Check Point Research Latest Research by our Team
- Breaking the Seal: Static Deobfuscation of JSCealâs Compiled V8 Bytecodeby shlomoo@checkpoint.com on August 31, 2026 at 1:38 pm
Research by:Â hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early The post Breaking the Seal: Static Deobfuscation of JSCealâs Compiled V8 Bytecode appeared first on Check Point Research.
- 31th August â Threat Intelligence Reportby urias on August 31, 2026 at 12:58 pm
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, The post 31th August â Threat Intelligence Report appeared first on Check Point Research.
- 24th August â Threat Intelligence Reportby urias on August 24, 2026 at 2:07 pm
For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latviaâs Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people â roughly two-thirds of the countryâs population â as well as 200,000 organizations. The The post 24th August â Threat Intelligence Report appeared first on Check Point Research.
- BTR Reforged: Weaponizing Defenderâs Remediation Driver as a Kernel Operation Primitiveby shlomoo@checkpoint.com on August 20, 2026 at 1:07 pm
Research by: JiĹĂ Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 â without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full The post BTR Reforged: Weaponizing Defenderâs Remediation Driver as a Kernel Operation Primitive appeared first on Check Point Research.
- Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtectby pedrod@checkpoint.com on August 18, 2026 at 1:05 pm
Research by: JaromĂr HoĹejĹĄĂ (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional downloaders and The post Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect appeared first on Check Point Research.
- 17th August â Threat Intelligence Reportby urias on August 17, 2026 at 1:37 pm
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombiaâs Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were The post 17th August â Threat Intelligence Report appeared first on Check Point Research.
- The State of Ransomware Q2 2026by matthewsu on August 13, 2026 at 12:54 pm
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but The post The State of Ransomware Q2 2026 appeared first on Check Point Research.
- Shattering the Dream â When a Job Offer Becomes a Zero-Day Attackby matthewsu on August 11, 2026 at 5:30 pm
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially The post Shattering the Dream â When a Job Offer Becomes a Zero-Day Attack appeared first on Check Point Research.
- 10th August â Threat Intelligence Reportby urias on August 10, 2026 at 1:53 pm
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained The post 10th August â Threat Intelligence Report appeared first on Check Point Research.
- When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workersby matthewsu on August 6, 2026 at 10:20 pm
By Yarden Porat, Check Point Research Key Points The short version We set out to break Cloudflare Code Mode, and ended up breaking Cloudflare Workers too. We did both by targeting workerd, the runtime beneath both: an in-process sandbox that relies entirely on V8 to isolate untrusted code. We found five memory-corruption bugs in workerdâs native C++ (the âglueâ The post When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers appeared first on Check Point Research.
- 3rd August â Threat Intelligence Reportby urias on August 3, 2026 at 1:15 pm
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported The post 3rd August â Threat Intelligence Report appeared first on Check Point Research.
- 27th July â Threat Intelligence Reportby urias on July 27, 2026 at 4:00 pm
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, The post 27th July â Threat Intelligence Report appeared first on Check Point Research.
- 20th July â Threat Intelligence Reportby urias on July 20, 2026 at 12:18 pm
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, The post 20th July â Threat Intelligence Report appeared first on Check Point Research.









