Reading view

AI Appreciation Day: Let’s Be Honest About What We’re Appreciating

Today is AI Appreciation Day, and honestly, we mean it. AI has changed how we write code, analyze threats, and get work done faster than anyone thought possible a few years ago. It deserves a moment of gratitude. But at Check Point, we spend most of our year studying the other side of that coin and our newly released AI Security Report 2026 makes one thing very clear: the same qualities we’re celebrating today are exactly what’s made AI such a powerful tool for attackers too. So in the spirit of appreciating AI honestly, not just enthusiastically, here’s what a […]

The post AI Appreciation Day: Let’s Be Honest About What We’re Appreciating appeared first on Check Point Blog.

  •  

AI Security Threats in 2026: Annual Insights from Check Point Research

Key Takeaways Vulnerability response times have collapsed from days to hours. AI can reason about code well enough to generate working exploits at scale, so defenders now face patch windows of 12 to 72 hours instead of the traditional timeframe Your exposed AI infrastructure is being actively probed right now. Model servers, inference endpoints, and agent control panels are facing the internet, and most security teams don’t know they’re there Data leakage through approved AI use doubled in one year. Employees sharing context with generative AI to get useful answers are exposing credentials and source code in ordinary workflows, no […]

The post AI Security Threats in 2026: Annual Insights from Check Point Research appeared first on Check Point Blog.

  •  

AI Agents are Only As Effective as Their Harness

Every AI vendor is talking about agents – autonomous systems that handle complex tasks without constant human input. The promise is real. But one question gets asked too rarely: what makes an agent reliable enough to trust with your network security?  The answer isn’t the model. It’s the harness.  Agents Run on LLMs. Reliability Runs on Something Else AI agents get their reasoning power from large language models (LLMs). LLMs are impressive. They understand context, reason through complex problems, and plan across a wide range of tasks.  But on its own, an LLM is a generalist. It knows a little about everything and not enough about your […]

The post AI Agents are Only As Effective as Their Harness appeared first on Check Point Blog.

  •  

Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security

Key takeaways  AI agents create a new email attack surface because they can process content before humans see it Email Agent Hijacking hides instructions in email content to manipulate AI interpretation, decisions, or outputs Post-delivery controls are too late when an AI agent acts immediately after delivery Organizations need preventive protection for AI-consumed content and validation for AI-generated responses AI agents are now reading and writing emails before humans ever see them. What was once a human-centric communication channel is quickly becoming an AI-driven workflow, and that shift introduces a new and largely unprotected attack surface.  Much of the industry’s recent attention has centered […]

The post Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security appeared first on Check Point Blog.

  •  

How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox

A student receives what looks like a routine summer job offer from a trusted school account. The link goes to Google Forms. The email passes authentication. There is no malware, no fake login page, and no strange-looking domain. To the student and to many security tools, it looks harmless.  But this is where modern phishing succeeds: it borrows trust instead of faking it. In this case, Check Point Research observed more than 3,200 copies of a phishing campaign targeting students with the promise of flexible summer work. The emails were sent from a compromised but legitimate school mailbox and directed […]

The post How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox appeared first on Check Point Blog.

  •  

A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide

Key takeaways Weekly cyber-attacks per organization reached 2,270 in June 2026, up 10% from May and 17% higher than June 2025 Education, Government, and Telecommunications again sat at the top of the industry list, with Education and Telecommunications posting double-digit gains while Government rose 5% year over year Most regions grew year over year, led by Latin America at a 27% increase, while Africa was the exception with a 9% decline GenAI exposure held roughly steady, though Healthcare and Telecommunications emerged as the industries carrying the most risk from unsafe prompts Ransomware attacks reached 646 for the month, a 33% […]

The post A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide appeared first on Check Point Blog.

  •  

How Unified Policies Close Security Gaps

As organizations adopt both on-premises firewalls and cloud-delivered SASE, security becomes more distributed and complex. Users connect from headquarters, branch offices, and remote locations, expecting the same secure and seamless internet experience everywhere. When Internet Access policies across firewalls and SASE are managed separately, maintaining consistency becomes harder, increasing the risk of human error and misconfiguration.  The 2026 Verizon Data Breach Investigations Report found that misconfiguration is one of the top recurring error types in breaches year after year, noting that, “the fact that Misconfiguration remains among the top errors over time is rather concerning.” In environments with separate Internet Access policies, that risk is […]

The post How Unified Policies Close Security Gaps appeared first on Check Point Blog.

  •  

Under Pressure: Insights from the 2026 Exposure Gap Report

Risk is concentrating. The 2026 Exposure Gap Report shows vulnerabilities claiming a larger share of critical exposure, and that shift has real implications for how security teams prioritize their response. Two findings are central to this change. Vulnerabilities now represent a much larger share of critical exposure, and only a small percentage of vulnerability alerts are validated as exploitable. Together, these findings show why prioritization depends on context, validation, and a clear understanding of which exposures require action. Exposure Is Shifting Toward Vulnerabilities Vulnerabilities now account for 42.6% of critical exposure, up from 18.7% in 2025. This increase shows that […]

The post Under Pressure: Insights from the 2026 Exposure Gap Report appeared first on Check Point Blog.

  •  

Check Point and Illumio Expand Partnership to Secure Hybrid Environments

Building on our previous Illumio Insights integration, Check Point and Illumio are expanding their partnership with an integration to Illumio Segmentation, helping organizations prevent threats, expose risky paths, contain lateral movement across hybrid and multi-cloud environments, and better align gateway enforcement with microsegmentation policy. Hybrid environments keep getting more complex. Applications and data now span data centers, private cloud, public cloud, SaaS, remote access paths, and shared services, while attackers are using AI to move faster from intrusion to impact. Security teams are not just trying to stop threats at the edge. They also need to see how traffic moves […]

The post Check Point and Illumio Expand Partnership to Secure Hybrid Environments appeared first on Check Point Blog.

  •  

The NCSC Patch Wave Is Coming. Do You Know Where Your Risk Lives?

The National Cyber Security Centre (NCSC) is warning organisations to prepare for an unprecedented wave of vulnerability disclosures, driven by AI-accelerated exploitation of technical debt. This commentary sets out how Check Point Exposure Management helps government, public sector, and CNI organisations get ahead of it.  The NCSC’s CTO, Ollie Whitehouse, published a clear and urgent warning in May 2026: AI is enabling threat actors to exploit long-standing technical debt at a scale and speed the industry has not seen before. A “patch wave” – a surge of vulnerability disclosures requiring rapid, large-scale remediation – is expected. For organisations operating critical […]

The post The NCSC Patch Wave Is Coming. Do You Know Where Your Risk Lives? appeared first on Check Point Blog.

  •  

Energy, Healthcare, and Finance: Why Midwest Industries Are Facing Surging Cyber Attacks

Across the United States, the average organization faced slightly fewer cyber attacks per week in May 2026 than it did a year earlier, according to Check Point Research — the national figure was essentially flat year over year. In the Central US, however, the trend ran the other way. Organizations there faced more attacks than a year ago, and more than the national average — as they did in every month of 2026.  Through the first five months of the year, the typical Central US organization faced about 1,552 cyber attacks per week, roughly 7% above the national average of […]

The post Energy, Healthcare, and Finance: Why Midwest Industries Are Facing Surging Cyber Attacks appeared first on Check Point Blog.

  •  

Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years. Here’s What Cyber Criminals Are Actually Doing

Every summer, hundreds of millions of people book flights, reserve hotels, and plan vacations online. And every summer, cyber criminals show up to take advantage of exactly that. Check Point Research tracked the threat landscape heading into the 2026 summer travel season, and what they found should give travelers pause before they click “confirm booking.”  The hospitality sector is under targeted attack  The hospitality, travel, and recreation sector recorded 2,291 average weekly cyberattacks per organization in May 2026, a 24% increase compared to the same month last year. To put that in context, the global year-over-year rise across all industries […]

The post Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years. Here’s What Cyber Criminals Are Actually Doing appeared first on Check Point Blog.

  •  

The AI Your Security Team Can’t See Is the One You Should Worry About

Shadow AI is no longer a theoretical risk. Employees are adopting AI tools faster than security teams can track them, often without IT’s knowledge, and frequently on devices and surfaces that traditional security tools simply can’t see. If you asked your security team right now how many AI tools are active across your organization, on which surfaces, and what’s being shared, could they answer? For most organizations, the honest answer is no. And that gap, between what your employees are doing with AI and what your security team can actually see, is where enterprise risk lives today.  AI adoption in the enterprise didn’t slow down and wait for governance to catch […]

The post The AI Your Security Team Can’t See Is the One You Should Worry About appeared first on Check Point Blog.

  •  

Check Point Engage Public Sector 2026: AI Is the New Battlefield

Last week, public sector leaders, cyber security practitioners, and technology experts gathered at the International Spy Museum in Washington, D.C. for Check Point Engage Public Sector: Securing the Mission of Public Sector Organizations in a Hyperconnected AI World. And what was on everyone’s mind? You guessed it – how federal and other public sector organizations secure mission-critical operations in an era where AI is transforming both cyber security defense and cyber warfare. What the audience learned across our several superb panel discussions was that AI has definitively become a challenging and fast-evolving battleground in the push and pull between attackers […]

The post Check Point Engage Public Sector 2026: AI Is the New Battlefield appeared first on Check Point Blog.

  •  

Check Point Joins OpenAI’s Trusted Access for Cyber Program and Daybreak Initiative

The model behind a security workflow shapes how fast a threat is caught, how accurately an incident is investigated, and how much a defender can trust the result. We treat that choice with care. Today we’re taking a clear step forward: Check Point has joined OpenAI’s Daybreak initiative through its Trusted Access for Cyber (TAC) program. These are real steps in how we bring AI into our defensive operations, and in the security we deliver to our customers. What Trusted Access for Cyber Gives Us Trusted Access for Cyber is OpenAI’s program for vetted security organizations that need its most […]

The post Check Point Joins OpenAI’s Trusted Access for Cyber Program and Daybreak Initiative appeared first on Check Point Blog.

  •  

When Your AI Agent’s Memory Becomes a Security Liability

Key Findings:   Check Point Research identified a critical vulnerability chain in LangGraph, an open-source framework from the creators of LangChain that enables developers to build complex, stateful, and controllable AI agent workflows using LLMs; they have approximately 46.5 million monthly downloads, making it one of the most widely adopted AI agent platforms in the world An SQL injection in LangGraph’s function could allow attackers to gain full control via remote code execution of a server by exploiting weaknesses in how the system processes and handles data. A compromised LangGraph server exposes everything the agent touches, including LLM API keys, customer data, CRM credentials, conversation history, and internal network […]

The post When Your AI Agent’s Memory Becomes a Security Liability appeared first on Check Point Blog.

  •  

Fraud, Ransomware, and Fake Apps Are Already Targeting FIFA 2026

The FIFA World Cup 2026 kicks off on June 11. Across 16 cities in the US, Canada, and Mexico, billions of people will be watching, traveling, betting, and spending. Threat actors have been watching too, and for far longer. Check Point Research and Check Point Exposure Management spent the past year tracking the cyber threat landscape building around this tournament. What emerged is a coordinated pre-positioning effort across three sectors that sit at the center of the World Cup economy: finance, travel and hospitality, and gambling. The infrastructure is already built, with most of them already live. Financial Sector: Fraud […]

The post Fraud, Ransomware, and Fake Apps Are Already Targeting FIFA 2026 appeared first on Check Point Blog.

  •  

The Meta AI Account Recovery Incident Wasn’t Just a Chatbot Problem

When people hear about hackers “asking an AI chatbot” to help them take over Instagram accounts, the instinctive reaction is to file it under prompt injection, jailbreaks, or “the model got tricked.”  That may be the wrong lesson.  According to reporting from 404 Media, hackers claimed they used Meta’s AI support chatbot to gain access to high-profile Instagram accounts by asking it to change the email address associated with the target account. The reported incidents coincided with several high-profile account takeovers, including accounts linked to the Obama White House, Sephora, and the Chief Master Sergeant of the Space Force.    […]

The post The Meta AI Account Recovery Incident Wasn’t Just a Chatbot Problem appeared first on Check Point Blog.

  •  

The 2026 U.S. Midterms Have a Cyber Problem, But it’s Not at the Ballot Box

As the U.S. approaches the 2026 elections in November, the greatest threat to voting integrity will likely not be from hackers targeting voting machines or altering ballots, but from a growing war over reality itself.   Voter influence operations are increasingly focused on manipulating the information environment surrounding voters, flooding social media and search results with misleading narratives and fake content, and impersonated news sources designed to erode trust in what people see and hear online. Sophisticated operators have already cloned major media brands like Reuters, The Washington Post, and Fox News using look-alike domains that can fool even attentive readers at a glance. In this new era of AI-powered disinformation, the […]

The post The 2026 U.S. Midterms Have a Cyber Problem, But it’s Not at the Ballot Box appeared first on Check Point Blog.

  •  

Check Point Lays the Groundwork for the Future of AI Factory Security with NVIDIA

At GTC Taipei during COMPUTEX 2026, NVIDIA is highlighting the growing adoption of its NVIDIA Vera BlueField-4 STX architecture and introducing new NVIDIA DOCA-powered innovations designed to secure the next generation of enterprise AI infrastructure. As organizations continue scaling AI factories, private LLM environments, distributed inference systems, and increasingly autonomous AI operations, enterprise infrastructure requirements are rapidly evolving. Modern AI environments combine high-performance compute, distributed storage systems, inference pipelines, Kubernetes clusters, APIs, GPU server farms, and sensitive enterprise data operating continuously at enormous scale. At the same time, AI-driven environments are introducing increasingly dynamic machine-to-machine interactions across infrastructure, applications, and […]

The post Check Point Lays the Groundwork for the Future of AI Factory Security with NVIDIA appeared first on Check Point Blog.

  •  
❌