Check Point Research
checkpoint-research · B · active
https://research.checkpoint.com/
Check Point Research blog. RSS at https://research.checkpoint.com/feed/. Includes weekly Threat Intelligence Report; useful for the 'Updates' section of weekly summaries. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → feed https://research.checkpoint.com/feed/ 5 (listing) then webfetch the per-article URL for the body. AVOID: Nothing to avoid; both RSS and WebFetch on articles work cleanly.. | 2026-07-05 admiralty audit: B (research-lab), original vendor research lab, feed clean and current. Status stays active. | 2026-07-14 intel run: fetched via feed + article, contributed the Annual AI Security Report 2026 entry.
Cited in 15 entries
Citation cadence
Citation days per ISO week (17 weeks of coverage span, total 15).
- Gambling Goblin (Earth Berberoka overlap): a Chinese-speaking cluster compiles malicious Apache modules on compromised Brazilian .gov.br servers, borrowing their search-engine trust for a global gambling-SEO fraud network2026-09-03
- Windows Defender ships its own kernel write primitive: BTR.sys, the signed boot-time remediation driver, takes an encrypted job list from an alternate data stream and will delete or create any file or registry value asked of it2026-08-23
- StopAndProtect runs its whole operation off other people's WordPress sites, a must-use plugin that never appears in the plugin list, a hidden REST route that accepts PHP, and an installer that deletes itself2026-08-19
- Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets, FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress servers2026-08-12
- Check Point breaks out of Cloudflare's Code Mode sandbox through a use-after-free in workerd's native glue, prompt injection to native host code, and a cross-tenant heap read2026-08-08
- HOLLOWGRAPH: a Cavern-framework backdoor that turns a compromised Microsoft 365 calendar into a Graph-API dead-drop C22026-07-21
- Check Point Annual AI Security Report 2026, AI shifts from attack accelerant to autonomous operator, with the agent's trusted config store as the new persistence surface2026-07-14
- Check Point: Iran MOIS-linked "Cavern Manticore" ships a modular .NET C2 that uses three compilation formats as an anti-analysis layer, delivered via SysAid RMM abuse2026-07-09
- Crypto clipboard-hijacker campaign weaponises VirusTotal community reputation to suppress detection2026-06-18
- Check Point chains SQL injection to RCE in LangGraph's checkpointer (CVE-2025-67644 + CVE-2026-28277)2026-06-13
- The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named2026-06-12
- Check Point: a TDS-gated ecosystem impersonates security tools (Ghidra, dnSpy, ILSpy) to deliver SessionGate, RemusStealer and a clipboard hijacker2026-06-10
- The Gentlemen ransomware, Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor2026-05-29
- Unit 42, Iran's Screening Serpens (UNC1549 / Smoke Sandstorm / Nimbus Manticore): AppDomainManager hijacking silently disables ETW + strong-name checks in six new RATs2026-05-23
- The Gentlemen RaaS, backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHub2026-05-14