Check Point Blog Blog
- Check Point Brings OpenAI Daybreak Models Across Its Security Platform to Help Defenders Find, Validate, and Remediate Riskby lizwu@checkpoint.com on September 3, 2026 at 9:00 pm
Three months ago, Check Point and OpenAI began expanding our work together through Daybreak, OpenAIās cyber defense initiative. Since then, we have taken the partnership further, bringing OpenAIās frontier cyber models into Check Point products and security workflows through the Daybreak Defense Network. And last week, we joined more than a hundred technology and security companies in backing OpenAIās call for a collective, global surge in cyber defense. Each moved us forward, but the work doesnāt stop there. Security must continuously adapt as new threats and attacker capabilities emerge, the software and technology stacks we protect evolve, and organizations find The post Check Point Brings OpenAI Daybreak Models Across Its Security Platform to Help Defenders Find, Validate, and Remediate Risk appeared first on Check Point Blog.
- AI Observability Must Evolve for the Agentic Eraby maciejd@checkpoint.com on September 2, 2026 at 1:00 pm
In this article Traditional observability tells you whether software worked. For AI agents, the harder question is whether the system made the right decision, and the telemetry that answers it must also be able to stop unsafe actions before they execute. āagents need a decision trace: goal, context, plan, tools, credentials, actions, and outcomes in one connected record āthe OpenAI incident report shows the gap: the signal existed more than a day before the Hugging Face breach, but nothing was watching it āshared infrastructure that two agents can both reach is a communication channel and an attack surface, whether anyone The post AI Observability Must Evolve for the Agentic Era appeared first on Check Point Blog.
- Gambling Goblin: A Chinese-Speaking Actor Hijacks Brazilian Government Sites to Fuel a Global SEO Fraud Machineby anap on September 2, 2026 at 10:00 am
Key Findings A Chinese-speaking threat actor, which CPR has dubbed āGambling Goblin,ā is compromising trusted government websites and turning them into infrastructure for a fraud operation built to scale The group compromises legitimate Brazilian government web servers, many of them .gov.br sites spanning federal, state, and municipal institutions, and installs malicious modules that silently turn them into reverse proxies for phishing content, invisible to the visitor The phishing pages impersonate Google Play, Microsoft Store, and Amazon, complete with fake ratings and reviews, and are used to push online gambling and sports betting The group is linked to Earth Berberoka, a The post Gambling Goblin: A Chinese-Speaking Actor Hijacks Brazilian Government Sites to Fuel a Global SEO Fraud Machine appeared first on Check Point Blog.
- The Inbox Is Disappearing. Why Security Must Follow the Workspaceby lizwu@checkpoint.com on September 1, 2026 at 4:45 pm
Enterprise work no longer fitsĀ neatly insideĀ a defined perimeter. The modern workspace spans inboxes, browsers, SaaS applications, collaboration platforms, identities, endpoints, data stores and, increasingly, AI agents that can act across several of these environments at once.Ā Attackers have adapted to this reality faster than many enterprise security programs have. Rather than staying withinĀ a single productĀ category, they follow the natural flow of work, moving from email to chat, from a browser session into a SaaS application, and from an identity prompt toward the data behind it.Ā That progression is exposing a structural gap in traditional security architecture. Many organizations still protect The post The Inbox Is Disappearing. Why Security Must Follow the Workspace appeared first on Check Point Blog.
- Security Hardening Assessment: Prepare for AI Transformation Without Increasing Riskby lizwu@checkpoint.com on August 31, 2026 at 1:00 pm
As organizations accelerate AI adoption, AI introduces new security considerations, but it can also amplify existing weaknesses such as excessive permissions, misconfigurations, and poor data governance. Without the right security guardrails, these gaps can create broader exposure as AI gains access to more systems, applications, and data. Check Point Servicesā Security Hardening Assessment combines automated validation and expert review to identify configuration gaps, prioritize remediation, and provide continuous visibility into security controls over time. How AI Expands the Attack Surface AI initiatives donāt operate in isolation. They connect to collaboration platforms, internal knowledge repositories, business applications, cloud environments, APIs, third-party The post Security Hardening Assessment: Prepare for AI Transformation Without Increasing Risk appeared first on Check Point Blog.
- Check Point Supports OpenAIās Call for Collective Action on Cyber Defenseby lizwu@checkpoint.com on August 27, 2026 at 5:18 pm
AI is reshaping cybersecurity at extraordinary speed. Check Point Research is already uncovering AI-powered attacks in the wild, revealing how threat actors are operating at greater scale and with growing sophistication. As these capabilities advance, cyber defense must advance just as quickly. That is why Check Point is proud to support OpenAIās call for collective action on cyber defense, alongside organizations across the technology and cybersecurity ecosystem. We share the belief that meeting this challenge requires the industry to come together, expanding access to effective security tools, sharing intelligence and expertise, and helping organizations strengthen their defenses and resilience. For The post Check Point Supports OpenAIās Call for Collective Action on Cyber Defense appeared first on Check Point Blog.
- Stopping the AI Agent Actions No Rule Could See Comingby maciejd@checkpoint.com on August 26, 2026 at 12:55 pm
Check Point introduces a new class of contextual AI protection that understands an agentās full context, intent and behavior across multiple steps, and prevents harmful actions before they execute. AI agents are already operating inside the enterprise. Coding agents write and execute code, interact with repositories, access cloud infrastructure and invoke tools. Workforce agents process documents and messages, retrieve enterprise data and complete business workflows. As these systems act with greater autonomy, security has to look beyond malicious prompts and individual payloads to the outcomes an agentās actions can create. Harmful behavior does not always begin with something recognizably malicious. The post Stopping the AI Agent Actions No Rule Could See Coming appeared first on Check Point Blog.
- Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizationsby lizwu@checkpoint.com on August 25, 2026 at 1:00 pm
Check Point hasĀ identifiedĀ and blocked a large-scale email phishing campaign using fraudulent financial hardship and debt-relief offers to manipulate recipients into calling attacker-controlled phone numbers. Over the pastĀ 14 days, Check PointĀ observedĀ approximatelyĀ 24,700 emails associated with the campaign targeting users across more than 9,000 organizations,Ā demonstratingĀ both the scale of the operation and the continued evolution of phishing beyond malicious links and attachments.Ā The campaign underscores a growing enterprise risk: phishing no longer needs an obvious malicious link, attachment, or spoofed sender to be effective. Attackers are turning routine-looking email into the entry point for trusted conversations that take users beyond traditional controls.Ā The Attack: The post Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations appeared first on Check Point Blog.
- The Approved-App Blind Spot: When Sanctioned AI Becomes Shadow AIby maciejd@checkpoint.com on August 20, 2026 at 9:00 am
At 9:03, an employee opens an approved AI assistant with a corporate account and asks it to summarize launch notes. At 9:27, a feature they need is unavailable in the enterprise version. They open the same service through a personal account and continue working. At 10:11, the CRM displays a new AI sidebar after a routine SaaS update. It can summarize customer records, draft follow-ups, and connect to the calendar. At 11:06, a browser extension offers to carry meeting notes from one application into another. One click later, a second AI service has joined the workflow. The employee has not The post The Approved-App Blind Spot: When Sanctioned AI Becomes Shadow AI appeared first on Check Point Blog.
- Back-to-School Cyber Risks Surge as Education Remains the Worldās Most Attacked Sectorby lizwu@checkpoint.com on August 19, 2026 at 1:00 pm
From record attack volumes to phishing campaigns targeting students and educators, threat actors are exploiting one of the busiest periods of the academic year. As students, teachers and families return to classrooms, campuses and online learning platforms at the end of summer, cyber-criminals are preparing for the new school year as well. According to Check Point Research, the education sector remains the worldās most targeted industry, facing significantly more cyberattacks than any other sector. Between January and July 2026, educational organizations such as colleges and universities, research institutes, and K-12 school systems alike, faced an average of 4,696 weekly cyberattacks The post Back-to-School Cyber Risks Surge as Education Remains the Worldās Most Attacked Sector appeared first on Check Point Blog.
















