Major Cyber Breaches Reported: Latvia, Sakura Internet, and SickKids Among Affected

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

In a week marked by significant cybersecurity incidents, the latest Threat Intelligence Bulletin from Check Point Research highlights major breaches affecting organizations across Europe and North America. Notably, Latvia’s Road Traffic Safety Directorate (CSDD) confirmed a breach that compromised the payment records of over 1.2 million individuals, representing approximately two-thirds of the country’s population. This incident underscores the vulnerabilities present in internet-facing systems, as attackers exploited a specific flaw to access sensitive data, including identification numbers, license plates, and payment details.

Major Breaches and Their Implications

In addition to the breach in Latvia, Sakura Internet, a prominent Japanese cloud and hosting provider, reported unauthorized access that may have exposed up to 1.36 million customer accounts. Attackers not only accessed rental server environments but also installed malware, raising concerns about the security of cloud services and the potential for widespread data theft.

Meanwhile, the Hospital for Sick Children in Canada faced a data theft incident linked to a third-party application. Although the breach did not affect clinical systems or patient information, it compromised personal data of current and former employees, highlighting the risks associated with third-party applications in sensitive environments.

In Berlin, authorities took precautionary measures by isolating two state ministries from government IT networks following a security breach. This disruption forced employees to rely on alternative communication methods, delaying public services and emphasizing the cascading effects of cyber incidents on governmental operations.

Emerging Threats: AI and Cybersecurity

The report also sheds light on the evolving landscape of AI-assisted cyber threats. Researchers demonstrated an autonomous AI agent exploiting a flaw in GitHub Actions, which allowed it to gain unauthorized access to internal systems within seconds. This incident illustrates the potential for AI to be weaponized in cyberattacks, raising alarms among security professionals.

US authorities have issued warnings about active AI-assisted attacks targeting Siemens S7 industrial controllers. Attackers are reportedly using AI-generated scripts disguised as legitimate tools to probe vulnerabilities in critical infrastructure sectors, including manufacturing and energy. This trend indicates a shift in attack methodologies, where AI is leveraged to enhance the sophistication and effectiveness of cyber operations.

Vulnerabilities and Patches: A Call to Action

As organizations grapple with these threats, the report highlights several critical vulnerabilities that require immediate attention. GitLab has released urgent fixes for a severe unauthenticated code injection vulnerability (CVE-2026-19478) that could allow remote attackers to manipulate public projects and user data. Cisco also addressed nine critical vulnerabilities in its Crosswork platforms, with some rated CVSS 10.0, indicating the highest severity level.

Citrix and NASA/JPL have similarly issued patches for critical vulnerabilities that could lead to unauthorized access and command execution, respectively. These incidents serve as a reminder of the importance of timely patch management and proactive security measures to mitigate risks.

In conclusion, the cybersecurity landscape continues to evolve, with significant breaches and emerging threats underscoring the need for organizations to remain vigilant. As attackers increasingly leverage AI and exploit vulnerabilities, the imperative for robust cybersecurity strategies has never been clearer. Organizations must prioritize security measures, including regular updates and employee training, to safeguard against the growing array of cyber threats.

Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...