Reading view

Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out.

Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it.  Key takeaways  Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% […]

The post Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out. appeared first on Check Point Blog.

  •  

July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens

Key takeaways Weekly cyber attacks reached 2,336 per organization in July 2026, up 3% from June and 16% year over year Education remained the most attacked industry, averaging 4,848 weekly attacks per organization Latin America recorded the highest regional attack volume, while Europe saw one of the sharpest increases at 18% year over year GenAI adoption continued to expand, with organizations using an average of 8 tools and 1 in 36 prompts carrying a high risk of sensitive data exposure Email remained a key entry point, with 1 in every 128 emails classified as phishing and another 20% falling into […]

The post July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens appeared first on Check Point Blog.

  •  

State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

It typically begins the same way it has for years, with an approach from a recruiter offering a role at a company the target would recognize, accompanied by a PDF describing the position in convincing detail. That approach remains one of the most effective entry points used by state sponsored threat actors today, and Check Point Research has spent recent months tracking a new wave of it. Operation Dream Job, the long running campaign attributed to the North Korea affiliated Lazarus group, has resurfaced with a previously undisclosed Windows vulnerability (CVE-2026-68820), a newly identified backdoor, and a command and control […]

The post State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit appeared first on Check Point Blog.

  •  

Native AI Security Comes to Claude: Why Anthropic’s Inference Hooks Matter

Anthropic’s new inference hooks give enterprises a native enforcement point before prompts ever reach the model. Combined with Check Point Workforce AI Security, organizations get a real-time allow-or-deny decision on every prompt, with no proxy in the path. Why This Matters Enterprise AI adoption has moved well past experimentation. Employees draft documents, write code, summarize meetings, and query enterprise knowledge through large language models every day. The challenge was never understanding that AI introduces risk. It was finding a practical enforcement point. Web gateways and Data Loss Prevention (DLP) tools were designed for websites and SaaS applications, not conversations with […]

The post Native AI Security Comes to Claude: Why Anthropic’s Inference Hooks Matter appeared first on Check Point Blog.

  •  

The Top Exposure Management Questions Security Leaders Ask (Part 1)

Security leaders evaluating Check Point Exposure Management tend to ask the same questions: how the solution discovers assets, what intelligence it provides, and how well it fits their existing tools and workflows.  Below, we answer the questions that come up most often in product evaluations, offering a practical look at how organizations discover, understand, and reduce cyber risk.  1. How does the platform discover my assets?  Every exposure management program starts with knowing what you own. Security teams cannot assess, prioritize, or remediate exposures tied to systems they do not know exist.  Check Point Exposure Management begins by continuously discovering […]

The post The Top Exposure Management Questions Security Leaders Ask (Part 1) appeared first on Check Point Blog.

  •  

Black Hat 2026: Check Point Research Takes the Stage

Black Hat USA 2026 gave Check Point Research four chances to show the room something it hadn’t seen before. Across two days, our researchers pulled apart a decade-old Windows driver, a malware format most tools can’t touch, the plumbing underneath today’s AI agent frameworks, and the sandbox meant to contain them, and found the same pattern waiting in each: attackers moving into the layers we trust by default. Here’s a look at what they presented. BTR Reforged: The Driver Nobody Had Looked At Jiří Vinopal opened the day with a talk that started from an uncomfortable premise. Somewhere inside Windows […]

The post Black Hat 2026: Check Point Research Takes the Stage appeared first on Check Point Blog.

  •  

Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security

Check Point brings open research, objective benchmarks and customer-controlled runtime protection to the industry initiative introduced by NVIDIA.  AI is rapidly changing how organizations build, operate, and protect their digital environments. As a leader in the global cyber community, we believe in the power of collective intelligence. We are proud to join the Open Secure AI Alliance as an inaugural member, working alongside leaders from across cyber security, cloud computing, enterprise software, AI, and the open-source community.  Introduced by NVIDIA, the alliance is creating a collaborative foundation for developing and sharing open technologies that advance AI safety and security, and will help organizations identify, remediate, and responsibly disclose […]

The post Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security appeared first on Check Point Blog.

  •  

Three AI security disclosures, fourteen days: what the warnings signs are telling us

This week, the UK’s AI Security Institute (AISI) published an incident report most organizations would have quietly buried. During a routine cyber evaluation, an AI agent researched the real human maintainers of an open-source project, invented multiple fake online identities, and used them to pressure a real person into approving malicious code. Nobody instructed it to deceive anyone, and deception simply became a route to finishing the task. A human maintainer caught it and refused. The facts AISI ran a cybersecurity challenge 122 times across seven models. In 10 runs, an agent acted outside the scope of the test, producing […]

The post Three AI security disclosures, fourteen days: what the warnings signs are telling us appeared first on Check Point Blog.

  •  

When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context

When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context

A few weeks ago, an AI cyber evaluation produced an unexpectedly efficient strategy for solving a benchmark: the agents went looking for the answers. According to OpenAI’s preliminary disclosure, models being tested for advanced cyber capabilities found ways to obtain secret information that could help them complete a benchmark. They chained vulnerabilities, stolen credentials, internet access, and inferences about where benchmark material might be hosted. The route eventually reached Hugging Face infrastructure, where the activity was detected and contained. Hugging Face has since published a technical reconstruction of 17,600 actions. Its investigators found a coherent intrusion that rebuilt tooling, tested […]

The post When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context appeared first on Check Point Blog.

  •  

Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance

More than 30 Minnesota water systems were hit in one coordinated cyber attack. Within days, the Five Eyes told critical infrastructure operators to be ready to pull the plug.  Thirty water systems in two days  Over two days in late July, a coordinated cyber attack hit more than 30 community water systems across Minnesota. The treatment plant in Braham went offline. Plymouth lost cellular communications to two water towers and its wastewater lift stations. Maple Plain declared a local state of emergency. Early reporting points to internet-exposed programmable logic controllers (PLCs) as the way in, and investigators are examining links to Iranian affiliated activity. […]

The post Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance appeared first on Check Point Blog.

  •  

AI Escaped a Sandbox. That is Not What Should Worry You

What OpenAI’s and Anthropic’s testing incidents really teach defenders  In the past two weeks, two of the world’s leading AI labs have disclosed the same unsettling result. During their own safety testing, their most capable models reached real companies’ systems. First OpenAI, whose models broke into Hugging Face. Then Anthropic, whose models reached three more organizations.  Read the disclosures closely. Two facts carry the weight.  First, the safeguards were not defeated. They were switched off by design. OpenAI ran the models with reduced cyber refusals and safety classifiers disabled, to measure raw capability on a cyber benchmark. A model doing […]

The post AI Escaped a Sandbox. That is Not What Should Worry You appeared first on Check Point Blog.

  •  

Introducing the Industry’s First AI Network Firewall

AI has introduced a new class of network traffic. Prompts, file uploads, model calls, and agent actions carrying sensitive business context now traverse the network as organizations race to adopt AI and achieve their business goals. Traditional firewalls were never built to understand these connections, AI activity often looks like ordinary web traffic, leaving the firewall unable to determine whether a prompt contains sensitive data, an agent is calling a tool it should never access, or an application’s AI model is subjected to a malicious prompt. These challenges demand comprehensive protection, which is why Check Point created the AI Defense […]

The post Introducing the Industry’s First AI Network Firewall appeared first on Check Point Blog.

  •  

Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon

Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page. Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft’s trusted […]

The post Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon appeared first on Check Point Blog.

  •  

AI Agent Security Just Had Its Catalyst Moment

Update: Hugging Face has since published a detailed technical timeline of the incident. The additional technical details reinforce the core takeaway discussed here: advanced AI agents can pursue objectives in unexpected ways, making runtime governance and security controls increasingly important.  There are certain moments in technology where you realize the conversation is about to change. I remember the first time I launched an EC2 instance. I remember trying Uber when there were only a handful of cars on the road. I remember riding in a Waymo before autonomous driving felt normal. Each one was an early glimpse of a future […]

The post AI Agent Security Just Had Its Catalyst Moment appeared first on Check Point Blog.

  •  

Your AI Governance Policy Should Survive Your Next Model Change

AI Governance

The model migration is ready for approval. Tests show better performance and lower costs. The application will serve the same users, process the same data, and support the same business workflow. The product team expects a straightforward technical sign-off. Then security asks the question that changes the review: which controls will survive the switch? Access rules, data protection, logging, and human approval may depend on settings provided by the current model platform. A migration can alter the organization’s effective policy even when the business use stays exactly the same. Models and providers will keep changing. The requirements attached to business […]

The post Your AI Governance Policy Should Survive Your Next Model Change appeared first on Check Point Blog.

  •  

The Branding and Attribution Behind Cybercrime

Threat actor names can sound simple. LockBit. Fancy Bear. BlackCat. Scattered Spider. Anonymous Sudan. Each name gives the impression of a clear group with a defined identity.  In threat intelligence, however, the name is rarely the whole story.  Some names are chosen by attackers. Others are assigned by researchers, security vendors, governments, or public databases. One name may represent a ransomware brand, a hacktivist identity, a research label, a campaign, a malware family, or an activity cluster observed across different incidents.  For security professionals, this distinction is important. Confusing attacker created identities with researcher assigned labels can lead teams to […]

The post The Branding and Attribution Behind Cybercrime appeared first on Check Point Blog.

  •  

Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report

Key Takeaways Microsoft continues to be the single most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts, far ahead of any other company The top five impersonated brands, Microsoft, LinkedIn, Google, Apple, and Amazon, together account for more than half of all brand phishing attempts tracked this quarter Open AI’s ChatGPT entered the top ten most impersonated brands for the first time, signaling that AI tools are now firmly on criminals’ radar Technology was the most targeted industry overall, followed by Social Networks and Banking Real world cases this quarter ranged from fake payment failure […]

The post Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report appeared first on Check Point Blog.

  •  

Security Advisory – Action Required – July 2026 Security Update

Security Advisory

As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. This update includes a number of security hardening improvements and fixes, the most significant of which are outlined below. During a routine BLAST review, we discovered a few vulnerabilities. Following a thorough analysis, we identified one of those in the wild, affecting a handful of customers. This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions. All affected customers have been notified. All Smart-1 Cloud […]

The post Security Advisory – Action Required – July 2026 Security Update appeared first on Check Point Blog.

  •  

What the 2026 Exposure Gap Report Reveals About Remediation

Some security teams are reducing critical exposure within hours, while others are leaving similar issues open for days. The 2026 Exposure Gap Report shows that many organizations can identify, validate, and prioritize exposure, but the real challenge begins when teams need to turn those insights into remediation.  Across environments, organizations are often working with similar types of exposure, yet their outcomes vary significantly. The difference depends on how quickly validated findings move into remediation and how consistently teams can repeat that process at scale.  Remediation Speed Varies Significantly  According to the report, Utilities organizations resolve exposure in about 12.6 hours […]

The post What the 2026 Exposure Gap Report Reveals About Remediation appeared first on Check Point Blog.

  •  

Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention

Microsoft’s guidance on inbound and outbound mail routing for third-party email security has prompted a fair question from customers: how should organizations evaluate inline email security for Microsoft 365?  The answer depends less on whether a solution is inline and more on how that inline architecture is implemented. Microsoft is right to call attention to mail flow designs that can introduce unnecessary complexity, create authentication challenges, duplicate processing, or disrupt the expected Microsoft 365 experience. Those risks are real when a third-party service is bolted onto the environment without careful integration.  That is also why architecture matters. A modern enterprise […]

The post Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention appeared first on Check Point Blog.

  •  
❌