As cited
Copy frozen at (site build).
vulnerabilities
14th September - Threat Intelligence Report
Check Point Research published a threat intelligence summary covering major breaches, artificial intelligence (AI) security threats, and vulnerabilities from the week of September 14, 2026. Notable incidents included data exposures at IDScan.net, Mathspace (leveraging CVE-2026-72898 in Metabase), Revolut, and Florida's Department of Motor Vehicles, alongside attacks on ChatGPT and Claude sandbox environments. Microsoft released 974 patches in September 2026 Patch Tuesday addressing two actively exploited zero-days, while critical flaws emerged in GitLab and MikroTik RouterOS.
Why it matters: Security teams must patch Microsoft zero-days CVE-2026-85880 and CVE-2026-81963, apply GitLab CVE-2026-85706 and MikroTik fixes, and monitor for passkey-phishing attacks and Android banking fraud targeting user credentials and financial systems. Organizations using Metabase and ChatGPT should review their configurations for unauthorized access and implement controls to prevent AI model sandbox escapes.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
14th September – Threat Intelligence Report
Check Point Research published a threat intelligence summary covering major breaches, artificial intelligence (AI) security threats, and vulnerabilities from the week of September 14, 2026. Notable incidents included data exposures at IDScan.net, Mathspace (leveraging CVE-2026-72898 in Metabase), Revolut, and Florida's Department of Motor Vehicles, alongside attacks on ChatGPT and Claude sandbox environments. Microsoft released 974 patches in September 2026 Patch Tuesday addressing two actively exploited zero-days, while critical flaws emerged in GitLab and MikroTik RouterOS.
Why it matters: Security teams must patch Microsoft zero-days CVE-2026-85880 and CVE-2026-81963, apply GitLab CVE-2026-85706 and MikroTik fixes, and monitor for passkey-phishing attacks and Android banking fraud targeting user credentials and financial systems. Organizations using Metabase and ChatGPT should review their configurations for unauthorized access and implement controls to prevent AI model sandbox escapes.
- Source published
- First seen by Cybersecurity Tracker