9th March – Threat Intelligence Report

2026-03-10T08:52:39Zd4412416f6cb6959bb18425a1c81c96a581a8e6ac22b325ff1c74ee97008eea7
AI-abuseAPTAmaranth-DragonCVE-2025-59536CVE-2025-8088CVE-2026-21852KONNISilver Dragonanthropicclaude-codecredential-theftdata-breacheScanespionageip-camera-compromiseransomwarercesupply-chainthreat-intelligence

What happened

Check Point Research weekly posts (Jan–Mar 2026) covering multiple high‑risk findings: critical RCE and API token‑exfiltration vulnerabilities in Anthropic’s Claude Code (CVE-2025-59536, CVE-2026-21852); weaponization of CVE-2025-8088 by the Amaranth‑Dragon cluster for targeted espionage in Southeast Asia; tracking of a Chinese‑aligned APT cluster “Silver Dragon” targeting governments in Southeast Asia and Europe; KONNI (North Korean) using AI to generate PowerShell backdoors; supply‑chain compromise of eScan; and growing abuse of web‑based AI services as C2 proxies. The feed also documents a串

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
d4412416f6cb6959bb18425a1c81c96a581a8e6ac22b325ff1c74ee97008eea7
Enrichment time
2026-03-10T08:52:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.