VYPR
advisoryPublished Aug 31, 2026· 1 source

Check Point Research Details Diverse Cyber Threats in August Threat Intelligence Report

Check Point Research's latest bulletin highlights a range of cyber incidents, including attacks on airports, government agencies, and medical device companies, alongside new AI-driven threats and critical software vulnerabilities.

Check Point Research has released its weekly threat intelligence report for the week ending August 31st, detailing a wide array of cyber incidents and emerging threats. The report highlights significant breaches affecting major organizations, including Manchester Airports Group, which disclosed a cyberattack exposing data for approximately 8.7 million customers. The compromised information encompasses contact details, vehicle registration numbers, and data from various airport services.

In the public sector, the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a cyberattack on a standalone computer containing investigation target information. The Qilin ransomware group claimed responsibility for this incident and listed the agency on its dark web leak site. Meanwhile, global medical device company Boston Scientific experienced a widespread cyberattack that disrupted operations and affected access to internal systems, including those supporting order processing and shipping.

The healthcare sector was also impacted by a data breach at McKesson, a major U.S. pharmaceutical company. Threat group ShinyHunters claimed to have exfiltrated approximately 1TB of data, containing around 284 million patient-related records, after compromising Okta accounts and accessing Salesforce and Snowflake instances.

Beyond traditional breaches, the report delves into emerging AI threats. Researchers detailed "Cryptographic Context Injection," a technique that hides malicious instructions within encrypted content to bypass AI assistant safeguards, impacting models like Grok and Gemini. A prompt injection vulnerability in Amazon Kiro was also identified, allowing malicious workspace files to manipulate the AI agent and exfiltrate local information.

Furthermore, the report profiles "AnonyMousKIT," an AI-enabled phishing-as-a-service operation that targets owners of stolen iPhones. This service employs a multi-channel approach, including AI-generated voice calls, to steal Apple IDs and authentication codes, facilitating the removal of Activation Lock and unauthorized account access.

The bulletin also covers critical vulnerabilities and patches. PaperCut released emergency fixes for two actively exploited vulnerabilities (CVE-2026-81578 and CVE-2026-82078) in its NG and MF products, which can be chained for unauthenticated remote code execution. Ubiquiti patched 21 critical and high-severity flaws across its UniFi product line, including several with CVSS scores of 10.0. Vercel addressed two critical vulnerabilities in Next.js, and ServiceNow released fixes for three critical vulnerabilities in its AI Platform, also rated CVSS 10.0, involving code injection and SQL injection.

Additional threat intelligence includes a large-scale phishing campaign using fraudulent debt-relief emails, the disruption of China-linked platforms QScan and QTRouter targeting U.S. critical infrastructure, an expanded toolset used by Iran-linked Nimbus Manticore, and a Chinese threat actor exploiting ownCloud and WordPress vulnerabilities against sensitive organizations in the Philippines.

Synthesized by Vypr AI