Gambling Goblin: A Chinese-Speaking Actor Hijacks Brazilian Government Sites to Fuel a Global SEO Fraud Machine

Key Findings A Chinese-speaking threat actor, which CPR has dubbed “Gambling Goblin,” is compromising trusted government websites and turning them into infrastructure for a fraud operation built to scale The group compromises legitimate Brazilian government web servers, many of them .gov.br sites spanning federal, state, and municipal institutions, and installs malicious modules that silently turn them into reverse proxies for phishing content, invisible to the visitor The phishing pages impersonate Google Play, Microsoft Store, and Amazon, complete with fake ratings and reviews, and are used to push online gambling and sports betting The group is linked to Earth Berberoka, a […]

The post Gambling Goblin: A Chinese-Speaking Actor Hijacks Brazilian Government Sites to Fuel a Global SEO Fraud Machine appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/IvuPX1M
via

The Inbox Is Disappearing. Why Security Must Follow the Workspace

Enterprise work no longer fits neatly inside a defined perimeter. The modern workspace spans inboxes, browsers, SaaS applications, collaboration platforms, identities, endpoints, data stores and, increasingly, AI agents that can act across several of these environments at once.  Attackers have adapted to this reality faster than many enterprise security programs have. Rather than staying within a single product category, they follow the natural flow of work, moving from email to chat, from a browser session into a SaaS application, and from an identity prompt toward the data behind it.  That progression is exposing a structural gap in traditional security architecture. Many organizations still protect […]

The post The Inbox Is Disappearing. Why Security Must Follow the Workspace appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/hqaFOX7
via

Security Hardening Assessment: Prepare for AI Transformation Without Increasing Risk

As organizations accelerate AI adoption, AI introduces new security considerations, but it can also amplify existing weaknesses such as excessive permissions, misconfigurations, and poor data governance. Without the right security guardrails, these gaps can create broader exposure as AI gains access to more systems, applications, and data. Check Point Services’ Security Hardening Assessment combines automated validation and expert review to identify configuration gaps, prioritize remediation, and provide continuous visibility into security controls over time. How AI Expands the Attack Surface AI initiatives don’t operate in isolation. They connect to collaboration platforms, internal knowledge repositories, business applications, cloud environments, APIs, third-party […]

The post Security Hardening Assessment: Prepare for AI Transformation Without Increasing Risk appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/8x4mqsT
via

Check Point Supports OpenAI’s Call for Collective Action on Cyber Defense

AI is reshaping cybersecurity at extraordinary speed. Check Point Research is already uncovering AI-powered attacks in the wild, revealing how threat actors are operating at greater scale and with growing sophistication. As these capabilities advance, cyber defense must advance just as quickly. That is why Check Point is proud to support OpenAI’s call for collective action on cyber defense, alongside organizations across the technology and cybersecurity ecosystem. We share the belief that meeting this challenge requires the industry to come together, expanding access to effective security tools, sharing intelligence and expertise, and helping organizations strengthen their defenses and resilience. For […]

The post Check Point Supports OpenAI’s Call for Collective Action on Cyber Defense appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/eYGQrqD
via

Stopping the AI Agent Actions No Rule Could See Coming

Check Point introduces a new class of contextual AI protection that understands an agent’s full context, intent and behavior across multiple steps, and prevents harmful actions before they execute. AI agents are already operating inside the enterprise. Coding agents write and execute code, interact with repositories, access cloud infrastructure and invoke tools. Workforce agents process documents and messages, retrieve enterprise data and complete business workflows. As these systems act with greater autonomy, security has to look beyond malicious prompts and individual payloads to the outcomes an agent’s actions can create. Harmful behavior does not always begin with something recognizably malicious. […]

The post Stopping the AI Agent Actions No Rule Could See Coming appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/cNfZnuP
via

Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations

Check Point has identified and blocked a large-scale email phishing campaign using fraudulent financial hardship and debt-relief offers to manipulate recipients into calling attacker-controlled phone numbers. Over the past 14 days, Check Point observed approximately 24,700 emails associated with the campaign targeting users across more than 9,000 organizations, demonstrating both the scale of the operation and the continued evolution of phishing beyond malicious links and attachments.  The campaign underscores a growing enterprise risk: phishing no longer needs an obvious malicious link, attachment, or spoofed sender to be effective. Attackers are turning routine-looking email into the entry point for trusted conversations that take users beyond traditional controls.  The Attack: […]

The post Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/Z0cdeAQ
via

The Approved-App Blind Spot: When Sanctioned AI Becomes Shadow AI

Approved App Blind Spot Blog Banner

At 9:03, an employee opens an approved AI assistant with a corporate account and asks it to summarize launch notes. At 9:27, a feature they need is unavailable in the enterprise version. They open the same service through a personal account and continue working. At 10:11, the CRM displays a new AI sidebar after a routine SaaS update. It can summarize customer records, draft follow-ups, and connect to the calendar. At 11:06, a browser extension offers to carry meeting notes from one application into another. One click later, a second AI service has joined the workflow. The employee has not […]

The post The Approved-App Blind Spot: When Sanctioned AI Becomes Shadow AI appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/jWeOyip
via

Gambling Goblin: A Chinese-Speaking Actor Hijacks Brazilian Government Sites to Fuel a Global SEO Fraud Machine

Key Findings A Chinese-speaking threat actor, which CPR has dubbed “Gambling Goblin,” is compromising trusted government websites and turnin...