resulted in the same automated response: "Our media team is currently touching grass and taking a break. Unlike our cameras, we can't work 24/7, so we'll get back to you when we've had a snack and regained the ability to form coherent sentences." Many law enforcement agencies purchase sensitive data on Americans from data brokers to learn intimate details about where they go, who they meet with and where they live - without needing to obtain a warrant. Advances in artificial intelligence are quickly making such data products even more powerful. Lawmakers from both parties have argued that law enforcement should not be able to purchase data they would otherwise need a warrant to obtain, since such data purchases circumvent protections granted by the Fourth Amendment, which prohibits "unreasonable searches and seizures." But Congress has yet to pass a law that would close this so-called "data broker loophole." Maryland lawmakers, however, have attempted to put restrictions on what data brokers can do with its residents' data. The Maryland Online Data Privacy Act passed in 2024, and state lawmakers passed additional updates to that law in the most recent legislative session that took effect last month. The Maryland attorney general's office declined to comment on the consumer complaint. When NPR inquired with the office in late June about the new data privacy provisions taking effect July 1, spokesperson Kelsey Hartman told NPR, "Entities subject to the law should ensure they are in compliance." Under current Maryland law, data brokers are barred from collecting or sharing state residents' sensitive data, including location data, unless it is to deliver a product or service the consumer requested, or in response to certain law enforcement demands. Data brokers are barred from selling or sharing Marylanders' location data unless law enforcement has gone through a legal process to obtain a subpoena or warrant. State law also bars data brokers from selling information to agencies that enforce immigration law, unless the law requires it or they receive a warrant. The complaint argues the named companies are violating the law by selling location data, or by selling to ICE, or in some cases - both. "If these practices are allowed to proceed, federal agencies will effectively be able to circumvent constitutional limits and judicial oversight altogether, and to conduct dragnet searches and go on fishing expeditions through Marylanders' private lives in ways that they should not be able to do," the complaint warns. New Jersey, Virginia, Oregon and Connecticut also recently banned the sale of some categories of sensitive data, including geolocation data. Maryland's law is unique for its rules barring data brokers from selling personal data to entities that assist with immigration enforcement, said Greg Nojeim, director of the Center for Democracy and Technology's Security and Surveillance Project. Data brokers in Maryland cannot comply with an ICE subpoena to seek a Marylander's sensitive data, instead ICE must present a warrant, Nojeim said. "This is important because ICE has abused its administrative subpoena authority to silence people who point out ICE abuses," Nojeim said. "Maryland is telling ICE, 'Get a warrant if you want Marylanders' sensitive data.'"
LexisNexis acquires Globe Law and Business, expanding its specialist legal content. iCrowdNewswire Aug 12, 2026 9:30 AM ET LONDON, 12 August 2026 - LexisNexis(R) Legal & Professional, a global leader in information, analytics and AI-powered legal workflow solutions, today announced it has acquired Globe Law and Business, a small, well-regarded UK-based publisher of specialist legal information. The acquisition adds specialist, practitioner-authored titles to the LexisNexis authoritative legal content library, which powers LexisNexis legal AI solutions, including Lexis+(R) with Protégé(TM). Founded in 2005 and based in London, Globe Law and Business publishes 300 specialist titles written by practitioners from top commercial law firms, senior academics and in-house counsel. Its portfolio covers energy, banking and finance, insolvency, arbitration, intellectual property, private client and law firm management practice areas. Founder and Managing Director Sian O'Neill remains with the business following the acquisition. LexisNexis Legal & Professional maintains one of the world's most comprehensive repositories of trusted, verifiable legal content, with more than 200 billion documents and records, and four million new documents added daily. This essential, unique and constantly updated legal content is enriched, linked and structured to ground the company's leading legal AI solutions. In Lexis+ with Protégé, this authoritative content powers agentic AI legal skills and workflow capabilities that help legal professionals draft, analyse, research and complete legal work with greater speed, accuracy and confidence. Financial terms were not disclosed. About LexisNexis(R) Legal & Professional LexisNexis(R) Legal & Professional provides AI-powered legal, regulatory, business information, analytics, and workflows that help customers increase their productivity, improve decision-making, achieve better outcomes, and advance the rule of law around the world. As a digital pioneer, the company was the first to bring legal and business information online with its Lexis(R) and Nexis(R) services. LexisNexis Legal & Professional, which serves customers in more than 150 countries with 11,900 employees worldwide, is part of RELX, a global provider of information-based analytics and decision tools for professional and business customers. Contact information: Name: Jill Van Nostran Email: [email protected] Job Title: VP, Communications & Global PR
LexisNexis suspends services following suspicious server activity. Publish Date: 2026-08-10. Description. LexisNexis temporarily took its Nexis Diligence, Nexis Metabase API, and Nexis Newsdesk services offline after detecting unusual activity on servers hosted and managed by an unnamed third-party vendor. The company disconnected from the affected systems to contain the incident and is investigating with an external cybersecurity forensics firm. LexisNexis is rebuilding the affected services in a new environment before restoring them. The company has not confirmed the exact nature of the activity, whether data was accessed or stolen, or whether the incident was caused by a specific threat actor. The affected services support due diligence, risk research, news and media data integration, and media monitoring for organizations such as corporations, law firms, financial institutions, government agencies, and compliance teams. LexisNexis clarified that its Nexis Metabase API is unrelated to the recently reported Metabase Cloud attacks involving a critical SQL injection vulnerability. Therefore, there is currently no indication that the Metabase Cloud vulnerability caused the LexisNexis service disruption. The incident follows previous security events involving LexisNexis, including a 2025 breach affecting approximately 364,000 individuals after attackers accessed private GitHub repositories and a 2026 intrusion involving AWS infrastructure that resulted in limited server access and the theft of legacy files. The current investigation remains ongoing, and LexisNexis has not disclosed whether customer information was compromised. * Affected Platform(s) / Version(s) * Nexis Diligence, Nexis Metabase API and Nexis Newsdesk * Distribution Method * Undisclosed * Attack Type * NA * Attack Source * NA * Region * Global * Affected Business(s) * Multiple Sectors * Recommendations * * Monitor LexisNexis service-status and security notifications for restoration and incident updates. * Review integrations with affected Nexis services for authentication or connectivity anomalies. * Rotate relevant API credentials if compromise cannot be ruled out. * Monitor logs for unusual API activity, unauthorized access, or unexpected data transfers. * Assess third-party hosting dependencies and require appropriate incident-notification and containment procedures. * Preserve relevant logs and telemetry to support forensic investigation. * References * * https://www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/ Protect your data and brand value from data breaches! DeadLock ransomware disables security defenses and backups before file encryption. DeadLock is a financially motivated ransomware operation first identified in July 2025. It follows a double-extortion model, encrypting organizational data while threatening to lea... Published Date: 2026-08-11 Android banking malware adopts dropper-based delivery to evade app-store detection. Android banking-malware operators are increasingly adopting dropper-based delivery to bypass mobile application-store controls and conceal financial payloads during initial applica... Published Date: 2026-08-11 Play ransomware masquerades as psexec to enable stealthy lateral movement. The ransomware campaign Play is now increasingly leveraging trusted Windows administration functionality to disguise its activity as part of a legitimate workflow process. Specifi... Published Date: 2026-08-11 This website uses COOKIES in order to offer you the most relevant information. Please accept cookies for optimal performance.
The Metabase zero-day: what a CVSS 10.0 breach teaches website owners about forgotten tools. On August 3, 2026, attackers exploited an unknown flaw to breach Metabase's own cloud platform - and rode it straight into customer databases at laptop maker Framework and form builder Tally. The vulnerability didn't have a name yet, and the company that makes the software didn't know about it either. Four days later, it was public: a perfect 10.0-rated flaw, already being exploited in the wild. This is the story of that breach, and the one lesson every website owner should take from it: the tools you self-host are part of your website's security, whether you remember them or not. What happened. Metabase is a free, open-source analytics tool that thousands of small businesses run to build dashboards from their data. It's the kind of software someone installs "on a quiet Friday" - free, easy to set up, and then quietly forgotten while it keeps holding something valuable: the connection credentials for the databases it reports on. On August 7, Metabase disclosed that its Cloud platform had been attacked, starting around August 3, through a previously unknown vulnerability - a zero-day. The flaw is an unauthenticated SQL injection in the password reset flow. In plain terms: an attacker with no login credentials could inject commands into the application's database, take over the administrator account, change the configuration, steal the stored credentials for every connected database, and export the data those databases could reach. The severity rating is the maximum possible: CVSS 10.0. As of disclosure, the flaw had no CVE identifier yet - it's being tracked under an advisory ID (GHSA-vwf4-m7j8-wcjf) instead. That matters practically: automated security scanners that only check against the official CVE database won't flag an exposed instance until one is assigned. If you're relying on a scanner alone, this is exactly the kind of gap it can miss. Three companies have so far confirmed impact: * Framework, the laptop maker, told customers that names, email addresses, billing and shipping addresses, phone numbers, and company data were stolen from its Metabase instance. * Tally, the online form builder, confirmed its analytics environment was compromised - customer email addresses and password hashes were taken (its forms and submitted answers are stored separately and were not reached). * LexisNexis reported service disruptions after unusual activity at a third-party vendor hosting Metabase on its behalf, and disconnected the affected systems while it investigated. Framework and Tally were both hit through Metabase's own Cloud SaaS platform - meaning the breach happened at the vendor's end, not because either company forgot to patch something. Metabase has since confirmed it blocked the malicious endpoints and pushed a fix, and every Metabase Cloud customer was patched automatically. Self-hosted instances got no such rescue. Metabase shipped fixed versions for self-hosted users too, but applying them is entirely down to whoever runs the instance - which is exactly the population that usually doesn't have a scheduled patch window for a tool most people forgot was internet-adjacent. Why this matters to website owners. There are two separate lessons buried in this one incident, and both apply even if you've never heard of Metabase. * Even the vendor can get zero-dayed. Metabase Cloud is the "someone else handles the security" option - and it still got hit by a flaw nobody knew existed. That's not a knock on Metabase; zero-days happen to well-run software too. But it's a reminder that "we pay for the managed version" reduces risk, it doesn't eliminate it. * If you self-host, you are the vendor. When a flaw is found in a cloud service, the provider patches everyone at once - which is what happened for Metabase Cloud customers here. When you run the software yourself, nobody is doing that job for you: not the vendor, not your hosting provider, not your developer, unless you specifically asked them to. The fix for this flaw existed within days of disclosure. The open question for every self-hosted install is simply: who applies it, and when? Both lessons point at the same blind spot: every website owner has a version of this story somewhere - a free analytics dashboard, a booking widget, an admin panel, a monitoring script - installed once, working fine, and then nobody's job. These tools sit next to your website, sometimes on the same server, often holding the same database credentials your shop runs on. They are not "just a dashboard." They are a second front door, and the attacker in this case didn't need to break into the database directly - they logged in through the reporting tool that was already allowed to. If you work with an agency or developer, this applies too: the person who manages your site may be running analytics or admin tools on your behalf. It's a fair question to ask - what runs on its servers, and who patches it? What to do. If you run a self-hosted Metabase instance: update to the patched version for your branch (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5 - whichever applies). If you genuinely can't update this week, the vendor's temporary workaround is to block access to the /api/session/reset_password endpoint. That is a stopgap, not a fix. Patching is only half the job. Metabase published a specific signature for the attack: a POST to /api/session/reset_password returning an HTTP 400 status, followed by a successful request to /api/user/current. If your logs show that pairing, treat the instance as compromised. The vendor also recommends revoking all active sessions, reviewing API keys and administrator accounts, rotating the credentials for every connected database, and reviewing query history for anything unexpected. If you use Metabase Cloud: you don't need to patch anything yourself - that's already been done. It's still worth reviewing your Metabase user accounts and connected database credentials as a precaution, since the exploitation window predates the public disclosure. For everyone else: the actionable version of this story is an inventory. List the tools you run that aren't your website - dashboards, analytics, booking systems, email tools, anything that connects to customer data. Next to each one, write down whether it's self-hosted or managed by a vendor, and who updates it and when it was last updated. If a self-hosted tool has no owner, it's a risk - not because it's malicious, but because when a 10.0-rated flaw comes out, nobody will be standing by to patch yours. And when a serious vulnerability is announced - regardless of which tool it affects, and regardless of whether it has a CVE number yet - treat patching as a this-week task, not a this-quarter task. The gap between "patch available" and "exploited in the wild" is measured in days. Key numbers. | Number | What it means | | 10.0 | CVSS severity - the maximum possible score | | 3 | Companies publicly affected so far: Framework, Tally, LexisNexis | | 3 Aug | Earliest confirmed date attackers exploited the flaw | | 7 Aug | Public disclosure of the zero-day | | 6 | Affected software branches, 0.58 through 0.63 | | 0.63.5 | Highest minimum safe release across the affected branches | Final takeaway. A perfect-10 vulnerability was exploited for days before anyone knew it existed - and it hit companies with real customers and real reputations, through both a managed cloud platform and (potentially) self-hosted installs. The defense isn't exotic. It's knowing what runs on your servers, knowing whether you or someone else owns the patching for it, and moving fast when a fix ships. Your website's security isn't just your website. Related reading: Not sure what's running behind your website? Not every risk shows up in an automated check. If you're unsure which tools, plugins, or dashboards touch your customer data, a short conversation with its team is free and obligation-free.
Metabase sqli zero-day exploited: data theft attacks confirmed. This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy Key points * " Metabase Cloud and self-hosted instances are compromised via a critical SQL injection zero-day, leading to customer data theft. * " Affected systems include Metabase versions 1.58 and above, including 0.58.x through 0.63.x branches. * " Immediately upgrade self-hosted Metabase instances to patched versions and follow post-compromise remediation steps. A critical, unauthenticated SQL injection zero-day vulnerability in Metabase, affecting versions 1.58 and above, has been actively exploited in the wild, leading to data theft from customer instances. Metabase, a popular open-source business intelligence platform, disclosed the attacks, confirming that its Metabase Cloud SaaS platform was compromised. Self-hosted installations are also vulnerable if not updated, posing a significant risk to organizations utilizing the platform, according to BleepingComputer. Metabase has identified and blocked the attack endpoints, subsequently rolling out a fix for the vulnerability. This unauthenticated SQL injection flaw allows a remote attacker to gain administrator access to a customer's Metabase instance. With administrative control, attackers can alter application configurations, steal stored credentials for connected databases, access any data available through those connections, and export sensitive information. Technical details of the Metabase sqli zero-day vulnerability. The zero-day, described by Metabase as a 'CRITICAL' vulnerability with a CVSS score of 10.0, enables attackers to inject arbitrary SQL into the Metabase application database. This critical flaw grants immediate administrative access without requiring any prior authentication. The broad capabilities afforded by this access include: * Configuration Manipulation: Attackers can modify Metabase application settings. * Credential Theft: Stored credentials for any connected databases can be exfiltrated. * Data Exfiltration: Any data accessible via database connections can be read and exported. The exploitation of this vulnerability has already impacted several organizations. Laptop manufacturer Framework confirmed that its Metabase instance was compromised on August 3, leading to the theft of customer information. This data included full names, email addresses, login IP addresses, billing and shipping address information, phone numbers, and company names. For Framework for Business customers, additional data such as VAT, EIN, and billing email addresses may also have been exposed. Online form builder Tally also reported a compromise of its Metabase analytics environment on August 3. Attackers accessed email addresses and cryptographic hashes of user passwords. Tally clarified that user forms and submitted answers, stored separately, were not affected. LexisNexis, while not explicitly linking its incident to this specific Metabase API vulnerability, confirmed that its Metabase API was impacted by a cyberattack on a third-party vendor earlier this week, causing service disruptions. Metabase states that all its Cloud customers have been automatically upgraded and patched. However, organizations running self-hosted Metabase instances must perform manual updates to secure their systems against this active threat. Mitigation and remediation for Metabase 1.58+ unauthenticated SQL injection. Given the active exploitation and critical nature of this vulnerability, immediate action is paramount for all self-hosted Metabase users. The following steps are crucial for Metabase 1.58+ unauthenticated SQL injection remediation: * Immediate Upgrade: Update all vulnerable Metabase installations to the patched versions. The minimum safe releases are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5. * Temporary Workaround: If immediate upgrading is not possible, temporarily block access to the /api/session/reset_password endpoint. This serves as a critical, albeit temporary, measure to prevent exploitation. * Post-Compromise Actions: For any potentially compromised instances, Metabase strongly recommends: * Revoking all active user sessions. * Reviewing API keys and administrator accounts for any unauthorized changes. * Rotating credentials for all connected databases. * Inspecting application logs and query history for signs of compromise. How to detect Metabase data theft compromise. Organizations should actively look for indicators of compromise (IOCs) in their system logs to detect Metabase data theft compromise. Attacks can be identified by a POST request to /api/session/reset_password returning a 400 status code, immediately followed by a successful GET request to /api/user/current. The presence of these entries in system logs strongly suggests that an instance has been compromised, and a full forensic investigation should be initiated immediately.