Reading view

Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out.

Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it.  Key takeaways  Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% […]

The post Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out. appeared first on Check Point Blog.

  •  

The Top Exposure Management Questions Security Leaders Ask (Part 1)

Security leaders evaluating Check Point Exposure Management tend to ask the same questions: how the solution discovers assets, what intelligence it provides, and how well it fits their existing tools and workflows.  Below, we answer the questions that come up most often in product evaluations, offering a practical look at how organizations discover, understand, and reduce cyber risk.  1. How does the platform discover my assets?  Every exposure management program starts with knowing what you own. Security teams cannot assess, prioritize, or remediate exposures tied to systems they do not know exist.  Check Point Exposure Management begins by continuously discovering […]

The post The Top Exposure Management Questions Security Leaders Ask (Part 1) appeared first on Check Point Blog.

  •  

The Branding and Attribution Behind Cybercrime

Threat actor names can sound simple. LockBit. Fancy Bear. BlackCat. Scattered Spider. Anonymous Sudan. Each name gives the impression of a clear group with a defined identity.  In threat intelligence, however, the name is rarely the whole story.  Some names are chosen by attackers. Others are assigned by researchers, security vendors, governments, or public databases. One name may represent a ransomware brand, a hacktivist identity, a research label, a campaign, a malware family, or an activity cluster observed across different incidents.  For security professionals, this distinction is important. Confusing attacker created identities with researcher assigned labels can lead teams to […]

The post The Branding and Attribution Behind Cybercrime appeared first on Check Point Blog.

  •  

Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report

Key Takeaways Microsoft continues to be the single most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts, far ahead of any other company The top five impersonated brands, Microsoft, LinkedIn, Google, Apple, and Amazon, together account for more than half of all brand phishing attempts tracked this quarter Open AI’s ChatGPT entered the top ten most impersonated brands for the first time, signaling that AI tools are now firmly on criminals’ radar Technology was the most targeted industry overall, followed by Social Networks and Banking Real world cases this quarter ranged from fake payment failure […]

The post Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report appeared first on Check Point Blog.

  •  

What the 2026 Exposure Gap Report Reveals About Remediation

Some security teams are reducing critical exposure within hours, while others are leaving similar issues open for days. The 2026 Exposure Gap Report shows that many organizations can identify, validate, and prioritize exposure, but the real challenge begins when teams need to turn those insights into remediation.  Across environments, organizations are often working with similar types of exposure, yet their outcomes vary significantly. The difference depends on how quickly validated findings move into remediation and how consistently teams can repeat that process at scale.  Remediation Speed Varies Significantly  According to the report, Utilities organizations resolve exposure in about 12.6 hours […]

The post What the 2026 Exposure Gap Report Reveals About Remediation appeared first on Check Point Blog.

  •  

Under Pressure: Insights from the 2026 Exposure Gap Report

Risk is concentrating. The 2026 Exposure Gap Report shows vulnerabilities claiming a larger share of critical exposure, and that shift has real implications for how security teams prioritize their response. Two findings are central to this change. Vulnerabilities now represent a much larger share of critical exposure, and only a small percentage of vulnerability alerts are validated as exploitable. Together, these findings show why prioritization depends on context, validation, and a clear understanding of which exposures require action. Exposure Is Shifting Toward Vulnerabilities Vulnerabilities now account for 42.6% of critical exposure, up from 18.7% in 2025. This increase shows that […]

The post Under Pressure: Insights from the 2026 Exposure Gap Report appeared first on Check Point Blog.

  •  

The NCSC Patch Wave Is Coming. Do You Know Where Your Risk Lives?

The National Cyber Security Centre (NCSC) is warning organisations to prepare for an unprecedented wave of vulnerability disclosures, driven by AI-accelerated exploitation of technical debt. This commentary sets out how Check Point Exposure Management helps government, public sector, and CNI organisations get ahead of it.  The NCSC’s CTO, Ollie Whitehouse, published a clear and urgent warning in May 2026: AI is enabling threat actors to exploit long-standing technical debt at a scale and speed the industry has not seen before. A “patch wave” – a surge of vulnerability disclosures requiring rapid, large-scale remediation – is expected. For organisations operating critical […]

The post The NCSC Patch Wave Is Coming. Do You Know Where Your Risk Lives? appeared first on Check Point Blog.

  •  

Fraud, Ransomware, and Fake Apps Are Already Targeting FIFA 2026

The FIFA World Cup 2026 kicks off on June 11. Across 16 cities in the US, Canada, and Mexico, billions of people will be watching, traveling, betting, and spending. Threat actors have been watching too, and for far longer. Check Point Research and Check Point Exposure Management spent the past year tracking the cyber threat landscape building around this tournament. What emerged is a coordinated pre-positioning effort across three sectors that sit at the center of the World Cup economy: finance, travel and hospitality, and gambling. The infrastructure is already built, with most of them already live. Financial Sector: Fraud […]

The post Fraud, Ransomware, and Fake Apps Are Already Targeting FIFA 2026 appeared first on Check Point Blog.

  •  

The 2026 U.S. Midterms Have a Cyber Problem, But it’s Not at the Ballot Box

As the U.S. approaches the 2026 elections in November, the greatest threat to voting integrity will likely not be from hackers targeting voting machines or altering ballots, but from a growing war over reality itself.   Voter influence operations are increasingly focused on manipulating the information environment surrounding voters, flooding social media and search results with misleading narratives and fake content, and impersonated news sources designed to erode trust in what people see and hear online. Sophisticated operators have already cloned major media brands like Reuters, The Washington Post, and Fox News using look-alike domains that can fool even attentive readers at a glance. In this new era of AI-powered disinformation, the […]

The post The 2026 U.S. Midterms Have a Cyber Problem, But it’s Not at the Ballot Box appeared first on Check Point Blog.

  •  

The Autonomous Security Platform Built for Attacker Speed

Attackers are now agentic. AI agents run reconnaissance, test exploits, and weaponize vulnerabilities at machine speed – collapsing the mean time from CVE disclosure to confirmed exploitation from 2.3 years in 2018 to roughly 10 hours in 2026, with 72.7% of exploited CVEs in 2026 hitting as zero days, up from 16.1% in 2018.   Every year, the major breach reports tell the same story. Misconfigurations. Unpatched systems. Identity sprawl. Flat networks. The root causes barely change, and yet organizations continue to get breached, not because they lack visibility into these problems, but because closing them at scale is genuinely hard. Too many […]

The post The Autonomous Security Platform Built for Attacker Speed appeared first on Check Point Blog.

  •  

Hacktivists, Ransomware, and a 124% Surge Across DACH

Hacktivism and ransomware targeting organizations across Germany, Austria, and Switzerland increased 124% in 2025, according to Check Point Exposure Management (based on published attacks on the web and dark web). Three distinct dynamics drove the surge, each with its own logic and its own implications for security teams in 2026.  Germany Absorbed Most of It  Germany accounted for more than 80% of regional incidents, with Switzerland at 12% and Austria at 8%. Across Europe, the DACH region represented 18% of all recorded attacks, placing Germany above France, Spain, and Italy by individual country share.  The concentration reflects Germany’s economic and […]

The post Hacktivists, Ransomware, and a 124% Surge Across DACH appeared first on Check Point Blog.

  •  

The Case for a Vulnerability Operations Center

Vulnerability remediation has become an execution problem. Security teams are generating more findings than ever, but too often those findings do not translate into timely risk reduction. The gap between newly introduced exposure and effective remediation continues to widen.  Addressing that gap requires more than improved scanning, better dashboards, or additional tooling. It requires a dedicated operating model. This is the role of the Vulnerability Operations Center, or VOC. As Dr. Natalie Foster Johnson, Executive Director of the CyberMINDS Research Institute, explains, “Operationalizing a VOC is a maturity step that allows organizations to address exposure concerns earlier, reducing risk before incidents occur rather than reacting afterward.”  A VOC centralizes how organizations […]

The post The Case for a Vulnerability Operations Center appeared first on Check Point Blog.

  •  

Q1 2026 Ransomware Report: Fewer Groups, Higher Impact

Ransomware activity remained elevated in Q1 2026, continuing the trend established over the past year. According to the State of Ransomware Q1 2026 report from Check Point Research, overall attack volume stayed near historic highs. At the same time, the structure of the ransomware ecosystem changed materially. After two years of increasing fragmentation, activity is consolidating around a smaller number of dominant groups. For organizations, this shift reduces the number of active actors but increases the potential impact of individual incidents.  Key Findings: 2,122 organizations were listed on ransomware data leak sites in Q1 2026, making it the second-highest Q1 on record The top […]

The post Q1 2026 Ransomware Report: Fewer Groups, Higher Impact appeared first on Check Point Blog.

  •  
❌