Check Point Research
checkpoint-research · B · active
https://research.checkpoint.com/
Check Point Research blog. RSS at https://research.checkpoint.com/feed/. Includes weekly Threat Intelligence Report; useful for the 'Updates' section of weekly summaries. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → feed https://research.checkpoint.com/feed/ 5 (listing) then webfetch the per-article URL for the body. AVOID: Nothing to avoid — both RSS and WebFetch on articles work cleanly.. | 2026-07-05 admiralty audit: B (research-lab) — original vendor research lab, feed clean and current. Status stays active. | 2026-07-14 intel run: fetched via feed + article, contributed the Annual AI Security Report 2026 entry.
Cited in 23 entries
Citation cadence
Citation days per ISO week (15 weeks of coverage span, total 19).
- Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets — FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress servers2026-08-12
- The CVE record failed as an index of what to patch in both directions this week — two national CERTs withdrew advisories built on CVEs an LLM invented, while three exploited or CVSS-10 flaws had no CVE at all and one vendor issued one CVE per bug class2026-08-09
- The AI attack surface moved below the prompt this week — the exploited layer was the gateway's own callback hooks, the C++ glue inside the sandbox, the coding agent's shell, and the API key's billing surface, all downstream of every prompt-level defence2026-08-09
- Check Point breaks out of Cloudflare's Code Mode sandbox through a use-after-free in workerd's native glue — prompt injection to native host code, and a cross-tenant heap read2026-08-08
- Kaspersky corroborates the Cavern/HOLLOWGRAPH cluster, associates it (low confidence) with OilRig (APT34), and details a DNS AAAA-record C2 config-recovery fallback2026-07-22
- The week's AI-and-attackers reporting converged on a calibrated read — AI is accelerating existing tradecraft, not creating a new attack class — and handed defenders a concrete hunt signal: emoji and Unicode artefacts in compiled-malware debug strings2026-07-19
- Check Point Annual AI Security Report 2026 — AI shifts from attack accelerant to autonomous operator, with the agent's trusted config store as the new persistence surface2026-07-14
- Threat-actor developments this week: Group-IB reframes Scattered Spider as a decentralised collective, and China- and Iran-nexus edge/ORB tradecraft advances2026-07-12
- Check Point: Iran MOIS-linked "Cavern Manticore" ships a modular .NET C2 that uses three compilation formats as an anti-analysis layer, delivered via SysAid RMM abuse2026-07-09
- Check Point State of Ransomware Q1 2026 — ecosystem consolidation, with Switzerland and Germany named2026-06-22
- Crypto clipboard-hijacker campaign weaponises VirusTotal community reputation to suppress detection2026-06-18
- Check Point chains SQL injection to RCE in LangGraph's checkpointer (CVE-2025-67644 + CVE-2026-28277)2026-06-13
- The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named2026-06-12
- Check Point: a TDS-gated ecosystem impersonates security tools (Ghidra, dnSpy, ILSpy) to deliver SessionGate, RemusStealer and a clipboard hijacker2026-06-10
- The Gentlemen ransomware — Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor2026-05-29
- Nimbus Manticore (UNC1549 / Screening Serpens) — Check Point details MiniFast backdoor, Zoom-task hijacking and SEO-poisoning delivery2026-05-27
- The Gentlemen / Storm-2697 — internal "Rocket" backend leaked by a rival; KELA and Check Point dissect the operator inner circle2026-05-25
- Check Point Q1 2026 State of Ransomware — ecosystem reconsolidates; LockBit returns with a deliberate Europe pivot2026-05-25
- The Gentlemen RaaS — backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHub2026-05-14
- "The Gentlemen" RaaS — operations continue post-leak, decryptor published, FortiOS / Erlang SSH initial access CVEs confirmed2026-05-11
- Looking ahead — 2026-W202026-05-11
- The Gentlemen RaaS — Europe-skewed operation surged approximately 448% QoQ; 32% of Q1 2026 victims in Europe; FortiGate CVE-2024-55591 initial-access funnel2026-05-04
- Looking ahead — 2026-W192026-05-04