Check Point Research Details Diverse Cyber Threats in August Threat Intelligence Report
Check Point Research's latest bulletin highlights a range of cyber incidents, including attacks on ports, data breaches, and vulnerabilities in AI tools and network devices.

Check Point Research's latest Threat Intelligence Bulletin, published on August 10th, 2026, provides a comprehensive overview of the cyber threat landscape, detailing numerous attacks, data breaches, and newly discovered vulnerabilities across various sectors.
The report highlights significant operational disruptions, such as a cyberattack on North Carolina Ports that forced a shift to manual processes and caused delays. In the consumer sector, electric scooter operator Ryde disclosed a data breach affecting all 4.5 million customer accounts across Scandinavia, exposing personal information like phone numbers, email addresses, and birth dates, though payment card details remained secure. A more financially impactful incident involved Canadian hardware wallet maker Coinkite, which reported the theft of at least 1,367 Bitcoin, valued at approximately $88.6 million, due to the exploitation of a Coldcard firmware vulnerability. Additionally, UK-based charity software provider Beacon experienced a data breach after an access key compromise, potentially exposing database information and donation records for around 1,500 nonprofit customers.
In the realm of Artificial Intelligence, Check Point Research identified several critical vulnerabilities. Five flaws were found in Cloudflare Code Mode, stemming from the workerd runtime, which could lead to sandbox escapes and cross-tenant data exposure. Cloudflare has since patched its managed Workers environment. Researchers also disclosed vulnerabilities in Google Gemini CLI and Anthropic Claude Code, with CVE-2026-12537 (CVSS 10.0) affecting Gemini CLI workflows and CVE-2026-54316 impacting Claude Code. Both Google and Anthropic have released patched versions, addressing risks of code execution and API key theft. The report also details AI-enabled identity fraud kits, such as ProKYC, capable of automating know-your-customer (KYC) bypasses for financial institutions and cryptocurrency exchanges by generating fake identity documents and synthetic media.
Several significant vulnerabilities and patches were also detailed. Cisco released fixes for critical flaws in Catalyst SD-WAN and IOS XE software, some carrying CVSS scores up to 9.9, which could lead to privilege escalation and system compromise. WordPress addressed CVE-2026-64638, a high-severity XSS2Shell vulnerability in its core login functionality that could be chained to achieve remote code execution. TP-Link patched 15 vulnerabilities across its Omada provisioning ecosystem, including risks of device impersonation and remote code execution. A concerning discovery was a vendor-installed backdoor found in at least 20 Zbtlink router models, allowing unauthenticated commands with root privileges.
The report also sheds light on sophisticated threat campaigns. The Shai-Hulud CHAINDROP supply-chain campaign backdoored over 400 npm packages, affecting an ecosystem with billions of monthly downloads by stealing developer tokens. Threat actors tracked as UNC6671 are targeting large US financial firms through social engineering, impersonating IT staff to steal credentials and multi-factor authentication codes, followed by ransom demands. A macOS ClickFix campaign uses hundreds of look-alike domains to distribute MacSync and Atomic Stealer malware, evolving to fingerprint visitors to evade detection. Furthermore, a campaign uploaded nearly 800 malicious npm packages delivering cross-platform RAT and infostealer malware, utilizing Cloudflare Workers and DNS TXT records for payload delivery.
This comprehensive report underscores the dynamic and multifaceted nature of current cyber threats, spanning critical infrastructure, financial services, consumer data, and the rapidly evolving AI landscape. The detailed findings serve as a crucial resource for organizations to understand and defend against the latest attack vectors and vulnerabilities.