Reading view

AI Escaped a Sandbox. That is Not What Should Worry You

What OpenAI’s and Anthropic’s testing incidents really teach defenders  In the past two weeks, two of the world’s leading AI labs have disclosed the same unsettling result. During their own safety testing, their most capable models reached real companies’ systems. First OpenAI, whose models broke into Hugging Face. Then Anthropic, whose models reached three more organizations.  Read the disclosures closely. Two facts carry the weight.  First, the safeguards were not defeated. They were switched off by design. OpenAI ran the models with reduced cyber refusals and safety classifiers disabled, to measure raw capability on a cyber benchmark. A model doing […]

The post AI Escaped a Sandbox. That is Not What Should Worry You appeared first on Check Point Blog.

  •  

Introducing the Industry’s First AI Network Firewall

AI has introduced a new class of network traffic. Prompts, file uploads, model calls, and agent actions carrying sensitive business context now traverse the network as organizations race to adopt AI and achieve their business goals. Traditional firewalls were never built to understand these connections, AI activity often looks like ordinary web traffic, leaving the firewall unable to determine whether a prompt contains sensitive data, an agent is calling a tool it should never access, or an application’s AI model is subjected to a malicious prompt. These challenges demand comprehensive protection, which is why Check Point created the AI Defense […]

The post Introducing the Industry’s First AI Network Firewall appeared first on Check Point Blog.

  •  

Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon

Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page. Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft’s trusted […]

The post Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon appeared first on Check Point Blog.

  •  

AI Agent Security Just Had Its Catalyst Moment

Update: Hugging Face has since published a detailed technical timeline of the incident. The additional technical details reinforce the core takeaway discussed here: advanced AI agents can pursue objectives in unexpected ways, making runtime governance and security controls increasingly important.  There are certain moments in technology where you realize the conversation is about to change. I remember the first time I launched an EC2 instance. I remember trying Uber when there were only a handful of cars on the road. I remember riding in a Waymo before autonomous driving felt normal. Each one was an early glimpse of a future […]

The post AI Agent Security Just Had Its Catalyst Moment appeared first on Check Point Blog.

  •  

Your AI Governance Policy Should Survive Your Next Model Change

AI Governance

The model migration is ready for approval. Tests show better performance and lower costs. The application will serve the same users, process the same data, and support the same business workflow. The product team expects a straightforward technical sign-off. Then security asks the question that changes the review: which controls will survive the switch? Access rules, data protection, logging, and human approval may depend on settings provided by the current model platform. A migration can alter the organization’s effective policy even when the business use stays exactly the same. Models and providers will keep changing. The requirements attached to business […]

The post Your AI Governance Policy Should Survive Your Next Model Change appeared first on Check Point Blog.

  •  

The Branding and Attribution Behind Cybercrime

Threat actor names can sound simple. LockBit. Fancy Bear. BlackCat. Scattered Spider. Anonymous Sudan. Each name gives the impression of a clear group with a defined identity.  In threat intelligence, however, the name is rarely the whole story.  Some names are chosen by attackers. Others are assigned by researchers, security vendors, governments, or public databases. One name may represent a ransomware brand, a hacktivist identity, a research label, a campaign, a malware family, or an activity cluster observed across different incidents.  For security professionals, this distinction is important. Confusing attacker created identities with researcher assigned labels can lead teams to […]

The post The Branding and Attribution Behind Cybercrime appeared first on Check Point Blog.

  •  

Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report

Key Takeaways Microsoft continues to be the single most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts, far ahead of any other company The top five impersonated brands, Microsoft, LinkedIn, Google, Apple, and Amazon, together account for more than half of all brand phishing attempts tracked this quarter Open AI’s ChatGPT entered the top ten most impersonated brands for the first time, signaling that AI tools are now firmly on criminals’ radar Technology was the most targeted industry overall, followed by Social Networks and Banking Real world cases this quarter ranged from fake payment failure […]

The post Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report appeared first on Check Point Blog.

  •  

Security Advisory – Action Required – July 2026 Security Update

Security Advisory

As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. This update includes a number of security hardening improvements and fixes, the most significant of which are outlined below. During a routine BLAST review, we discovered a few vulnerabilities. Following a thorough analysis, we identified one of those in the wild, affecting a handful of customers. This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions. All affected customers have been notified. All Smart-1 Cloud […]

The post Security Advisory – Action Required – July 2026 Security Update appeared first on Check Point Blog.

  •  

What the 2026 Exposure Gap Report Reveals About Remediation

Some security teams are reducing critical exposure within hours, while others are leaving similar issues open for days. The 2026 Exposure Gap Report shows that many organizations can identify, validate, and prioritize exposure, but the real challenge begins when teams need to turn those insights into remediation.  Across environments, organizations are often working with similar types of exposure, yet their outcomes vary significantly. The difference depends on how quickly validated findings move into remediation and how consistently teams can repeat that process at scale.  Remediation Speed Varies Significantly  According to the report, Utilities organizations resolve exposure in about 12.6 hours […]

The post What the 2026 Exposure Gap Report Reveals About Remediation appeared first on Check Point Blog.

  •  

Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention

Microsoft’s guidance on inbound and outbound mail routing for third-party email security has prompted a fair question from customers: how should organizations evaluate inline email security for Microsoft 365?  The answer depends less on whether a solution is inline and more on how that inline architecture is implemented. Microsoft is right to call attention to mail flow designs that can introduce unnecessary complexity, create authentication challenges, duplicate processing, or disrupt the expected Microsoft 365 experience. Those risks are real when a third-party service is bolted onto the environment without careful integration.  That is also why architecture matters. A modern enterprise […]

The post Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention appeared first on Check Point Blog.

  •  
❌