CVE Tools

7th September – Threat Intelligence Report

Check Point ResearchBy urias4 min read

Reported exploitedDropboxGambling GoblinSonicWall SMA 1000

Our summary

Check Point's weekly threat intelligence report confirms active exploitation of SonicWall SMA 1000 gateways via two critical flaws, CVE-2026-83548 and CVE-2026-83549, alongside a newly discovered authentication bypass in self-hosted JFrog Artifactory deployments tracked as CVE-2026-82329.

The briefing also covers the release of "FalconFlank," a proof-of-concept privilege escalation technique targeting CrowdStrike Falcon on recent Windows versions, as well as ongoing breaches at major organizations including Thomson Reuters and Dropbox.

Read at Check Point Research

Below is the opening; the full story is at Check Point Research.

From Check Point Research

For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin.

TOP ATTACKS AND BREACHES

  • Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files containing court records, including names and other personal information.
  • Hit, a major Slovenian gambling and tourism operator, has sustained a cyberattack that forced six casinos to close for about three days. Operations have resumed, but some table games, bingo, loyalty services, cash registers, and hotel systems remained unavailable during restoration, while some employees were temporarily furloughed.
  • Baylor Genetics, a US clinical diagnostic laboratory, has disclosed a data breach affecting 2.8M patients and employees after unauthorized access to part of its IT environment in June. Stolen data included names, birth dates, medical testing and laboratory results, health insurance information, and some Social Security numbers.
  • Global cloud storage provider Dropbox has disclosed unauthorized access to about 5,000 accounts after attackers exploited Lenovo’s email verification process. Fraudulent Lenovo IDs created with victims’ email addresses enabled access without Dropbox passwords, while files were viewed or downloaded from affected accounts.…
Continue at Check Point Research

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store