The Approved-App Blind Spot: When Sanctioned AI Becomes Shadow AI

Approved App Blind Spot Blog Banner

At 9:03, an employee opens an approved AI assistant with a corporate account and asks it to summarize launch notes. At 9:27, a feature they need is unavailable in the enterprise version. They open the same service through a personal account and continue working. At 10:11, the CRM displays a new AI sidebar after a routine SaaS update. It can summarize customer records, draft follow-ups, and connect to the calendar. At 11:06, a browser extension offers to carry meeting notes from one application into another. One click later, a second AI service has joined the workflow. The employee has not […]

The post The Approved-App Blind Spot: When Sanctioned AI Becomes Shadow AI appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/jWeOyip
via

Back-to-School Cyber Risks Surge as Education Remains the World’s Most Attacked Sector

From record attack volumes to phishing campaigns targeting students and educators, threat actors are exploiting one of the busiest periods of the academic year. As students, teachers and families return to classrooms, campuses and online learning platforms at the end of summer, cyber-criminals are preparing for the new school year as well. According to Check Point Research, the education sector remains the world’s most targeted industry, facing significantly more cyberattacks than any other sector. Between January and July 2026, educational organizations such as colleges and universities, research institutes, and K-12 school systems alike, faced an average of 4,696 weekly cyberattacks […]

The post Back-to-School Cyber Risks Surge as Education Remains the World’s Most Attacked Sector appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/2LstHFN
via

The Mistake That Exposed a Global Cyber Crime Operation

Most cyber crime investigations reveal the aftermath of an attack. Few reveal the attackers themselves. That’s what makes Check Point Research‘s latest investigation into StopAndProtect so unusual. While analyzing a newly identified cyber crime operation, researchers uncovered a series of operational security (OPSEC) mistakes that exposed the attackers’ own infrastructure including: victim logs, screenshots, source code, internal management tools, and evidence of a campaign impacting more than 5,000 infected computers worldwide. The investigation also uncovered files referencing close to 2,000 compromised WordPress domains, providing a rare look inside how a modern cyber criminal operation is built and managed. According to […]

The post The Mistake That Exposed a Global Cyber Crime Operation appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/tdjMNHe
via

Reading the Signals in the OWASP LLM Top 10 2026

In this article OWASP has released the GenAI LLM Top 10 for 2026. The movement between rankings signals where AI security priorities are heading: toward agency, context and the consequences of AI actions. →prompt injection and sensitive information disclosure hold the top two positions →excessive agency jumps from LLM06 to LLM03, the biggest move in the ranking →hidden context exposure replaces system prompt leakage, widening what needs protecting →misinformation rises as AI output feeds workflows, code and automated actions OWASP has released the GenAI LLM Top 10 for 2026, updating one of the security community’s key reference points for understanding risk […]

The post Reading the Signals in the OWASP LLM Top 10 2026 appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/dRvWT6x
via

Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out.

Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it.  Key takeaways  Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% […]

The post Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out. appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/DbAX4v8
via

July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens

Key takeaways Weekly cyber attacks reached 2,336 per organization in July 2026, up 3% from June and 16% year over year Education remained the most attacked industry, averaging 4,848 weekly attacks per organization Latin America recorded the highest regional attack volume, while Europe saw one of the sharpest increases at 18% year over year GenAI adoption continued to expand, with organizations using an average of 8 tools and 1 in 36 prompts carrying a high risk of sensitive data exposure Email remained a key entry point, with 1 in every 128 emails classified as phishing and another 20% falling into […]

The post July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/dMJzY57
via

State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

It typically begins the same way it has for years, with an approach from a recruiter offering a role at a company the target would recognize, accompanied by a PDF describing the position in convincing detail. That approach remains one of the most effective entry points used by state sponsored threat actors today, and Check Point Research has spent recent months tracking a new wave of it. Operation Dream Job, the long running campaign attributed to the North Korea affiliated Lazarus group, has resurfaced with a previously undisclosed Windows vulnerability (CVE-2026-68820), a newly identified backdoor, and a command and control […]

The post State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/TD9golh
via

The Approved-App Blind Spot: When Sanctioned AI Becomes Shadow AI

At 9:03, an employee opens an approved AI assistant with a corporate account and asks it to summarize launch notes. At 9:27, a feature they ...