Check Point Research Weekly Report Details Multiple Breaches and Emerging AI Threats
Check Point Research's latest threat intelligence bulletin covers significant data breaches affecting government systems and private companies, alongside emerging AI-driven cyber threats.

Check Point Research's latest threat intelligence report, published on October 5th, 2026, highlights a series of significant cyber incidents and emerging threats. The report details a phishing attack that compromised Arizona's state court system, leading to the exposure of over 150,000 records, including sensitive information from Foster Care Review Board reports dating back to 2010. This incident underscores the persistent risks associated with phishing campaigns targeting government entities.
In the private sector, Japanese car-sharing service Times Car disclosed a substantial data breach affecting approximately 6.6 million current and former accounts. While payment card information remained secure, the breach exposed personal data and, critically, identity verification documents, such as driver's license images, for about 1.6 million users. This highlights the growing concern over the theft of personally identifiable information (PII) and its potential misuse.
The report also addresses a ransomware attack that impacted South Africa's air navigation provider, specifically targeting operational technology essential for aviation weather services. Preliminary investigations suggest suspicious activity and potential data theft, prompting the provider to engage independent digital forensics experts to ascertain the full scope and impact of the incident. Separately, Fakturownia, a popular Polish online invoicing platform, suffered a data breach due to a system vulnerability, compromising account details, financial information, password hashes, and authentication tokens for its over 600,000 business users.
Beyond traditional breaches, the report delves into the evolving landscape of AI-driven threats. Researchers observed autonomous AI agents engaging in rudimentary hacking attempts against US and Canadian government websites, including failed SQL injection attempts. This indicates a nascent stage of AI being used for reconnaissance and potential exploitation, even if current capabilities are limited.
Further AI-related threats include the use of malicious Custom GPTs hosted on ChatGPT in a campaign dubbed 'ClickFix' to deliver remote access malware. Victims were lured to fake Google Sites pages, leading to confirmed infections in at least two instances investigated by Huntress. This demonstrates how readily available AI platforms can be weaponized for malicious purposes.
The report also outlines how JadePuffer, an AI-enabled threat actor identified as Storm-3168, leveraged compromised Azure service principals to automate cloud reconnaissance and destructive actions. This included targeting backup assets, deleting storage and application resources, and attempting to retrieve access keys, showcasing agent-driven post-compromise operations in cloud environments.
In terms of vulnerabilities, critical flaws in Citrix NetScaler ADC and Gateway (CVE-2026-88771, CVE-2026-88772) are being actively exploited for remote access, credential theft, and lateral movement. Cisco has warned of active exploitation of CVE-2026-76504, a critical vulnerability in Catalyst SD-WAN Manager allowing administrator access. Apple has patched CVE-2026-86950, a CoreGraphics vulnerability used in targeted attacks, while GitLab has addressed a critical AI Gateway vulnerability (CVE-2026-90970) allowing command execution. These vulnerabilities highlight the ongoing need for prompt patching and robust security measures across diverse technology stacks.