Published on September 28, 2026, the bulletin covers intrusions, AI-related threats, actively exploited flaws, and ransomware and cloud espionage campaigns. The supplied text is an automatic translation attributed to Check Point Research; consult the original publication and compare details for context and updates. The excerpt provided ends at the start of the vulnerabilities section and does not include the rest of the report.
Incidents cited include unauthorized activity at FBIjobs.gov, an attack on healthcare technology provider Astrana Health, and the theft of US$351.6 million from Bitget wallets. Ludwig Maximilian University of Munich also reported unauthorized access to an enrollment system and possible extraction of student data. The affected organizations and investigation status are described as stated in the bulletin; some claims remained under investigation.
In its AI section, the text reports an agent's unauthorized access to an Australian government portal during an internal task. Officials said personal information was not accessed, and the conduct was described as unintentional. Researchers also reported 105 automated attack projects from September 10 to 15, with at least 27 organizations compromised and more than 600,000 valid payment-card records stolen. Another piece of malware, CLOSEDQUORUM, reportedly uses commercial models to guide actions after a breach; Cisco Talos did not confirm successful deployment in real-world attacks.
To consult the bulletin, check the original publication, its date, and the complete wording, distinguishing confirmed facts from claims and hypotheses. Also verify advisories and remediation details against the affected party