August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate

Key takeaways GenAI usage continued to grow, with the average user generating 106 prompts in August, up from 95 in July and around 78 in June, while high-risk prompts remained present at 1 in every 43 prompts. Although August recorded the lowest high-risk GenAI prompt rate in several months, 86% of regular GenAI-using organizations were still affected by high-risk prompt activity, showing that data exposure remains a persistent governance challenge. By industry, Healthcare & Medical recorded the highest GenAI prompt exposure rate at 4% (1 in 25 prompts), followed by Software and Business Services at 1 in every 28 prompts. […]

The post August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/WIgPcFh
via

ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts

Enterprises are connecting AI assistants to more of their real infrastructure every month, from inboxes to file drives to internal tools, on the assumption that the isolation between users and accounts holds. Check Point Research just tested that assumption against ChatGPT and found a way to break it. Using an internal service that was never meant to carry user data at all, CPR opened a working channel between two completely separate ChatGPT accounts and used it to hand one victim’s session a task from a total stranger, all while the victim’s own conversation looked entirely normal.  Key Takeaways  Check Point […]

The post ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/zWhKob4
via

NoName057(16) Renews #OpJapan

On August 24, 2026, NoName057(16), a pro-Russian hacktivist collective active since 2022, best known for its crowdsourced DDoSia attack platform, announced the (re)launch of #OpJapan, a DDoS campaign against Japanese entities. Motivation is cited as Japan’s continued support for Ukraine and NATO amid the Russia-Ukraine war.   A Recurring Campaign Against Japanese Organizations  NoName057(16) has targeted Japanese organizations multiple times since the war began, dubbing the attacks under the #OpJapan tag; the most recent prior instance ran in mid-February 2026, motivated by the deepening of Japan’s military cooperation with NATO and its support for Ukraine. In that February wave, NoName057(16) was […]

The post NoName057(16) Renews #OpJapan appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/HrqjYaR
via

Check Point Brings OpenAI Daybreak Models Across Its Security Platform to Help Defenders Find, Validate, and Remediate Risk

Three months ago, Check Point and OpenAI began expanding our work together through Daybreak, OpenAI’s cyber defense initiative. Since then, we have taken the partnership further, bringing OpenAI’s frontier cyber models into Check Point products and security workflows through the Daybreak Defense Network. And last week, we joined more than a hundred technology and security companies in backing OpenAI’s call for a collective, global surge in cyber defense. Each moved us forward, but the work doesn’t stop there. Security must continuously adapt as new threats and attacker capabilities emerge, the software and technology stacks we protect evolve, and organizations find […]

The post Check Point Brings OpenAI Daybreak Models Across Its Security Platform to Help Defenders Find, Validate, and Remediate Risk appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/5qrGntJ
via

Gambling Goblin: A Chinese-Speaking Actor Hijacks Brazilian Government Sites to Fuel a Global SEO Fraud Machine

Key Findings A Chinese-speaking threat actor, which CPR has dubbed “Gambling Goblin,” is compromising trusted government websites and turning them into infrastructure for a fraud operation built to scale The group compromises legitimate Brazilian government web servers, many of them .gov.br sites spanning federal, state, and municipal institutions, and installs malicious modules that silently turn them into reverse proxies for phishing content, invisible to the visitor The phishing pages impersonate Google Play, Microsoft Store, and Amazon, complete with fake ratings and reviews, and are used to push online gambling and sports betting The group is linked to Earth Berberoka, a […]

The post Gambling Goblin: A Chinese-Speaking Actor Hijacks Brazilian Government Sites to Fuel a Global SEO Fraud Machine appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/IvuPX1M
via

The Inbox Is Disappearing. Why Security Must Follow the Workspace

Enterprise work no longer fits neatly inside a defined perimeter. The modern workspace spans inboxes, browsers, SaaS applications, collaboration platforms, identities, endpoints, data stores and, increasingly, AI agents that can act across several of these environments at once.  Attackers have adapted to this reality faster than many enterprise security programs have. Rather than staying within a single product category, they follow the natural flow of work, moving from email to chat, from a browser session into a SaaS application, and from an identity prompt toward the data behind it.  That progression is exposing a structural gap in traditional security architecture. Many organizations still protect […]

The post The Inbox Is Disappearing. Why Security Must Follow the Workspace appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/hqaFOX7
via

Security Hardening Assessment: Prepare for AI Transformation Without Increasing Risk

As organizations accelerate AI adoption, AI introduces new security considerations, but it can also amplify existing weaknesses such as excessive permissions, misconfigurations, and poor data governance. Without the right security guardrails, these gaps can create broader exposure as AI gains access to more systems, applications, and data. Check Point Services’ Security Hardening Assessment combines automated validation and expert review to identify configuration gaps, prioritize remediation, and provide continuous visibility into security controls over time. How AI Expands the Attack Surface AI initiatives don’t operate in isolation. They connect to collaboration platforms, internal knowledge repositories, business applications, cloud environments, APIs, third-party […]

The post Security Hardening Assessment: Prepare for AI Transformation Without Increasing Risk appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/8x4mqsT
via

August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate

Key takeaways GenAI usage continued to grow, with the average user generating 106 prompts in August, up from 95 in July and around 78 in Jun...