This weekly threat intelligence report covers multiple active breaches, AI-related threats, and critical vulnerability disclosures. PaperCut, ServiceNow, Vercel Next.js, and Ubiquiti all released patches for critical vulnerabilities, several rated CVSS 10.0, with PaperCut vulnerabilities actively exploited in the wild. Notable breaches include Manchester Airports Group (8.7 million records exposed), ATF (Qilin ransomware), Boston Scientific (operational disruption), and McKesson (ShinyHunters exfiltrated 1TB via Okta vishing). Threat actor activity includes expanded toolsets from Iran-linked Nimbus Manticore and China-linked QTFY infrastructure disruption by U.S. authorities.
Nimbus Manticore
5 posts
31th August – Threat Intelligence Report - Check Point Research AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict Between January and June 2026, Iran integrated AI technologies as a force multiplier across its hybrid warfare model — cyber operations, influence operations, military systems, and domestic surveillance — without fundamentally altering its asymmetric strategic doctrine. Iranian state-sponsored threat actors (APT42, MuddyWater, APT34, and others) leveraged LLMs to accelerate malware development, enhance spearphishing lures, and conduct ICS reconnaissance, while AI-generated propaganda and inauthentic social media accounts flooded the information environment at unprecedented scale. Russia likely transferred AI-enabled Shahed drone variants and operational tactics to Iran, though independent confirmation of AI use in 2026 kinetic operations remains limited.
8th June – Threat Intelligence Report This threat intelligence report highlights active exploitation of critical vulnerabilities, including a Windows Netlogon RCE (CVE-2026-41089) and an Android Framework flaw. It also details significant data breaches affecting DentaQuest and the UN WFP, emerging AI-driven threats such as EDR evasion labs, a supply chain compromise of the Hola browser, and Iranian state-sponsored espionage operations utilizing Dutch hosting infrastructure.
25th May – Threat Intelligence Report This threat intelligence report highlights multiple high-profile breaches, including 7-Eleven and GitHub, alongside the active exploitation of vulnerabilities in Windows Defender, Trend Micro, and Drupal. It also details emerging threats such as the Kali365 phishing kit, AI-driven prompt injection attacks, the Nimbus Manticore IRGC-linked campaign deploying the MiniFast backdoor, and a supply chain attack on Laravel Lang packages.
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict Iranian threat actor Nimbus Manticore (UNC1549) conducted a series of campaigns in early 2026 utilizing AppDomain Hijacking, SEO poisoning, and task hijacking to deploy the new MiniFast backdoor. The group demonstrated rapid toolset evolution, likely aided by AI-assisted development, targeting the aviation and software sectors across the US, Europe, and the Middle East.