Check Point Research Details Diverse Cyber Threats in August Threat Intelligence Report
Check Point Research's latest bulletin highlights a range of cyber incidents, including attacks on ports, data breaches, and vulnerabilities in AI tools and network devices.

Check Point Research's weekly threat intelligence report for the week of August 17th, 2026, details a multifaceted landscape of cyber threats, encompassing ransomware attacks, significant data breaches, and emerging AI-driven espionage campaigns.
In the realm of ransomware, Colombia's Ministry of Justice fell victim to an attack that encrypted some of its files, disrupting public services related to drug monitoring and legal processes. While officials confirmed no data theft, the incident underscores the persistent threat of ransomware to critical government infrastructure.
Poland's primary healthcare platform, MyDr, experienced a severe data breach affecting nearly 19 million citizens. Attackers claimed to possess 2.5TB of sensitive information, including personal details and medical records, and provided evidence of the compromise by leaking a politician's data. This breach highlights the vulnerability of healthcare systems and the vast personal data they hold.
Global apparel company Levi Strauss & Co. reported a cyberattack involving social engineering tactics that compromised employee devices and led to the theft of corporate information. The company stated that no consumer data was accessed, but the incident serves as a reminder of the human element in cybersecurity and the effectiveness of social engineering.
AI continues to be a significant vector for cyber threats. Researchers detailed a suspected China-linked campaign utilizing autonomous AI agents against Taiwanese government systems, mapping numerous systems, compromising accounts, and exfiltrating personnel records. Concurrently, North Korea-linked Kimsuky is reportedly building an offline AI environment to enhance its cyberespionage capabilities, integrating local language models for phishing, intelligence analysis, and malware development.
The report also touches upon vulnerabilities in AI models themselves, noting that encrypted reasoning blocks from major AI providers like OpenAI, Anthropic, and Google could be replayed across sessions. This analysis recovered sensitive artifacts such as API keys, passwords, and private cryptographic keys from published agent logs, indicating potential risks associated with the deployment and logging of AI agents.
In terms of software vulnerabilities, Microsoft's August Patch Tuesday addressed 421 flaws, including an actively exploited Windows Ancillary Function Driver for WinSock vulnerability (CVE-2026-68820) that allows local privilege escalation. Apple released patches for a critical macOS Screen Sharing authentication vulnerability (CVE-2026-65400), which has been actively exploited for cryptomining. Adobe also fixed a critical authentication vulnerability in Adobe Commerce (CVE-2026-71362) that was being exploited shortly after disclosure, and Zoom addressed three critical vulnerabilities in its Workplace application, including one enabling remote code execution during meetings.
Check Point Research also exposed a new wave of the Lazarus Group's 'Operation Dream Job,' targeting defense organizations with fraudulent job offers and exploiting a Windows zero-day. Their analysis of Q2 2026 ransomware activity revealed a 33% year-over-year increase in publicly reported victims and the expansion of the ransomware ecosystem to 93 active groups. Furthermore, organizations faced an average of 2,336 weekly cyberattacks in July 2026, a 16% increase from the previous year, with generative AI usage contributing to corporate information exposure through high-risk prompts.