9th March – Threat Intelligence Report
2026-03-10T08:52:39Z•d4412416f6cb6959bb18425a1c81c96a581a8e6ac22b325ff1c74ee97008eea7
AI-abuseAPTAmaranth-DragonCVE-2025-59536CVE-2025-8088CVE-2026-21852KONNISilver Dragonanthropicclaude-codecredential-theftdata-breacheScanespionageip-camera-compromiseransomwarercesupply-chainthreat-intelligence
What happened
Check Point Research weekly posts (Jan–Mar 2026) covering multiple high‑risk findings: critical RCE and API token‑exfiltration vulnerabilities in Anthropic’s Claude Code (CVE-2025-59536, CVE-2026-21852); weaponization of CVE-2025-8088 by the Amaranth‑Dragon cluster for targeted espionage in Southeast Asia; tracking of a Chinese‑aligned APT cluster “Silver Dragon” targeting governments in Southeast Asia and Europe; KONNI (North Korean) using AI to generate PowerShell backdoors; supply‑chain compromise of eScan; and growing abuse of web‑based AI services as C2 proxies. The feed also documents a串
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- checkpoint_research
- Record identifier
- d4412416f6cb6959bb18425a1c81c96a581a8e6ac22b325ff1c74ee97008eea7
- Enrichment time
- 2026-03-10T08:52:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.