Check Point Research Highlights Surging Ransomware, Zero-Day Exploits, and AI-Driven Threats
Check Point Research has released its comprehensive Threat Intelligence Report for June 2026, painting a stark picture of an evolving and increasingly aggressive cyber threat landscape. The report, covering trends observed in May and early June, indicates a notable shift in attacker methodologies and a significant uptick in specific threat categories.
One of the most alarming findings is the substantial 48% year-over-year increase in ransomware incidents. While overall weekly cyberattacks saw a slight decrease of 7% month-over-month, the surge in ransomware underscores its continued effectiveness and profitability for cybercriminal groups. Education remains the most targeted sector, experiencing an average of 4,641 weekly attacks per organization, a 7% rise from the previous year, with government and telecommunications sectors also facing high volumes of attacks.
The report details several high-profile incidents, including a major data breach at the University of Nottingham. The incident, attributed to the ShinyHunters group, compromised the records of approximately 454,600 current and former students, exposing sensitive information such as contact details, passport numbers, and enrollment data. This breach is linked to the exploitation of CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft that allows for remote code execution.
In addition to the Oracle flaw, Check Point Research identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured with the deprecated IKEv1 protocol. This vulnerability has been tied to Qilin ransomware activity, highlighting the immediate danger posed by unpatched systems.
Microsoft's latest Patch Tuesday was also a significant event, addressing over 200 Windows and Defender vulnerabilities. This record-breaking update included fixes for critical flaws like CVE-2026-45657, a Windows vulnerability with a CVSS score of 9.8 that could enable network-based propagation, and CVE-2026-41091, which has been actively exploited to gain full system control. The sheer volume of patches reflects an AI-driven surge in vulnerability discovery, indicating that artificial intelligence is increasingly being leveraged by both attackers and defenders.
The report also touches upon the broader impact of Generative AI (GenAI) on the threat landscape, noting continued exposure across enterprise environments and risks associated with business-related prompts. For instance, researchers warned about prompt-injection attacks against Anthropic's Claude Code GitHub Action, which could potentially leak CI/CD workflow secrets and enable workflow abuse. This dual-edged nature of AI – enhancing both offensive and defensive capabilities – remains a central theme in current cybersecurity discussions.
Overall, the June 2026 Threat Intelligence Report from Check Point Research underscores the critical importance of proactive vulnerability management, robust incident response strategies, and continuous threat intelligence monitoring to combat the escalating and increasingly sophisticated cyber threats.
Read original source