VYPR
researchPublished Sep 21, 2026· 1 source

Check Point Research Details Multiple Cyber Incidents, Including Japan Digital Agency Breach and AI Threats

Check Point Research's latest threat intelligence report highlights a range of cyber incidents, from a significant data breach at Japan's Digital Agency to evolving threats in the AI landscape.

Check Point Research has released its latest threat intelligence bulletin, detailing a diverse array of cyber incidents that occurred during the week of September 21st, 2026. The report underscores the persistent and evolving nature of cyber threats across various sectors.

A significant data breach impacted Japan's Digital Agency, which manages the Government Solution Service utilized by multiple ministries. Attackers successfully exploited a vulnerability within a VPN appliance, leading to the exposure of approximately 246,000 records. These records contained sensitive information such as names and contact details of government officials and contractors, though financial data was reportedly unaffected.

In a separate incident, two oil tankers en route to Texas experienced disruptions due to cyberattacks. While US Coast Guard and FBI personnel investigated the onboard systems, officials confirmed malicious cyber activity on the VL Prosperity. However, no specific threat actor has been publicly attributed to these attacks.

The report also details a supply chain attack affecting Brevo, a French customer communication and marketing platform. Threat actors gained access to a compromised Cloudflare API key, which they used to inject malicious ClickFix scripts into websites utilizing Brevo components. This attack compromised an estimated 100,000 websites.

Further compounding the breach landscape, Japanese software company Helpfeel, known for its image-sharing service Gyazo, reported a data breach. Attackers exploited a vulnerability in an image upload server, resulting in the exposure of over 23 million user records and 490 million image metadata records. This included email addresses, password hashes, session IDs, integration tokens, and location metadata.

Beyond traditional infrastructure attacks, Check Point Research also analyzed the growing threat landscape surrounding Artificial Intelligence (AI). The report highlights how AI is increasingly being weaponized by attackers for operational efficiency, while AI systems themselves are becoming targets. This includes the emergence of AI-assisted ransomware, criminal markets for stolen AI model access, and vulnerabilities in AI coding agents and enterprise copilots.

Researchers uncovered 'Luciferus,' an uncensored AI service advertised on underground forums for creating malware and other illicit activities. Testing demonstrated its capability to generate code for a basic remote access trojan. Additionally, the 'BragJack' attack was detailed, which allows malicious browser extensions to hijack AI assistants by forcing prompts through trusted browser channels, potentially enabling unauthorized access to files, screenshots, and microphone/camera usage before vendors could issue fixes.

The bulletin also covers critical vulnerabilities and patches. Check Point released a fix for CVE-2026-91843, a critical flaw in its Security Management and Log Servers. Cisco addressed two critical vulnerabilities in its ISE and Secure Email Gateway products, with active exploitation noted for one. Oracle's September Critical Security Patch Update addressed over 800 vulnerabilities, and ISC released updates for BIND 9 to fix 14 vulnerabilities, including several high-severity denial-of-service flaws.

Synthesized by Vypr AI
Check Point Research Details Multiple Cyber Incidents, Including Japan Digital Agency Breach and AI Threats · VYPR