In a week marked by significant cyber incidents, the cybersecurity landscape has seen notable attacks targeting critical infrastructure and major companies. The latest Threat Intelligence Bulletin from Check Point Research highlights these developments, including a cyberattack on North Carolina Ports and a data breach affecting Ryde, an electric scooter operator in Scandinavia.
Cyberattack on North Carolina Ports
The North Carolina Ports authority, which oversees operations at key ports including Wilmington and Morehead City, recently experienced a cyberattack that disrupted its operations. The attack forced the authority to revert to manual processes, causing delays in service restoration. While officials claim to have contained the intrusion, the incident underscores the vulnerabilities present in critical infrastructure systems and the potential for significant operational disruptions.
Data Breach at Ryde
In a separate incident, Ryde disclosed a data breach that compromised the personal information of approximately 4.5 million customers across Norway, Sweden, Finland, and Germany. The attackers accessed sensitive data, including phone numbers, email addresses, birth dates, and partial payment card information. Fortunately, full card numbers and ride histories remained unaffected. This breach highlights the ongoing risks faced by companies in the transportation sector, particularly those handling large volumes of customer data.
Emerging Threats in AI and Vulnerabilities
As cyber threats evolve, the intersection of artificial intelligence and cybersecurity has become increasingly concerning. Check Point Research revealed vulnerabilities in Cloudflare’s Code Mode, which could allow for sandbox escape and cross-tenant data exposure. Additionally, critical flaws were identified in Google’s Gemini CLI and Anthropic’s Claude Code, both of which could lead to code execution and API key theft. These vulnerabilities, rated with high CVSS scores, emphasize the need for robust security measures in AI-driven environments.
Moreover, researchers have documented the rise of AI-enabled identity fraud kits that automate processes to bypass know-your-customer (KYC) checks across various financial platforms. Tools like ProKYC can generate fake identity documents and synthetic videos, posing a significant threat to the integrity of identity verification processes.
Recent Vulnerabilities and Patches
In response to the growing number of vulnerabilities, several companies have released critical patches. Cisco addressed multiple high-severity vulnerabilities in its Catalyst SD-WAN and IOS XE software, with some issues carrying CVSS scores as high as 9.9. Similarly, WordPress released an update to fix a high-severity vulnerability known as XSS2Shell, which could allow attackers to execute remote code under specific conditions.
TP-Link also responded to security concerns by patching 15 vulnerabilities in its Omada provisioning ecosystem, which could expose devices to impersonation and remote code execution risks. These updates are crucial for maintaining the security posture of organizations relying on these technologies.
Conclusion
The incidents reported in the latest Threat Intelligence Bulletin serve as a stark reminder of the persistent and evolving nature of cyber threats. As organizations continue to digitize their operations, the need for comprehensive cybersecurity strategies becomes increasingly critical. The combination of targeted attacks on infrastructure and the exploitation of vulnerabilities in widely used software highlights the importance of vigilance and proactive measures in safeguarding sensitive data and maintaining operational integrity.
Readers can also explore current and upcoming editions through the Cyber Warriors Middle East magazine section.


