VYPR
researchPublished Sep 7, 2026· 1 source

Check Point Research Details Diverse Cyber Threats in September Week 1

Check Point Research's latest threat intelligence report highlights breaches at Thomson Reuters and Dropbox, an AI-assisted ransomware attack, and critical vulnerabilities in SonicWall and JFrog products.

Check Point Research's latest threat intelligence bulletin for the week of September 7th, 2026, paints a broad picture of the current cyber threat landscape, detailing significant breaches, novel attack techniques, and critical vulnerabilities across various sectors.

The report opens with a series of high-profile breaches. Thomson Reuters disclosed a breach affecting its C-Track court case-management platform, exposing court records across 11 US states and Canada. Separately, global cloud storage provider Dropbox reported unauthorized access to approximately 5,000 accounts, a compromise facilitated by attackers exploiting Lenovo's email verification process. In the gambling and tourism sector, Slovenian operator Hit sustained a cyberattack that forced the closure of six casinos for three days, with some services remaining unavailable during restoration. Baylor Genetics, a US clinical diagnostic laboratory, also disclosed a data breach affecting 2.8 million patients and employees, with stolen data including names, birth dates, medical records, and some Social Security numbers.

A particularly concerning development highlighted by researchers is an AI-assisted ransomware intrusion that managed to compromise an enterprise network in under 10 hours. This sophisticated attack utilized autonomous agents to map internal systems, extract credentials from secrets managers, and abuse cloud resources, dramatically accelerating the timeline typically associated with such intrusions. The report also details GitSpawn, a new vulnerability class affecting AI coding agents like Claude Code and Codex, where malicious repository configurations can trigger arbitrary code execution on developer machines. Furthermore, researchers demonstrated how AI can accelerate exploit development for industrial systems by assisting in porting known exploits to different Programmable Logic Controller (PLC) models.

In terms of vulnerabilities and patches, SonicWall has addressed two critical zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, affecting its SMA 1000 remote access gateways. CVE-2026-83548 is a pre-authentication SSRF flaw with a CVSS score of 10.0, while CVE-2026-83549 allows post-authentication remote code execution. Both were actively exploited in the wild. JFrog has also patched CVE-2026-82329, a critical authentication bypass vulnerability in its self-hosted Artifactory deployments, which was observed being exploited shortly after its disclosure. Additionally, a zero-day privilege escalation technique named FalconFlank was unveiled, affecting CrowdStrike Falcon on Windows 11 and Windows Server 2025, by abusing the product's remediation behavior.

The report also sheds light on several ongoing threat campaigns. A Chinese-speaking cybercrime cluster, dubbed Gambling Goblin, has been observed compromising Brazilian government and education websites to redirect visitors to gambling and phishing pages. Another threat actor, Iran-linked Mirage Kitten, is using fake LinkedIn coding tests to distribute NodeRabbit and PollCat malware, targeting organizations in Egypt, Ethiopia, and Afghanistan. Check Point researchers also analyzed JSCeal, a cryptocurrency-focused information stealer compiled into V8 bytecode, which employs keylogging and credential theft techniques, with newer variants targeting macOS.

Further analysis delves into North Korea's Contagious Interview campaign, which uses fake job interviews and trojanized disk images to deliver malware to macOS users, with infrastructure linked to previous malicious Git hooks. The report also provides protection details for Check Point IPS and Harmony Endpoint against several of these threats, including the JFrog Artifactory Authentication Bypass and the Gambling Goblin campaign.

This comprehensive report underscores the dynamic nature of cyber threats, from sophisticated AI-driven attacks and zero-day exploits to widespread data breaches and targeted espionage campaigns. The findings emphasize the need for continuous vigilance, rapid patching, and robust security solutions to defend against an ever-evolving threat landscape.

Synthesized by Vypr AI