VYPR
advisoryPublished Sep 14, 2026· 1 source

Check Point Research Uncovers Wide-Ranging Threats: Data Breaches, AI Exploits, and Critical Vulnerabilities

Check Point Research's latest threat intelligence report details significant data breaches at IDScan.net and Mathspace, novel AI attack techniques, and numerous critical vulnerabilities across major software vendors.

Check Point Research has released its latest threat intelligence report, detailing a broad spectrum of cyber threats observed during the week of September 14th, 2026. The report highlights several significant data breaches, including one affecting IDScan.net, a US-based identity verification provider. The breach, discovered on September 1st, exposed customer names and government identification numbers. A criminal marketplace subsequently advertised a massive collection of identity documents, reportedly linked to the company's services, raising concerns about widespread identity theft.

Another notable incident impacted Mathspace, an educational platform used in Australia and New Zealand, which suffered a data breach affecting over one million individuals. Attackers exploited CVE-2026-72898, a vulnerability in the self-hosted Metabase tool, to gain access to an internal reporting database. While passwords and academic records remained unaffected, the breach exposed personal information such as names, email addresses, usernames, and locations.

The report also delves into emerging threats in the artificial intelligence landscape. Researchers detailed 'PuzzleMask,' a sophisticated prompt injection technique designed to bypass security filters in large language models (LLMs). This method allows malicious instructions to be hidden from initial gatekeepers while being recoverable by more powerful target models, demonstrating a significant evasion capability. Furthermore, a covert cross-account channel exploit within ChatGPT's code-execution environment was demonstrated, enabling hidden tasks to access and exfiltrate data from a victim's connected applications, such as Gmail.

In the realm of software vulnerabilities, Microsoft's September Patch Tuesday updates addressed an unprecedented 974 flaws, including two actively exploited zero-day vulnerabilities (CVE-2026-85880 and CVE-2026-81963) that allow for privilege escalation to SYSTEM. Additionally, GitLab released a patch for CVE-2026-85706, a critical path traversal vulnerability with a CVSS score of 10.0, enabling unauthenticated attackers to read arbitrary files. MikroTik also addressed two vulnerabilities, CVE-2026-67276 and CVE-2026-86060, which can be chained to achieve passwordless SSH access and full administrator privileges on affected routers.

The report further touches upon a social engineering campaign targeting Microsoft 365 accounts using passkey lures, directing users to fake login pages. It also details an Android banking-fraud campaign by the GoldFactory group, which utilizes the 'Vwork' tool to clone banking applications and has resulted in significant financial losses. The BlueMoon exploit chain, combining vulnerabilities in Chromium's V8 engine and a Windows flaw, was also highlighted for its use by espionage groups to compromise targeted systems.

Overall, the Check Point Research report underscores the dynamic and evolving nature of cyber threats, from large-scale data breaches and sophisticated AI-driven attacks to critical vulnerabilities in widely used software. The findings emphasize the ongoing need for robust security measures, timely patching, and advanced threat detection capabilities across both traditional IT infrastructure and emerging AI systems.

Synthesized by Vypr AI