When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context

When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context

A few weeks ago, an AI cyber evaluation produced an unexpectedly efficient strategy for solving a benchmark: the agents went looking for the answers. According to OpenAI’s preliminary disclosure, models being tested for advanced cyber capabilities found ways to obtain secret information that could help them complete a benchmark. They chained vulnerabilities, stolen credentials, internet access, and inferences about where benchmark material might be hosted. The route eventually reached Hugging Face infrastructure, where the activity was detected and contained. Hugging Face has since published a technical reconstruction of 17,600 actions. Its investigators found a coherent intrusion that rebuilt tooling, tested […]

The post When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/7MELZkY
via

Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance

More than 30 Minnesota water systems were hit in one coordinated cyber attack. Within days, the Five Eyes told critical infrastructure operators to be ready to pull the plug.  Thirty water systems in two days  Over two days in late July, a coordinated cyber attack hit more than 30 community water systems across Minnesota. The treatment plant in Braham went offline. Plymouth lost cellular communications to two water towers and its wastewater lift stations. Maple Plain declared a local state of emergency. Early reporting points to internet-exposed programmable logic controllers (PLCs) as the way in, and investigators are examining links to Iranian affiliated activity. […]

The post Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/scJmETg
via

Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms

Frost & Sullivan evaluated more than 30 vendors that identified themselves as enterprise risk mitigation and management (ERMM) platforms. Only 15 met the bar for inclusion. Just five earned Visionary Leader status. Check Point Exposure Management is one of them. What Frost & Sullivan Was Actually Measuring The Frost Radar™: Enterprise Risk Mitigation and Management Platforms, 2026 set a high bar for qualification. Vendors had to natively offer attack surface management, cyber threat intelligence, and digital risk protection in a unified platform. Point solutions requiring integration with external remediation tools were excluded. Platforms had to deliver both an outside-in view […]

The post Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/fZp7VYv
via

AI Escaped a Sandbox. That is Not What Should Worry You

What OpenAI’s and Anthropic’s testing incidents really teach defenders  In the past two weeks, two of the world’s leading AI labs have disclosed the same unsettling result. During their own safety testing, their most capable models reached real companies’ systems. First OpenAI, whose models broke into Hugging Face. Then Anthropic, whose models reached three more organizations.  Read the disclosures closely. Two facts carry the weight.  First, the safeguards were not defeated. They were switched off by design. OpenAI ran the models with reduced cyber refusals and safety classifiers disabled, to measure raw capability on a cyber benchmark. A model doing […]

The post AI Escaped a Sandbox. That is Not What Should Worry You appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/nxd3LaI
via

Introducing the Industry’s First AI Network Firewall

AI has introduced a new class of network traffic. Prompts, file uploads, model calls, and agent actions carrying sensitive business context now traverse the network as organizations race to adopt AI and achieve their business goals. Traditional firewalls were never built to understand these connections, AI activity often looks like ordinary web traffic, leaving the firewall unable to determine whether a prompt contains sensitive data, an agent is calling a tool it should never access, or an application’s AI model is subjected to a malicious prompt. These challenges demand comprehensive protection, which is why Check Point created the AI Defense […]

The post Introducing the Industry’s First AI Network Firewall appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/sN8z7d3
via

Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon

Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page. Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft’s trusted […]

The post Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/auW8Er7
via

AI Agent Security Just Had Its Catalyst Moment

There are certain moments in technology where you realize the conversation is about to change. I remember the first time I launched an EC2 instance. I remember trying Uber when there were only a handful of cars on the road. I remember riding in a Waymo before autonomous driving felt normal. Each one was an early glimpse of a future arriving a little earlier than everyone else expected. That’s how this week felt to me. When OpenAI disclosed that models operating as agents during an internal evaluation had found a path out of an isolated research environment and ultimately reached […]

The post AI Agent Security Just Had Its Catalyst Moment appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/5RDQ7KH
via

When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context

A few weeks ago, an AI cyber evaluation produced an unexpectedly efficient strategy for solving a benchmark: the agents went looking for the...