Threat Intel
August 24th Threat Intel: Latvia Breach, AI‑Driven Attacks, and Critical Vulnerabilities
The latest Check Point research bulletin highlights a sweeping data breach at Latvia’s Road Traffic Safety Directorate, affecting over 1.2 million citizens and 200,000 organisations. Sakura Internet exposed up to 1.36 million customer accounts through a compromised rental‑server environment. A Canadian children’s hospital suffered a third‑party data leak, while Berlin’s urban ministries were isolated after a security incident. AI‑driven threats are on the rise: an autonomous GitHub Actions agent stole Snowflake tokens, and U.S. authorities warn of AI‑assisted attacks on Siemens S7 industrial c
The Check Point Research Threat Intelligence Bulletin for the week of August 24th surfaces several high‑profile incidents and emerging attack trends.
Massive Data Breach in Latvia
Latvia’s Road Traffic Safety Directorate confirmed a breach that exposed payment records for more than 1.2 million residents—roughly two‑thirds of the country’s population—alongside 200,000 organisations. Stolen details included identification numbers, licence plates, payment amounts, dates and addresses, all accessed via a vulnerability in an internet‑facing system.
Security Fallout at Sakura Internet
Japanese cloud provider Sakura Internet revealed unauthorized access to its rental‑server environments and a separate sales‑management system. Up to 1.36 million customer accounts may have been compromised, and attackers installed malware across hundreds of rental‑server accounts.
Canadian Hospital Data Leak
The Hospital for Sick Children in Canada disclosed a third‑party application breach that affected its careers website. Employee, applicant and staff data were exposed, though clinical systems and patient information remained untouched.
Berlin Ministries Cut Off
Following a security incident, Berlin authorities isolated the city’s urban development and mobility ministries from the broader government IT network. The move disrupted email and internet access, forcing staff to rely on alternative channels and delaying several public services.
AI‑Driven Threats on the Rise
- Researchers demonstrated an autonomous AI agent exploiting a GitHub Actions flaw in Snowflake’s public repository. Within seconds, the agent read internal Jira data and exfiltrated tokens; Snowflake patched the workflow and rotated credentials immediately.
- U.S. authorities warn of active AI‑assisted attacks targeting Siemens S7 industrial controllers across critical sectors. Attackers use AI‑generated scripts masquerading as monitoring tools to probe internet‑exposed systems and potentially alter configurations or cause operational disruption.
- ‘Kriminal’, a publicly available AI platform marketed as uncensored, offers social engineering and exploit assistance through cryptocurrency subscriptions. The service merges models such as Grok, Claude and Llama, enabling users to generate phishing content, malicious code and other cybercrime materials.
Critical Vulnerabilities and Patches
- GitLab released out‑of‑band fixes for CVE‑2026‑19478, a critical unauthenticated code‑injection flaw (CVSS 9.4) that could allow attackers to alter or delete public projects and user data. Exploitation attempts were observed after disclosure.
- Cisco issued patches for nine critical vulnerabilities affecting Crosswork platforms and Secure Workload software, including six CVSS 10.0 flaws that could enable unauthorized access or system compromise.
- Citrix published patches for CVE‑2026‑19489 and CVE‑2026‑19490, which affect NetScaler ADC and NetScaler Gateway. The first flaw allows unauthenticated authentication bypass, while the second can cause denial of service.
- NASA/JPL fixed a critical vulnerability (CVSS 9.4) in the open‑source AMMOS Instrument Toolkit AIT‑GUI, which enabled unauthenticated command execution via its web console. Version 2.5.2 contains the fix.
These incidents underscore the growing intersection of AI and cyber threats, the continued prevalence of data breaches, and the urgent need for timely patching of critical vulnerabilities.