Weekly threat intelligence roundup covering major data breaches at Carnival Corporation (~6M affected), Charter Communications (4.9M records via ShinyHunters), Lithuania's Centre of Registers, and Station Casinos. AI threat highlights include the Russia-aligned GREYVIBE group using ChatGPT and Gemini for phishing campaigns, an AI-driven fraud operation on Telegram, and an AI-generated malicious npm package stealing developer files. Key vulnerabilities include an actively exploited Palo Alto GlobalProtect auth bypass (CVE-2026-0257), an unpatched critical RCE in Gogs (CVSS 9.4), and active exploitation of Ghost CMS SQL injection. Threat intelligence reports cover Iran-linked attacks on LA Metro, Grandoreiro banking malware targeting Portuguese banks, a FIFA World Cup fraud network (GHOST STADIUM), and JINX-0164 targeting crypto organizations via supply chain compromise.

4m read timeFrom research.checkpoint.com
Post cover image
110 Impressions