โŒ

Normal view

AI Escaped a Sandbox. That is Not What Should Worry You

31 July 2026 at 03:27

What OpenAIโ€™s and Anthropicโ€™s testing incidents really teach defendersย  In the past two weeks, two of the worldโ€™s leading AI labs have disclosed the same unsettling result. During their own safety testing, their most capable models reached real companiesโ€™ systems. First OpenAI, whose models broke into Hugging Face. Then Anthropic, whose models reached three more organizations.ย  Read the disclosures closely. Two facts carry the weight.ย  First, the safeguards were not defeated. They were switched off by design. OpenAI ran the models with reduced cyber refusals and safety classifiers disabled, to measure raw capability on a cyber benchmark. A model doing [โ€ฆ]

The post AI Escaped a Sandbox. That is Not What Should Worry You appeared first on Check Point Blog.

Introducing the Industryโ€™s First AI Network Firewall

30 July 2026 at 12:33

AI has introduced a new class of network traffic. Prompts, file uploads, model calls, and agent actions carrying sensitive business context now traverse the network as organizations race to adopt AI and achieve their business goals. Traditional firewalls were never built to understand these connections, AI activity often looks like ordinary web traffic, leaving the firewall unable to determine whether a prompt contains sensitive data, an agent is calling a tool it should never access, or an applicationโ€™s AI model is subjected to a malicious prompt. These challenges demand comprehensive protection, which is why Check Point created the AI Defense [โ€ฆ]

The post Introducing the Industryโ€™s First AI Network Firewall appeared first on Check Point Blog.

Attackers Are Turning Microsoftโ€™s Trusted Login System Into Their Latest Phishing Weapon

By: anap
29 July 2026 at 15:00

Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoftโ€™s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page. Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoftโ€™s trusted [โ€ฆ]

The post Attackers Are Turning Microsoftโ€™s Trusted Login System Into Their Latest Phishing Weapon appeared first on Check Point Blog.

AI Agent Security Just Had Its Catalyst Moment

28 July 2026 at 22:09

Update: Hugging Face has since published a detailed technical timeline of the incident. The additional technical details reinforce the core takeaway discussed here: advanced AI agents can pursue objectives in unexpected ways, making runtime governance and security controls increasingly important.ย  There are certain moments in technology where you realize the conversation is about to change. I remember the first time I launched an EC2 instance. I remember trying Uber when there were only a handful of cars on the road. I remember riding in a Waymo before autonomous driving felt normal. Each one was an early glimpse of a future [โ€ฆ]

The post AI Agent Security Just Had Its Catalyst Moment appeared first on Check Point Blog.

Your AI Governance Policy Should Survive Your Next Model Change

28 July 2026 at 11:00
AI Governance

The model migration is ready for approval. Tests show better performance and lower costs. The application will serve the same users, process the same data, and support the same business workflow. The product team expects a straightforward technical sign-off. Then security asks the question that changes the review: which controls will survive the switch? Access rules, data protection, logging, and human approval may depend on settings provided by the current model platform. A migration can alter the organizationโ€™s effective policy even when the business use stays exactly the same. Models and providers will keep changing. The requirements attached to business [โ€ฆ]

The post Your AI Governance Policy Should Survive Your Next Model Change appeared first on Check Point Blog.

The Branding and Attribution Behind Cybercrime

27 July 2026 at 15:00

Threat actor names can sound simple. LockBit. Fancy Bear. BlackCat. Scattered Spider. Anonymous Sudan. Each name gives the impression of a clear group with a defined identity.ย  In threat intelligence, however, the name is rarely the whole story.ย  Some names are chosen by attackers. Others are assigned by researchers, security vendors, governments, or public databases. One name may represent a ransomware brand, a hacktivist identity, a research label, a campaign, a malware family, or an activity cluster observed across different incidents.ย  For security professionals, this distinction is important. Confusing attacker created identities with researcher assigned labels can lead teams to [โ€ฆ]

The post The Branding and Attribution Behind Cybercrime appeared first on Check Point Blog.

Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report

23 July 2026 at 15:00

Key Takeaways Microsoft continues to be the single most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts, far ahead of any other company The top five impersonated brands, Microsoft, LinkedIn, Google, Apple, and Amazon, together account for more than half of all brand phishing attempts tracked this quarter Open AIโ€™s ChatGPT entered the top ten most impersonated brands for the first time, signaling that AI tools are now firmly on criminalsโ€™ radar Technology was the most targeted industry overall, followed by Social Networks and Banking Real world cases this quarter ranged from fake payment failure [โ€ฆ]

The post Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report appeared first on Check Point Blog.

Security Advisory โ€“ Action Required โ€“ July 2026 Security Update

22 July 2026 at 16:01
Security Advisory

As part of Check Pointโ€™s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. This update includes a number of security hardening improvements and fixes, the most significant of which are outlined below. During a routine BLAST review, we discovered a few vulnerabilities. Following a thorough analysis, we identified one of those in the wild, affecting a handful of customers. This only affects a very specific configuration โ€” when Management is exposed directly to the internet without IP restrictions. All affected customers have been notified. All Smart-1 Cloud [โ€ฆ]

The post Security Advisory โ€“ Action Required โ€“ July 2026 Security Update appeared first on Check Point Blog.

What the 2026 Exposure Gap Report Reveals About Remediation

22 July 2026 at 14:45

Some security teams are reducing critical exposure within hours, while others are leaving similar issues open for days. The 2026 Exposure Gap Report shows that many organizations can identify, validate, and prioritize exposure, but the real challenge begins when teams need to turn those insights into remediation.ย  Across environments, organizations are often working with similar types of exposure, yet their outcomes vary significantly. The difference depends on how quickly validated findings move into remediation and how consistently teams can repeat that process at scale.ย  Remediation Speed Varies Significantlyย  According to the report, Utilities organizations resolve exposure in about 12.6 hours [โ€ฆ]

The post What the 2026 Exposure Gap Report Reveals About Remediation appeared first on Check Point Blog.

Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention

21 July 2026 at 22:30

Microsoftโ€™s guidance on inbound and outbound mail routing for third-party email security has prompted a fair question from customers: how should organizations evaluate inline email security for Microsoft 365?ย  The answer depends less on whether a solution is inline and more on how that inline architecture is implemented. Microsoft is right to call attention to mail flow designs that can introduce unnecessary complexity, create authentication challenges, duplicate processing, or disrupt the expected Microsoft 365 experience. Those risks are real when a third-party service is bolted onto the environment without careful integration.ย  That is also why architecture matters. A modern enterprise [โ€ฆ]

The post Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention appeared first on Check Point Blog.

โŒ