The Goal Tells an Agent What to Do. Security Has to Govern How.

In this article An agent’s goal rarely says how the agent may reach it, and capable agents are good at finding routes nobody planned for. →NVIDIA Open Agent Safety Platform puts the boundary in the infrastructure, outside the agent’s reach →Check Point semantic monitoring judges whether each step still fits the task →the two already work together in a beta integration with NVIDIA OpenShell →the monitor’s verdict can arrive before the action runs, in under 100 milliseconds What the Goal Leaves Out When an organization hands an autonomous agent a job, such as processing supplier invoices, it states the goal […]

The post The Goal Tells an Agent What to Do. Security Has to Govern How. appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/PaAcuET
via

Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right

Cyber Asset Attack Surface Management (CAASM) solved a significant problem. Security teams can now say with confidence what they own.  But, two things separate a CAASM tool that stops there from one that actually moves the needle on risk. The first is what the inventory itself carries. The second is what it connects to. 1. An inventory needs to do more than list what exists A list of assets is just the beginning. The tools worth building on now attach criticality and connection data to every asset from day one, so a security team isn’t just looking at a spreadsheet […]

The post Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/Y4lT1nN
via

Can We Control Every AI Agent Before It Becomes Our Next Privileged Insider?

AI agents are moving into the enterprise much faster than most security programs were designed to handle. They are no longer just answering questions or generating content. Agents can read email, access SaaS applications, query databases, invoke APIs, use MCP tools, modify records and execute business workflows. In other words, AI is moving from generating answers to taking actions. For CISOs and C-level leaders, that changes the security conversation. The question isn’t simply whether an organization is using AI safely. A more important question is: Can we confidently identify, govern, monitor, and control every AI agent before it becomes our […]

The post Can We Control Every AI Agent Before It Becomes Our Next Privileged Insider? appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/bj20eul
via

Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616

As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our Firewall and Management products. This advisory addresses the active exploitation described below, and the immediate steps customers should take to protect affected systems. Check Point Research has identified active exploitation of two vulnerabilities affecting Security Gateway and Security Management: A fix for CVE-2026-85102 has been available since September 9, and customers who have applied it are already protected. CVE-2026-93616 is a newly discovered zero-day vulnerability in Security Management, and a fix is available now as part of […]

The post Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/s0zUSRi
via

No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security

In this article Nineteen Check Point AI Security R&D teams spent two days on one prompt: build the demo customers would ask to see twice. Three of the results tell a single story about securing AI agents, and none of it starts with an attacker. →an autonomous agent took dangerous actions with no attacker involved, it simply hit a wall and improvised →a single poisoned file in a code repository turned a popular coding agent into a data exfiltration channel →questioning an off-track agent prevented as many attacks as blocking it, and completed more legitimate work →the lesson for anyone […]

The post No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/t3qHjRc
via

Workforce AI Security Policy Management Is Now Conversational 

In this article The new Workforce AI MCP is Check Point’s own Model Context Protocol server for Workforce AI Security. Connect a compatible AI client and you can query, analyze, and manage your employee AI usage policy in natural language instead of working through filters, screens, and individual rule checks. →ask plain questions such as which rule applies to a given user and application, or whether a rule is shadowed by a higher-priority one →work across users, managed assets, GenAI application usage, DLP data types, and agent and MCP activity in a single conversation →create and update rules by request […]

The post Workforce AI Security Policy Management Is Now Conversational  appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/JH1Yy5M
via

When Security Operations Can’t Keep Up:  4 Ways Agentic Network Security Management Improves Security Operations

Security teams are under pressure.   Networks are growing. Cloud environments are expanding. AI is accelerating change across users, applications, and infrastructure.   At the same time, security teams are expected to maintain strong protection, support business initiatives, and operate efficiently.  The challenge is not a lack of security control. The challenge is keeping up with a hybrid environment that changes faster than people can manage it.   This challenge will only grow as organizations adopt AI. Gartner predicts that by 2028, 15% of day-to-day work decisions will be made autonomously by agentic AI. As environments become more dynamic, security operations will need to be adapted.   This is where agentic network security […]

The post When Security Operations Can’t Keep Up:  4 Ways Agentic Network Security Management Improves Security Operations appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/QRwOA6m
via

AI Models Broke Their Own Containment: Key Findings from the July-August 2026 AI Threat Landscape

Between mid-July and early August 2026, models being evaluated internally by OpenAI, Anthropic, and Meta reached real production systems outside their test environments. One exploited a previously unknown vulnerability to escape its sandbox entirely. At the same time, criminal groups showed that frontier capability isn’t required for serious attacks: a ransomware affiliate ran a full intrusion through Claude Code, and a separate campaign, JADEPUFFER, is now documented as the first case of agentic ransomware, an extortion operation a model carried out end to end once a human set it in motion. Check Point Research’s July-August 2026 AI Threat Landscape Digest […]

The post AI Models Broke Their Own Containment: Key Findings from the July-August 2026 AI Threat Landscape appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/Lvt3GIQ
via

Scammers Are Watching Airline Complaints and Posing as Customer Support

Check Point uncovers thousands of fake support accounts, with hundreds more appearing every day A delayed flight. Missing luggage. A refund that never arrived.  For frustrated customers, social media has become a direct route to customer support. They tag the company, explain the problem, and wait for a response.  However, threat actors are watching those same conversations.  A Check Point Exposure Management investigation uncovered a coordinated social engineering campaign in which scammers monitor public complaints, impersonate customer support accounts, and approach customers seeking help. Researchers engaged directly with the scammers and followed the attack from the first social media interaction […]

The post Scammers Are Watching Airline Complaints and Posing as Customer Support appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/pDLaWOf
via

Synchronous Control Monitoring: Preventing Harmful Agent Actions in Real Time

We ensure alignment and control in agents using synchronous control monitoring. Our model oversees agent execution, continuously ingests the trace as context, and prevents harmful actions before they execute in real time at sub-100ms latency. Agent trace at 30 tok/s, streamed to the control monitor model on the right. Prevents harmful actions before they are executed. Background Control Monitoring is a powerful tool for ensuring the runtime alignment and safety of autonomous agents. Since the Hugging Face Incident, the need for control monitoring on top of existing safety mechanisms was reinforced: OpenAI started investing more heavily into monitoring safety tools. […]

The post Synchronous Control Monitoring: Preventing Harmful Agent Actions in Real Time appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/1oEPHaB
via

Fake Voicemail Transcript Emails Target 7,800+ Organizations in Large-Scale Credential Phishing

Automated voicemail transcripts have become part of the daily rhythm of enterprise communication. They arrive with familiar subject lines, system-generated formatting, and little human context, exactly the qualities that make them easy to trust and easy to overlook. Attackers are now exploiting that familiarity, turning routine call-transcription notifications into a vehicle for credential phishing. Check Point researchers identified a large-scale phishing campaign that exploits this shift in enterprise behavior. The emails impersonate automated voicemail-transcript notifications and deliver malicious Scalable Vector Graphics (SVG) attachments that redirect users to credential-harvesting pages, converting a familiar collaboration workflow into a potential path for account […]

The post Fake Voicemail Transcript Emails Target 7,800+ Organizations in Large-Scale Credential Phishing appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/xZDHEf1
via

The Top Exposure Management Questions Security Leaders Ask: Insights from Customer Conversations (Part 2)

We analyzed ongoing conversations with prospective customers to find out what buyers ask most. Below are those questions, covering how Check Point Exposure Management helps teams validate risk, cut noise, coordinate remediation, and report progress. Part 1 covered how security leaders think about asset discovery, cloud visibility, threat intelligence, credential exposure, and integrations. Once teams know what’s exposed, the conversation shifts to prioritization and response. 1. How do you prioritize which exposures matter? Security teams often manage thousands of vulnerabilities across applications, endpoints, cloud resources, and internet facing infrastructure. A severity score alone does not provide enough context to determine […]

The post The Top Exposure Management Questions Security Leaders Ask: Insights from Customer Conversations (Part 2) appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/ctfMqn9
via

PuzzleMask: The Prompt Injection Hiding in Plain Sight

Introduction Most prompt injection detection is built to catch the obvious. Encoding anomalies, invisible unicode, emoji smuggling, the signatures a classifier can pattern match against. PuzzleMask, a newly disclosed technique, sidesteps all of it. It embeds a policy-violating payload inside fluent, properly punctuated prose, and gets that payload past an LLM-based gatekeeper without tripping any heuristics naively looking for obfuscation on the input side. The technique targets a specific architecture that’s become standard in production LLM pipelines: a fast, low-cost model screens incoming input against a policy before a more capable target model, often running with high reasoning effort and […]

The post PuzzleMask: The Prompt Injection Hiding in Plain Sight appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/dfDigy2
via

Check Point is a Leader in the 2026 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall

The AI era is rewriting the rules of network security. We believe our recognition as a Leader in the 2026 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall reflects how we help enterprises secure the AI transformation — end to end. Download your complimentary copy of the report: 2026 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall Why AI Changes the Security Equation AI adoption has outpaced the ability to govern it. Only 5% of organizations have full visibility into AI tool usage on their network1. The other 95% are working blind. That gap has consequences: 54% of organizations have already reported […]

The post Check Point is a Leader in the 2026 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/IjJ9B4K
via

August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate

Key takeaways GenAI usage continued to grow, with the average user generating 106 prompts in August, up from 95 in July and around 78 in June, while high-risk prompts remained present at 1 in every 43 prompts. Although August recorded the lowest high-risk GenAI prompt rate in several months, 86% of regular GenAI-using organizations were still affected by high-risk prompt activity, showing that data exposure remains a persistent governance challenge. By industry, Healthcare & Medical recorded the highest GenAI prompt exposure rate at 4% (1 in 25 prompts), followed by Software and Business Services at 1 in every 28 prompts. […]

The post August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/WIgPcFh
via

ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts

Enterprises are connecting AI assistants to more of their real infrastructure every month, from inboxes to file drives to internal tools, on the assumption that the isolation between users and accounts holds. Check Point Research just tested that assumption against ChatGPT and found a way to break it. Using an internal service that was never meant to carry user data at all, CPR opened a working channel between two completely separate ChatGPT accounts and used it to hand one victim’s session a task from a total stranger, all while the victim’s own conversation looked entirely normal.  Key Takeaways  Check Point […]

The post ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/zWhKob4
via

NoName057(16) Renews #OpJapan

On August 24, 2026, NoName057(16), a pro-Russian hacktivist collective active since 2022, best known for its crowdsourced DDoSia attack platform, announced the (re)launch of #OpJapan, a DDoS campaign against Japanese entities. Motivation is cited as Japan’s continued support for Ukraine and NATO amid the Russia-Ukraine war.   A Recurring Campaign Against Japanese Organizations  NoName057(16) has targeted Japanese organizations multiple times since the war began, dubbing the attacks under the #OpJapan tag; the most recent prior instance ran in mid-February 2026, motivated by the deepening of Japan’s military cooperation with NATO and its support for Ukraine. In that February wave, NoName057(16) was […]

The post NoName057(16) Renews #OpJapan appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/HrqjYaR
via

Check Point Brings OpenAI Daybreak Models Across Its Security Platform to Help Defenders Find, Validate, and Remediate Risk

Three months ago, Check Point and OpenAI began expanding our work together through Daybreak, OpenAI’s cyber defense initiative. Since then, we have taken the partnership further, bringing OpenAI’s frontier cyber models into Check Point products and security workflows through the Daybreak Defense Network. And last week, we joined more than a hundred technology and security companies in backing OpenAI’s call for a collective, global surge in cyber defense. Each moved us forward, but the work doesn’t stop there. Security must continuously adapt as new threats and attacker capabilities emerge, the software and technology stacks we protect evolve, and organizations find […]

The post Check Point Brings OpenAI Daybreak Models Across Its Security Platform to Help Defenders Find, Validate, and Remediate Risk appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/5qrGntJ
via

Gambling Goblin: A Chinese-Speaking Actor Hijacks Brazilian Government Sites to Fuel a Global SEO Fraud Machine

Key Findings A Chinese-speaking threat actor, which CPR has dubbed “Gambling Goblin,” is compromising trusted government websites and turning them into infrastructure for a fraud operation built to scale The group compromises legitimate Brazilian government web servers, many of them .gov.br sites spanning federal, state, and municipal institutions, and installs malicious modules that silently turn them into reverse proxies for phishing content, invisible to the visitor The phishing pages impersonate Google Play, Microsoft Store, and Amazon, complete with fake ratings and reviews, and are used to push online gambling and sports betting The group is linked to Earth Berberoka, a […]

The post Gambling Goblin: A Chinese-Speaking Actor Hijacks Brazilian Government Sites to Fuel a Global SEO Fraud Machine appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/IvuPX1M
via

The Inbox Is Disappearing. Why Security Must Follow the Workspace

Enterprise work no longer fits neatly inside a defined perimeter. The modern workspace spans inboxes, browsers, SaaS applications, collaboration platforms, identities, endpoints, data stores and, increasingly, AI agents that can act across several of these environments at once.  Attackers have adapted to this reality faster than many enterprise security programs have. Rather than staying within a single product category, they follow the natural flow of work, moving from email to chat, from a browser session into a SaaS application, and from an identity prompt toward the data behind it.  That progression is exposing a structural gap in traditional security architecture. Many organizations still protect […]

The post The Inbox Is Disappearing. Why Security Must Follow the Workspace appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/hqaFOX7
via

The Goal Tells an Agent What to Do. Security Has to Govern How.

In this article An agent’s goal rarely says how the agent may reach it, and capable agents are good at finding routes nobody planned for. →N...