< ciso
brief />
Tag Banner

All news with #check point tag

157 articles

PromptGuardX: Extending AI Security into Files

🛡️ PromptGuardX inspects PDFs before their content reaches an LLM or AI agent, detecting hidden instructions and obfuscation techniques that can enable prompt injection. Integrated into Check Point Threat Emulation, it extracts and normalizes text, locates suspicious instruction regions, analyzes context with fine-tuned classifiers, and returns explainable verdicts and confidence scores. This upstream file-layer protection complements runtime monitoring, access controls and prompt inspection.
read more →

Amazon Prime Big Deal Days 2026: Rising Cyber Threats

🔎 New Check Point Research findings show a surge in Amazon- and Prime Day-related domain registrations ahead of Fall Prime Day (October 6–7, 2026), with many domains flagged as malicious. The report documents phishing campaigns, fake storefronts, and credential-theft infrastructure targeting shoppers worldwide, and warns that generative AI is enabling more convincing scams. It urges consumers and organizations to verify URLs, enable MFA, and block threats proactively.
read more →

Securing AI Agents with NVIDIA OpenShell

🔒 This article examines how NVIDIA Open Agent Safety Platform and Check Point's semantic monitoring address gaps in autonomous agent control. It explains that prompts and model safeguards can be circumvented, so OpenShell enforces an infrastructure-level boundary while NVIDIA Sentry provides out-of-band hardware-isolated enforcement. Check Point integrates semantic monitoring to judge whether successive actions still match the agent's task and enforces controls through OpenShell's middleware.
read more →

Check Point warns of Security Gateway VPN RCE exploit

🔒 Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution flaw in the VPN certificate-handling of its Security Gateway product, and warned of active abuse of CVE-2026-93616 affecting the Management web service. The company reported attacks beginning September 12, 2026, originating from anonymization services, and advised administrators to apply LivePatch Take 26 or specified Jumbo Hotfixes, update Spark firewalls, and follow temporary VPN rule restrictions if updates are not possible.
read more →

InfraTrust report: Management systems under attack

🛡️ The September InfraTrust Pulse warns attackers are increasingly targeting infrastructure management systems across vendors, with many critical flaws exploited before or soon after disclosure. Between Aug 25 and Sep 17, InfraTrust tracked 158 advisories covering 1,699 vulnerabilities, including 42 critical and several with CVSS 10.0. The report highlights chained exploits against Cisco FMC and ISE, active exploitation of SonicWall and Check Point flaws, and supply-chain and firmware weaknesses.
read more →

Check Point warns of critical management server flaw

🔒 Check Point disclosed a critical management server vulnerability, CVE-2026-93616, exploited in targeted attacks on July 23 that allows unauthenticated web service access to run scripts. A patch was released on September 22 for affected Security Management Server versions; administrators should verify releases and install the fix in support article sk1000171. Separately, attempts to exploit a VPN certificate flaw, CVE-2026-85102, have targeted Spark firewalls since September 12 despite fixes issued on September 9. Check Point published mitigation and hunting guidance including indicators of compromise for both issues.
read more →

Check Point issues hotfix for critical management server zero‑day

🛡️ Check Point Software issued emergency hotfixes for a critical Security Management Server vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts via a path traversal flaw tracked as CVE-2026-93616. The company confirmed active exploitation against a small number of customers and published indicators of compromise and temporary mitigations for those who cannot immediately patch. The fix is included in the R82.20 Security Hotfix and applies to Management, Log, Multi‑Domain, and SmartEvent products.
read more →

Active exploitation of two high‑severity Check Point flaws

🔒 Check Point Research reports active exploitation of two critical vulnerabilities affecting Security Gateway and Security Management. CVE-2026-85102 (RCE during VPN certificate handling) had patches available since September 9 and is being actively probed; unpatched Spark customers are at risk. CVE-2026-93616 is a newly observed pre-authentication path traversal zero-day in Management; a fix is available now. Customers should install vendor fixes immediately and follow published mitigation and hunting guidance.
read more →

Conversational Policy Management for Workforce AI

🛡️ Check Point’s Workforce AI Security lets organizations control employee interactions with AI across apps, conversations, and agent activity. Through Manage Interactions, teams can define allowed AI applications, data handling for prompts and uploads, and govern the Model Context Protocol (MCP) servers and tools available to agents. The Workforce AI MCP enables natural-language access to policy information, investigation, and management, making complex analysis and changes more direct and efficient.
read more →

Critical Check Point flaw allows root code execution

🔒 Check Point Software released updates for a critical stack-based buffer overflow (CVE-2026-91843) in Security Management Server and Log Server login flows that can enable remote root code execution without user interaction. The vendor offered temporary mitigations, including system hardening and restricting trusted client IPs in SmartConsole, and advised teams to watch for "Administrator failed to log in: Username too long" alerts. The issue is part of a series of recent critical patches affecting Check Point firewalls and management systems.
read more →

Critical Check Point Management Server Flaw Alert

🔒 A critical stack overflow vulnerability (CVE-2026-91843) in Check Point Security Management and Log Servers can allow unauthenticated attackers to execute code as root over the network. Check Point issued a LivePatch fix and says it has no evidence of exploitation; customers with automatic updates enabled may already be protected. Administrators should apply sk1000155, confirm LivePatch installation, and limit Trusted Clients to known hosts while avoiding direct Internet exposure.
read more →

Dutch NCSC Warns of Critical Check Point VPN Flaws

🔒 The Dutch Nationaal Cyber Security Centrum (NCSC) warns of imminent exploitation of two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, urging immediate patching. Check Point issued fixes on September 9 (SK1000117, SK1000118) and provided LivePatch and hotfix releases for affected versions including R81.20, R82, and R82.10. Administrators are advised to apply updates promptly and restrict Site-to-Site VPN access to trusted IPs where possible.
read more →

Check Point patches two 9.8-rated VPN certificate flaws

🔒 Check Point released fixes on September 9 for two critical VPN certificate vulnerabilities affecting its Security Gateway appliances and Security Management Server. Both flaws — CVE-2026-85102 (certificate trust validation) and CVE-2026-85103 (ASN.1 heap overflow) — carry a CVSS score of 9.8 and could, under specific conditions, allow unauthenticated remote code execution. The company deployed fixes via Live Patch and Jumbo Hotfixes, but customers reported rollout delays, broken advisory links, and incomplete version clarity. Check Point says it discovered the issues internally and has no evidence of active exploitation.
read more →

Compiled V8 JavaScript Malware Evades Defenses

🔒 Check Point Research analyzed JSCeal, a sophisticated compiled V8 JavaScript malware used to harvest credentials, surveil victims, and intercept traffic. Operators deliver JSCeal via malvertising and fake trading sites, using Node.js runtimes and obfuscated payloads assembled in memory. The malware targets many Chromium-based browsers to extract cookies, passwords, OAuth tokens, and can replay sessions to access Google accounts. JSCeal also sets up local proxies, installs certificates, and applies service-specific request and response modifications to target crypto platforms and trading services.
read more →

Chinese-speaking group weaponises Brazilian sites

🛡️ Check Point Research attributes a sustained SEO fraud and phishing campaign to a Chinese-speaking cluster dubbed Gambling Goblin, active since mid-2025. Attackers implanted custom Apache modules to act as reverse proxies on compromised Brazilian government, education and commercial websites, redirecting specific visitors to localized phishing pages that impersonated app stores and promoted betting. The operation leveraged a broad Linux malware toolkit including AlphaAgent, oRAT and credential stealers, plus reconnaissance tools to map targets.
read more →

Check Point Endorses OpenAI Call for Cyber Defense

🔒 Check Point Research warns that AI is accelerating cyberattacks, requiring faster and broader defensive measures. The company publicly supports OpenAI’s open letter calling for collective action across industry, government, and AI labs to expand access to security tools, share intelligence, and help under-resourced organizations. Check Point emphasizes its 30-year commitment to prevention and pledges to support customers adopting AI securely while contributing to shared defenses and practical remediation efforts.
read more →

Contextual AI Protection Prevents Harmful Agent Actions

🛡️ Check Point introduces contextual AI protection that evaluates an agent’s full activity—intent, encountered information, prior actions and applicable policy—to prevent harmful or unauthorized outcomes before they execute. Traditional controls detect isolated risks like prompt injection or data exposure, but contextual protection links multi-step behavior to identify dangerous outcomes that no single rule would catch. Running in production, it enforces decisions in about 50 ms to block data leaks, unauthorized uploads, destructive commands and improper permission changes without slowing agents.
read more →

Large-Scale Debt-Relief Phishing Campaign Blocked

📧 Check Point detected and blocked a widespread email phishing campaign that used fraudulent debt-relief and financial hardship offers to trick recipients into calling attacker-controlled phone numbers. Over 14 days, about 24,700 messages targeted users at more than 9,000 organizations, highlighting phishing tactics that rely on social engineering and phone-based conversion rather than malicious links or attachments. Check Point Email Security uses AI, threat intelligence, and intent analysis to stop such campaigns before users engage.
read more →

Windows Defender driver can be repurposed for abuse

🛡️ Check Point Research found that Microsoft-signed Boot-Time Removal driver BTR.sys can be abused to perform kernel-level file and registry operations, potentially neutralizing security controls. The technique uses an undocumented encrypted transaction format rather than a conventional IOCTL interface and affects Windows versions from Windows 7 through Windows 11 25H2. CPR released a proof-of-concept tool, BTR_CLI, demonstrating extraction, transaction construction, and driver loading using the system's own copy of BTR.sys. Microsoft indicated the issue did not meet criteria for immediate servicing and noted the attack requires pre-existing privileges.
read more →

Microsoft Defender driver can be abused for kernel ops

🔒 Check Point Research demonstrated that Microsoft Defender's boot-time remediation driver, BTR.sys, can be repurposed to perform arbitrary kernel-level file and registry operations on Windows 7 through Windows 11 25H2 without exploiting a software flaw. The researcher published a proof-of-concept tool, BTR_CLI, and presented results at Black Hat USA 2026 and DEF CON 34, showing the driver can delete or move protected binaries and schedule actions for the next reboot. The technique requires administrative privileges (SeLoadDriverPrivilege) and leverages the driver's embedded RC4-encrypted protocol, making the component difficult to block without disrupting Defender. Check Point reported no evidence of real-world abuse and shared detection indicators and mitigation guidance focused on restricting SeLoadDriverPrivilege.
read more →