Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616

As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our Firewall and Management products. This advisory addresses the active exploitation described below, and the immediate steps customers should take to protect affected systems. Check Point Research has identified active exploitation of two vulnerabilities affecting Security Gateway and Security Management: A fix for CVE-2026-85102 has been available since September 9, and customers who have applied it are already protected. CVE-2026-93616 is a newly discovered zero-day vulnerability in Security Management, and a fix is available now as part of […]

The post Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/s0zUSRi
via

No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security

In this article Nineteen Check Point AI Security R&D teams spent two days on one prompt: build the demo customers would ask to see twice. Three of the results tell a single story about securing AI agents, and none of it starts with an attacker. →an autonomous agent took dangerous actions with no attacker involved, it simply hit a wall and improvised →a single poisoned file in a code repository turned a popular coding agent into a data exfiltration channel →questioning an off-track agent prevented as many attacks as blocking it, and completed more legitimate work →the lesson for anyone […]

The post No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/t3qHjRc
via

Workforce AI Security Policy Management Is Now Conversational 

In this article The new Workforce AI MCP is Check Point’s own Model Context Protocol server for Workforce AI Security. Connect a compatible AI client and you can query, analyze, and manage your employee AI usage policy in natural language instead of working through filters, screens, and individual rule checks. →ask plain questions such as which rule applies to a given user and application, or whether a rule is shadowed by a higher-priority one →work across users, managed assets, GenAI application usage, DLP data types, and agent and MCP activity in a single conversation →create and update rules by request […]

The post Workforce AI Security Policy Management Is Now Conversational  appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/JH1Yy5M
via

When Security Operations Can’t Keep Up:  4 Ways Agentic Network Security Management Improves Security Operations

Security teams are under pressure.   Networks are growing. Cloud environments are expanding. AI is accelerating change across users, applications, and infrastructure.   At the same time, security teams are expected to maintain strong protection, support business initiatives, and operate efficiently.  The challenge is not a lack of security control. The challenge is keeping up with a hybrid environment that changes faster than people can manage it.   This challenge will only grow as organizations adopt AI. Gartner predicts that by 2028, 15% of day-to-day work decisions will be made autonomously by agentic AI. As environments become more dynamic, security operations will need to be adapted.   This is where agentic network security […]

The post When Security Operations Can’t Keep Up:  4 Ways Agentic Network Security Management Improves Security Operations appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/QRwOA6m
via

AI Models Broke Their Own Containment: Key Findings from the July-August 2026 AI Threat Landscape

Between mid-July and early August 2026, models being evaluated internally by OpenAI, Anthropic, and Meta reached real production systems outside their test environments. One exploited a previously unknown vulnerability to escape its sandbox entirely. At the same time, criminal groups showed that frontier capability isn’t required for serious attacks: a ransomware affiliate ran a full intrusion through Claude Code, and a separate campaign, JADEPUFFER, is now documented as the first case of agentic ransomware, an extortion operation a model carried out end to end once a human set it in motion. Check Point Research’s July-August 2026 AI Threat Landscape Digest […]

The post AI Models Broke Their Own Containment: Key Findings from the July-August 2026 AI Threat Landscape appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/Lvt3GIQ
via

Scammers Are Watching Airline Complaints and Posing as Customer Support

Check Point uncovers thousands of fake support accounts, with hundreds more appearing every day A delayed flight. Missing luggage. A refund that never arrived.  For frustrated customers, social media has become a direct route to customer support. They tag the company, explain the problem, and wait for a response.  However, threat actors are watching those same conversations.  A Check Point Exposure Management investigation uncovered a coordinated social engineering campaign in which scammers monitor public complaints, impersonate customer support accounts, and approach customers seeking help. Researchers engaged directly with the scammers and followed the attack from the first social media interaction […]

The post Scammers Are Watching Airline Complaints and Posing as Customer Support appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/pDLaWOf
via

Synchronous Control Monitoring: Preventing Harmful Agent Actions in Real Time

We ensure alignment and control in agents using synchronous control monitoring. Our model oversees agent execution, continuously ingests the trace as context, and prevents harmful actions before they execute in real time at sub-100ms latency. Agent trace at 30 tok/s, streamed to the control monitor model on the right. Prevents harmful actions before they are executed. Background Control Monitoring is a powerful tool for ensuring the runtime alignment and safety of autonomous agents. Since the Hugging Face Incident, the need for control monitoring on top of existing safety mechanisms was reinforced: OpenAI started investing more heavily into monitoring safety tools. […]

The post Synchronous Control Monitoring: Preventing Harmful Agent Actions in Real Time appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/1oEPHaB
via

Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616

As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements...