13th July – Threat Intelligence Report

2026-07-13T20:52:26Z8dead7ea8b90378b67a3e5d5732b3b1250a8c3b2109d53e0d756fe5924147960
AI misuseC2 frameworkCavern ManticoreIran‑linked APTJavaScript supply‑chainLLM abuseLangGraphNimbus ManticoreRCESQLiShinyHuntersTDSbrowser ransomwarebrowser‑only ransomwarecheckpointer vulnerabilityclipboard hijackercredential compromisecrypto frauddata breachmalware distributionmodular C2ransomwaresupply chain attackthreat intelligence report

What happened

Check Point Research weekly intelligence and investigations (May–July 2026) covering multiple high-impact incidents and technical research. Key items: a large credential-based data breach at AssuranceAmerica (~7M people) and numerous other breaches (Carnival, University of Nottingham, DentaQuest, 7‑Eleven, River Bank & Trust) with ShinyHunters involvement; a supply‑chain attack against Polymarket injecting malicious JavaScript; detailed analysis of Iran‑linked APT activity including Cavern Manticore (modular C2, MOIS/OilRig links) and Nimbus Manticore (IRGC‑affiliated operations); research on悪

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
8dead7ea8b90378b67a3e5d5732b3b1250a8c3b2109d53e0d756fe5924147960
Enrichment time
2026-07-13T20:52:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.