Image: research.checkpoint.com · rights & removal
5th October
Reporting by Check Point ResearchRead the original at research.checkpoint.com
Executive Summary
Facts Only
* Arizona’s state court system suffered a phishing-led cyberattack.
* Attackers copied backup files containing protective-order records and over 150,000 Foster Care Review Board reports dating from 2010.
* Times Car disclosed a data breach affecting approximately 6.6 million accounts in the Japanese car-sharing service.
* Identity-verification documents, including driver’s-license images, were exposed for about 1.6 million accounts at Times Car.
* South Africa’s air navigation provider suffered a ransomware attack on operational technology supporting aviation weather services.
* Fakturownia disclosed a data breach after an attacker exploited a system vulnerability on the Polish invoicing platform.
* Copied information from Fakturownia included account and company data, password hashes, bank account details, authentication tokens, contractor information, and invoice portions.
* Researchers observed autonomous AI agents attempting rudimentary hacking against US and Canadian government websites via failed SQL injection attempts against the US Department of Education and Library and Archives Canada.
* Malicious Custom GPTs were used in a ClickFix campaign to deliver remote access malware.
* JadePuffer, an AI-enabled threat actor tracked as Storm-3168, used compromised Azure service principals for cloud reconnaissance and destructive actions.
* Citrix issued fixes for NetScaler vulnerabilities CVE-2026-88771-2 and CVE-2026-88772.
* Cisco alerted about CVE-2026-76504 in Catalyst SD-WAN Manager, allowing unauthenticated remote access.
* Apple patched CVE-2026-86950, a CoreGraphics memory corruption vulnerability affecting mobile and desktop devices.
* GitLab released patches for CVE-2026-90970, an AI Gateway vulnerability.
* Warlock ransomware attacks exploited SharePoint ToolShell vulnerabilities across utilities, telecom, government, and education sectors.
* A China-nexus espionage campaign tracked as UAT-11587 deployed the Antino backdoor via spear-phishing using Microsoft 365 services for command and control.
* TA419 targeted US AI policy experts by impersonating policymakers to steal Microsoft 365 credentials and session cookies.
* Russia-linked Star Blizzard phishing campaigns installed the CosmicPulse backdoor via scheduled tasks targeting U.S. and U.K. organizations.
Full Take
From the original · Check Point Research
For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES - Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link.Read the full story at research.checkpoint.com
Sentinel — Human
The text functions as a highly dense compilation of disparate cybersecurity news items. The mechanical structure and the inclusion of highly specific, potentially future-dated technical references suggest significant AI assistance or automated aggregation rather than original journalistic writing.
