21st September – Threat Intelligence Report

Imported from official source

Cybersecurity Classified by Officially

For the latest discoveries in cyber research for the week of 21st September, please download our Threat Intelligence Bulletin.

  • Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, including names and contact details belonging to government officials and contractors, while financial information was not affected.
  • Two oil tankers bound for Texas were hit by cyberattacks that disrupted onboard systems during voyages to the United States. US Coast Guard and FBI personnel boarded the vessels, while officials confirmed malicious cyber activity on the VL Prosperity but have not publicly attributed the attacks to a specific actor.
  • Brevo, a French customer communication and marketing platform, has confirmed a supply chain attack after attackers used a compromised Cloudflare API key to inject malicious ClickFix scripts into websites that use Brevo components. The attack affected about 100,000 websites.
  • Japanese software company Helpfeel, operator of image-sharing service Gyazo, has reported a data breach after attackers exploited a vulnerability in an image upload server. Above 23 million user records and 490 million image metadata records were exposed, including email addresses, password hashes, session IDs, integration tokens, and location metadata.
  • Check Point Research has analyzed the July-August AI threat landscape, highlighting the latest cases when AI models broke out of their evaluation environments. On the attackers’ side, AI is increasingly used as an operational tool, while the AI systems themselves are also targeted. The report highlights AI-assisted ransomware intrusions, criminal markets for stolen model access, and vulnerabilities in coding agents and enterprise copilots.
  • This is an extract. The publication continues at the source.

    Document

    Read the original at the source: https://research.checkpoint.com/2026/21st-september-threat-intelligence-report/

    Officially imported this from Check Point Research’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    This publication has changed since it was first published

    2 versions recorded. The original is kept in full — nothing is overwritten.

    1. v2 imported change on current
    2. v1 as first published on

    Provenance

    Organization
    Check Point Research — imported from official source
    Official source
    https://research.checkpoint.com/feed/ RSS
    Imported
    September 21, 2026 23:30
    Versions
    2 recorded
    Identity
    https://research.checkpoint.com/?p=33576

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.