14th September – Threat Intelligence Report
Reported exploitedIDScan.netShinyHuntersMathspaceOur summary
Check Point Research’s September 14 threat bulletin highlights widespread breaches affecting IDScan.net, Mathspace, Revolut, and the Florida DMV, with the ShinyHunters group explicitly linked to the motor vehicle records exposure. Notable software vulnerabilities addressed this week include a CVSS 10.0 path traversal flaw in GitLab (CVE-2026-85706), router takeover risks via MikroTik RouterOS, and a SQL injection in Metabase (CVE-2026-72898). Additionally, Microsoft issued a record-breaking update for 974 vulnerabilities, including two exploited zero-days in Windows.
Below is the opening; the full story is at Check Point Research.
From Check Point Research
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
- IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a collection containing millions of identity documents, including driver’s licenses, associated with the company’s verification services.
- Mathspace, an education platform used in Australia and New Zealand, has suffered a data breach affecting more than 1 million people. The attackers exploited CVE-2026-72898 in self-hosted tool Metabase to access an internal reporting database. Exposed information included names, email addresses, usernames, and locations, while passwords and academic records were not affected.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.