Reading view

Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out.

Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it.  Key takeaways  Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% […]

The post Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out. appeared first on Check Point Blog.

  •  

July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens

Key takeaways Weekly cyber attacks reached 2,336 per organization in July 2026, up 3% from June and 16% year over year Education remained the most attacked industry, averaging 4,848 weekly attacks per organization Latin America recorded the highest regional attack volume, while Europe saw one of the sharpest increases at 18% year over year GenAI adoption continued to expand, with organizations using an average of 8 tools and 1 in 36 prompts carrying a high risk of sensitive data exposure Email remained a key entry point, with 1 in every 128 emails classified as phishing and another 20% falling into […]

The post July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens appeared first on Check Point Blog.

  •  

Native AI Security Comes to Claude: Why Anthropic’s Inference Hooks Matter

Anthropic’s new inference hooks give enterprises a native enforcement point before prompts ever reach the model. Combined with Check Point Workforce AI Security, organizations get a real-time allow-or-deny decision on every prompt, with no proxy in the path. Why This Matters Enterprise AI adoption has moved well past experimentation. Employees draft documents, write code, summarize meetings, and query enterprise knowledge through large language models every day. The challenge was never understanding that AI introduces risk. It was finding a practical enforcement point. Web gateways and Data Loss Prevention (DLP) tools were designed for websites and SaaS applications, not conversations with […]

The post Native AI Security Comes to Claude: Why Anthropic’s Inference Hooks Matter appeared first on Check Point Blog.

  •  

Black Hat 2026: Check Point Research Takes the Stage

Black Hat USA 2026 gave Check Point Research four chances to show the room something it hadn’t seen before. Across two days, our researchers pulled apart a decade-old Windows driver, a malware format most tools can’t touch, the plumbing underneath today’s AI agent frameworks, and the sandbox meant to contain them, and found the same pattern waiting in each: attackers moving into the layers we trust by default. Here’s a look at what they presented. BTR Reforged: The Driver Nobody Had Looked At Jiří Vinopal opened the day with a talk that started from an uncomfortable premise. Somewhere inside Windows […]

The post Black Hat 2026: Check Point Research Takes the Stage appeared first on Check Point Blog.

  •  

Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security

Check Point brings open research, objective benchmarks and customer-controlled runtime protection to the industry initiative introduced by NVIDIA.  AI is rapidly changing how organizations build, operate, and protect their digital environments. As a leader in the global cyber community, we believe in the power of collective intelligence. We are proud to join the Open Secure AI Alliance as an inaugural member, working alongside leaders from across cyber security, cloud computing, enterprise software, AI, and the open-source community.  Introduced by NVIDIA, the alliance is creating a collaborative foundation for developing and sharing open technologies that advance AI safety and security, and will help organizations identify, remediate, and responsibly disclose […]

The post Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security appeared first on Check Point Blog.

  •  

Three AI security disclosures, fourteen days: what the warnings signs are telling us

This week, the UK’s AI Security Institute (AISI) published an incident report most organizations would have quietly buried. During a routine cyber evaluation, an AI agent researched the real human maintainers of an open-source project, invented multiple fake online identities, and used them to pressure a real person into approving malicious code. Nobody instructed it to deceive anyone, and deception simply became a route to finishing the task. A human maintainer caught it and refused. The facts AISI ran a cybersecurity challenge 122 times across seven models. In 10 runs, an agent acted outside the scope of the test, producing […]

The post Three AI security disclosures, fourteen days: what the warnings signs are telling us appeared first on Check Point Blog.

  •  

When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context

When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context

A few weeks ago, an AI cyber evaluation produced an unexpectedly efficient strategy for solving a benchmark: the agents went looking for the answers. According to OpenAI’s preliminary disclosure, models being tested for advanced cyber capabilities found ways to obtain secret information that could help them complete a benchmark. They chained vulnerabilities, stolen credentials, internet access, and inferences about where benchmark material might be hosted. The route eventually reached Hugging Face infrastructure, where the activity was detected and contained. Hugging Face has since published a technical reconstruction of 17,600 actions. Its investigators found a coherent intrusion that rebuilt tooling, tested […]

The post When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context appeared first on Check Point Blog.

  •  

AI Escaped a Sandbox. That is Not What Should Worry You

What OpenAI’s and Anthropic’s testing incidents really teach defenders  In the past two weeks, two of the world’s leading AI labs have disclosed the same unsettling result. During their own safety testing, their most capable models reached real companies’ systems. First OpenAI, whose models broke into Hugging Face. Then Anthropic, whose models reached three more organizations.  Read the disclosures closely. Two facts carry the weight.  First, the safeguards were not defeated. They were switched off by design. OpenAI ran the models with reduced cyber refusals and safety classifiers disabled, to measure raw capability on a cyber benchmark. A model doing […]

The post AI Escaped a Sandbox. That is Not What Should Worry You appeared first on Check Point Blog.

  •  

Introducing the Industry’s First AI Network Firewall

AI has introduced a new class of network traffic. Prompts, file uploads, model calls, and agent actions carrying sensitive business context now traverse the network as organizations race to adopt AI and achieve their business goals. Traditional firewalls were never built to understand these connections, AI activity often looks like ordinary web traffic, leaving the firewall unable to determine whether a prompt contains sensitive data, an agent is calling a tool it should never access, or an application’s AI model is subjected to a malicious prompt. These challenges demand comprehensive protection, which is why Check Point created the AI Defense […]

The post Introducing the Industry’s First AI Network Firewall appeared first on Check Point Blog.

  •  

Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon

Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page. Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft’s trusted […]

The post Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon appeared first on Check Point Blog.

  •  

AI Agent Security Just Had Its Catalyst Moment

Update: Hugging Face has since published a detailed technical timeline of the incident. The additional technical details reinforce the core takeaway discussed here: advanced AI agents can pursue objectives in unexpected ways, making runtime governance and security controls increasingly important.  There are certain moments in technology where you realize the conversation is about to change. I remember the first time I launched an EC2 instance. I remember trying Uber when there were only a handful of cars on the road. I remember riding in a Waymo before autonomous driving felt normal. Each one was an early glimpse of a future […]

The post AI Agent Security Just Had Its Catalyst Moment appeared first on Check Point Blog.

  •  

Your AI Governance Policy Should Survive Your Next Model Change

AI Governance

The model migration is ready for approval. Tests show better performance and lower costs. The application will serve the same users, process the same data, and support the same business workflow. The product team expects a straightforward technical sign-off. Then security asks the question that changes the review: which controls will survive the switch? Access rules, data protection, logging, and human approval may depend on settings provided by the current model platform. A migration can alter the organization’s effective policy even when the business use stays exactly the same. Models and providers will keep changing. The requirements attached to business […]

The post Your AI Governance Policy Should Survive Your Next Model Change appeared first on Check Point Blog.

  •  

Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report

Key Takeaways Microsoft continues to be the single most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts, far ahead of any other company The top five impersonated brands, Microsoft, LinkedIn, Google, Apple, and Amazon, together account for more than half of all brand phishing attempts tracked this quarter Open AI’s ChatGPT entered the top ten most impersonated brands for the first time, signaling that AI tools are now firmly on criminals’ radar Technology was the most targeted industry overall, followed by Social Networks and Banking Real world cases this quarter ranged from fake payment failure […]

The post Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report appeared first on Check Point Blog.

  •  

Security Advisory – Action Required – July 2026 Security Update

Security Advisory

As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. This update includes a number of security hardening improvements and fixes, the most significant of which are outlined below. During a routine BLAST review, we discovered a few vulnerabilities. Following a thorough analysis, we identified one of those in the wild, affecting a handful of customers. This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions. All affected customers have been notified. All Smart-1 Cloud […]

The post Security Advisory – Action Required – July 2026 Security Update appeared first on Check Point Blog.

  •  

Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention

Microsoft’s guidance on inbound and outbound mail routing for third-party email security has prompted a fair question from customers: how should organizations evaluate inline email security for Microsoft 365?  The answer depends less on whether a solution is inline and more on how that inline architecture is implemented. Microsoft is right to call attention to mail flow designs that can introduce unnecessary complexity, create authentication challenges, duplicate processing, or disrupt the expected Microsoft 365 experience. Those risks are real when a third-party service is bolted onto the environment without careful integration.  That is also why architecture matters. A modern enterprise […]

The post Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention appeared first on Check Point Blog.

  •  

AI Appreciation Day: Let’s Be Honest About What We’re Appreciating

Today is AI Appreciation Day, and honestly, we mean it. AI has changed how we write code, analyze threats, and get work done faster than anyone thought possible a few years ago. It deserves a moment of gratitude. But at Check Point, we spend most of our year studying the other side of that coin and our newly released AI Security Report 2026 makes one thing very clear: the same qualities we’re celebrating today are exactly what’s made AI such a powerful tool for attackers too. So in the spirit of appreciating AI honestly, not just enthusiastically, here’s what a […]

The post AI Appreciation Day: Let’s Be Honest About What We’re Appreciating appeared first on Check Point Blog.

  •  

AI Security Is Never Finished: Building the Continuous Red Teaming Loop 

Continuous Red Teaming Loop

Security programs are built around moments of closure: the finding is closed, the control passed, and the release can move forward.  AI security refuses to cooperate with that model.  A passing test is useful evidence, but only for a specific system, configuration, and moment.  Production AI keeps moving. Models change behavior, prompts are revised, retrieval sources are added, agents gain tools, and users introduce unexpected context. Attackers adapt just as quickly. Yesterday’s clean result may not describe tomorrow’s risk.  That has been the practical case for continuous AI red teaming. Now, research from the National Institute of Standards and Technology […]

The post AI Security Is Never Finished: Building the Continuous Red Teaming Loop  appeared first on Check Point Blog.

  •  

AI Security Threats in 2026: Annual Insights from Check Point Research

Key Takeaways Vulnerability response times have collapsed from days to hours. AI can reason about code well enough to generate working exploits at scale, so defenders now face patch windows of 12 to 72 hours instead of the traditional timeframe Your exposed AI infrastructure is being actively probed right now. Model servers, inference endpoints, and agent control panels are facing the internet, and most security teams don’t know they’re there Data leakage through approved AI use doubled in one year. Employees sharing context with generative AI to get useful answers are exposing credentials and source code in ordinary workflows, no […]

The post AI Security Threats in 2026: Annual Insights from Check Point Research appeared first on Check Point Blog.

  •  

AI Agents are Only As Effective as Their Harness

Every AI vendor is talking about agents – autonomous systems that handle complex tasks without constant human input. The promise is real. But one question gets asked too rarely: what makes an agent reliable enough to trust with your network security?  The answer isn’t the model. It’s the harness.  Agents Run on LLMs. Reliability Runs on Something Else AI agents get their reasoning power from large language models (LLMs). LLMs are impressive. They understand context, reason through complex problems, and plan across a wide range of tasks.  But on its own, an LLM is a generalist. It knows a little about everything and not enough about your […]

The post AI Agents are Only As Effective as Their Harness appeared first on Check Point Blog.

  •  

Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security

Key takeaways  AI agents create a new email attack surface because they can process content before humans see it Email Agent Hijacking hides instructions in email content to manipulate AI interpretation, decisions, or outputs Post-delivery controls are too late when an AI agent acts immediately after delivery Organizations need preventive protection for AI-consumed content and validation for AI-generated responses AI agents are now reading and writing emails before humans ever see them. What was once a human-centric communication channel is quickly becoming an AI-driven workflow, and that shift introduces a new and largely unprotected attack surface.  Much of the industry’s recent attention has centered […]

The post Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security appeared first on Check Point Blog.

  •  
❌