REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
36 reports · page 1 of 1
checkpoint_research · tlp:amber · 7/20/2026, 12:18:41 PM
20th July – Threat Intelligence Report For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] The post 20th July – Threat Intelligence R…
Read original ↗https://research.checkpoint.com/2026/20th-july-threat-intelligence-reportcheckpoint_research · tlp:amber · 7/14/2026, 12:51:31 AM
AI Security Report 2026 For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that goes further. AI has crossed from assistant to operator. Where it once helped attackers prepare, it now runs the […] The post AI Security Report 2026 appeared first on Che…
checkpoint_research · tlp:amber · 7/13/2026, 1:06:08 PM
13th July – Threat Intelligence Report For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license […] The post 13th July – Threat Intel…
Read original ↗https://research.checkpoint.com/2026/13th-july-threat-intelligence-reportcheckpoint_research · tlp:amber · 7/6/2026, 12:25:02 PM
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig […] The post Cavern Manticore…
Read original ↗https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-frameworkcheckpoint_research · tlp:amber · 7/6/2026, 12:01:54 PM
6th July – Threat Intelligence Report For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the network of parent company River Financial Corporation on June 16. The bank found […] The post 6th July – Threat Intelligence Report appeared first on Check Po…
Read original ↗https://research.checkpoint.com/2026/6th-july-threat-intelligence-report-2checkpoint_research · tlp:amber · 7/1/2026, 10:05:35 AM
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped software development, and malware development has followed the same path. Check Point Research has documented this trend from early experiments showing that AI systems could generate offensive components, to cases of cybercriminals using ChatGPT to create malicious tools…
Read original ↗https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-techniquecheckpoint_research · tlp:amber · 6/29/2026, 2:06:59 PM
29th June – Threat Intelligence Report For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Polymarket, a large cryptocurrency-based prediction market, has confirmed a supply chain attack after a third-party frontend vendor breach led to malicious JavaScript being injected into its website. Attackers tricked users into approving fraudulent […] The post 29th June – Threat Intel…
Read original ↗https://research.checkpoint.com/2026/29th-june-threat-intelligence-report-2checkpoint_research · tlp:amber · 6/22/2026, 4:00:02 PM
22nd June – Threat Intelligence Report For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for […] The post 22nd June – Threat Intelligence …
Read original ↗https://research.checkpoint.com/2026/22nd-june-threat-intelligence-reportcheckpoint_research · tlp:amber · 6/17/2026, 1:38:55 PM
From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker Key Points Introduction In this research, we analyze a clipboard hijacker campaign that is hidden inside a collection of “solutions” and “tools” that claim to give users an unfair advantage. These offers include Solana and Pump.fun sniper bots (automated tools that try to buy new tokens or meme coins faster than other traders), Aviator Predictor […] The post From Stars to Upvotes: Fake Reputatio…
Read original ↗https://research.checkpoint.com/2026/from-stars-to-upvotes-fake-reputation-fueling-a-crypto-clipboard-hijackercheckpoint_research · tlp:amber · 6/15/2026, 1:40:44 PM
15th June – Threat Intelligence Report For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The University of Nottingham, a UK research university, has suffered a data breach after ShinyHunters accessed its student records system. The incident affected about 454,600 current and former students and exposed contact details, […] The post 15th June – Threat Intelligence Report app…
Read original ↗https://research.checkpoint.com/2026/15th-june-threat-intelligence-reportcheckpoint_research · tlp:amber · 6/11/2026, 1:37:11 PM
From SQLi to RCE – Exploiting LangGraph’s Checkpointer By Yarden Porat AI agents need memory. Frameworks like LangGraph provide it through checkpointers – persistence layers that store execution state. But what happens when that persistence layer isn’t locked down? Key Points Background LangGraph is an open-source framework for building stateful, multi-agent AI systems with built-in persistence. It’s an extension of LangChain, with over […] The post F…
Read original ↗https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointercheckpoint_research · tlp:amber · 6/8/2026, 2:47:59 PM
8th June – Threat Intelligence Report For the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES DentaQuest, a U.S. dental benefits administrator owned by Sun Life, has suffered a data breach after threat group ShinyHunters leaked exfiltrated data. Analysts assessed that 2.6 million accounts were exposed, including names, emails, […] The post 8th June – Threat Intelligence Report app…
Read original ↗https://research.checkpoint.com/2026/8th-june-threat-intelligence-reportcheckpoint_research · tlp:amber · 6/3/2026, 1:21:44 PM
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem Research by: Alexey Bukhteyev Key Takeaways Introduction When we search Google for a popular piece of software, we usually click the first result, sometimes without even looking at the rest, because official project sites tend to rank highest and appear near the top of the results. After landing on a site with a professional design and […] The post Impersonation, Click Hijacking, and …
Read original ↗https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystemcheckpoint_research · tlp:amber · 6/1/2026, 2:43:11 PM
1st June – Threat Intelligence Report For the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Carnival Corporation, a global cruise line operator, has confirmed a data breach affecting nearly 6 million people after attackers used social engineering to compromise an employee account. Exposed information may include names, contact […] The post 1st June – Threat Intelligence Report a…
Read original ↗https://research.checkpoint.com/2026/1st-june-threat-intelligence-reportcheckpoint_research · tlp:amber · 5/26/2026, 10:09:59 AM
AI Threat Landscape Digest March-April 2026 Executive Summary During the March–April 2026 reporting period, AI use in offensive operations advanced from development and planning to real-time operational deployment. Multiple independent cases, involving individual criminal actors, mass exploitation platforms, ransomware groups, and state-sponsored espionage, show evidence of commercial AI models executing autonomous attack workflows across extended campaigns. Key findings: AI…
Read original ↗https://research.checkpoint.com/2026/ai-threat-landscape-digest-march-april-2026checkpoint_research · tlp:amber · 5/25/2026, 3:08:40 PM
25th May – Threat Intelligence Report For the latest discoveries in cyber research for the week of 25th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES 7-Eleven, the global convenience store chain, confirmed a breach after an unauthorized access to systems used for franchisee documents. ShinyHunters claimed responsibility and said it stole more than 600,000 Salesforce records containing personal […] The post 25th May – Threat Intelligenc…
Read original ↗https://research.checkpoint.com/2026/25th-may-threat-intelligence-reportcheckpoint_research · tlp:amber · 5/22/2026, 3:09:29 PM
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict Key Findings Introduction During the recent geopolitical tensions in the Middle East, we reported on multiple Iran-nexus threat actors advancing Iran’s strategic objectives through cyber operations. These activities included targeting internet-connected cameras, conducting destructive attacks against US and Israeli entities, and exfiltrating data from cloud environme…
Read original ↗https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflictcheckpoint_research · tlp:amber · 5/18/2026, 2:58:29 PM
18th May – Threat Intelligence Report For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to GitHub files through compromised third-party development software, while stating that […] The post 18th May – Threat Intelligence Repor…
Read original ↗https://research.checkpoint.com/2026/18th-may-threat-intelligence-reportcheckpoint_research · tlp:amber · 5/13/2026, 1:01:01 PM
Thus Spoke…The Gentlemen Key Points Introduction The Gentlemen ransomware‑as‑a‑service (RaaS) operation is a relatively new group that emerged around mid‑2025. Its operators advertise the service across multiple underground forums, promoting their ransomware platform and inviting penetration testers and other technically skilled actors to join as affiliates. In 2026, based on victims listed on the data leak site (DLS), […] The post Thus Spoke…The Gentlemen appeared fir…
Read original ↗https://research.checkpoint.com/2026/thus-spoke-the-gentlemencheckpoint_research · tlp:amber · 5/11/2026, 12:49:37 PM
11th May – Threat Intelligence Report For the latest discoveries in cyber research for the week of 11th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Instructure, the US education technology company behind the Canvas learning platform, has confirmed a major data breach affecting its cloud-hosted environment. Exposed data reportedly includes student and staff records and private messages, while […] The post 11th May – Threat Intelligenc…
Read original ↗https://research.checkpoint.com/2026/11th-may-threat-intelligence-reportcheckpoint_research · tlp:amber · 5/11/2026, 9:58:28 AM
The State of Ransomware – Q1 2026 Key Findings Ransomware in Q1 2026: Consolidation at Scale During the first quarter of 2026, we monitored more than 70 active data leak sites (DLS) that collectively listed 2,122 new victims. This figure represents a 12.2% decline from the Q4 2025 all-time record of 2,416 victims but remains the second-highest Q1 on record at 117% […] The post The State of Ransomware – Q1 2026 appeared first on Check Point Research . Key Finding…
Read original ↗https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026checkpoint_research · tlp:amber · 5/4/2026, 1:49:31 PM
4th May – Threat Intelligence Report For the latest discoveries in cyber research for the week of 4th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Medtronic, a global medical device maker, has disclosed a cyberattack on its corporate IT systems. An unauthorized party accessed data, while the company reported no impact on products, operations, or financial systems. Threat […] The post 4th May – Threat Intelligence Report appeared first…
Read original ↗https://research.checkpoint.com/2026/4th-may-threat-intelligence-reportcheckpoint_research · tlp:amber · 4/28/2026, 1:03:01 PM
VECT: Ransomware by design, Wiper by accident Key Takeaways Background VECT Ransomware is a Ransomware-as-a-Service (RaaS) program that made its first appearance in December 2025 on a Russian-language cybercrime forum. After claiming their first two victims in January 2026, the group got back into the public eye due to an announcement of a partnership with TeamPCP, the actor behind several supply-chain attacks […] The post VECT: Ransomware by design, Wiper by accident …
Read original ↗https://research.checkpoint.com/2026/vect-ransomware-by-design-wiper-by-accidentcheckpoint_research · tlp:amber · 4/27/2026, 12:07:53 PM
27th April – Threat Intelligence Report For the latest discoveries in cyber research for the week of 27th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vercel, a frontend cloud platform, has disclosed a security incident linked to a compromise at Context.ai, where stolen OAuth tokens enabled unauthorized access through a connected app. The company reported access to employee […] The post 27th April – Threat Intelligence Report appear…
Read original ↗https://research.checkpoint.com/2026/27th-april-threat-intelligence-reportcheckpoint_research · tlp:amber · 4/20/2026, 2:24:24 PM
20th April – Threat Intelligence Report For the latest discoveries in cyber research for the week of 20th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Booking.com, the Amsterdam-based travel platform, has confirmed a data breach after unauthorized parties accessed reservation data linked to some customers. Exposed information included names, email addresses, phone numbers, physical addresses, and booking […] The post 20th April – Th…
Read original ↗https://research.checkpoint.com/2026/20th-april-threat-intelligence-reportcheckpoint_research · tlp:amber · 4/20/2026, 12:55:53 PM
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy Key Points The Gentlemen RaaS The Gentlemen ransomware‑as‑a‑service (RaaS) operation is a relatively new group that emerged around mid‑2025. The operators advertise their services across multiple underground forums, promoting their ransomware platform and inviting penetration testers (and other technically skilled actors) to join as affiliates. The RaaS provides affiliates with multi‑OS lockers for Windows…
Read original ↗https://research.checkpoint.com/2026/dfir-report-the-gentlemencheckpoint_research · tlp:amber · 4/13/2026, 1:11:17 PM
13th April – Threat Intelligence Report For the latest discoveries in cyber research for the week of 13th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The Los Angeles Police Department has reported a data breach involving a digital storage system used by the L.A. City Attorney’s Office. The exposure included 7.7 terabytes and more than 337,000 files, […] The post 13th April – Threat Intelligence Report appeared first on Check Point …
Read original ↗https://research.checkpoint.com/2026/13th-april-threat-intelligence-reportcheckpoint_research · tlp:amber · 4/6/2026, 11:21:31 AM
6th April – Threat Intelligence Report For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The European Commission, the European Union’s executive body, has confirmed a data breach after its Europa.eu platform was compromised through a third-party exchange linked to the Trivy supply chain attack. The incident […] The post 6th April – Threat Intelligence Report appeared…
Read original ↗https://research.checkpoint.com/2026/6th-march-threat-intelligence-report-2checkpoint_research · tlp:amber · 3/31/2026, 1:16:50 PM
Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets Key Points Introduction At the beginning of 2026, Check Point Research observed a series of targeted attacks against government entities in Southeast Asia carried out via a legitimate TrueConf software installed in the targets’ environment. The investigation led to the discovery of a zero-day vulnerability in the TrueConf client, tracked as CVE-2026-3502 with a CVSS score of 7.8…
Read original ↗https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targetscheckpoint_research · tlp:amber · 3/30/2026, 1:09:01 PM
ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime Key Takeaways What Happened AI assistants now handle some of the most sensitive data people own. Users discuss symptoms and medical history. They ask questions about taxes, debts, and personal finances, upload PDFs, contracts, lab results, and identity-rich documents that contain names, addresses, account details, and private records. That trust depends on a simple expectation: […] The pos…
Read original ↗https://research.checkpoint.com/2026/chatgpt-data-leakage-via-a-hidden-outbound-channel-in-the-code-execution-runtimecheckpoint_research · tlp:amber · 3/30/2026, 12:53:08 PM
30th March – Threat Intelligence Report For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Iranian state-affiliated threat group Handala Hack has breached FBI director’s Patel’s personal Gmail account and leaked many personal photos and documents. This follows the FBI’s seizure of domains related to Handala Hack’s […] The post 30th March – Threat Intelligence Report appeare…
Read original ↗https://research.checkpoint.com/2026/30th-march-threat-intelligence-reportcheckpoint_research · tlp:amber · 3/29/2026, 10:08:45 AM
AI Threat Landscape Digest January-February 2026 KEY FINDINGS AI-assisted malware development has reached operational maturity.VoidLink framework, which is modular, professionally engineered, and fully functional, was built by a single developer using a commercial AI-powered IDE within a compressed timeframe. AI-assisted development is no longer experimental but produces deployment ready output. AI-assisted development is not always obvious from the final product.VoidLink wa…
Read original ↗https://research.checkpoint.com/2026/ai-threat-landscape-digest-january-february-2026checkpoint_research · tlp:amber · 3/23/2026, 1:38:09 PM
23rd March – Threat Intelligence Report For the latest discoveries in cyber research for the week of 23rd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Navia Benefit Solutions, a United States-based employee benefits administrator, has disclosed a breach affecting more than 2.6 million individuals after unauthorized access and potential data exfiltration occurred between December 22, 2025 and […] The post 23rd March – Threat Intellig…
Read original ↗https://research.checkpoint.com/2026/23rd-march-threat-intelligence-reportcheckpoint_research · tlp:amber · 3/16/2026, 3:09:00 PM
16th March – Threat Intelligence Report For the latest discoveries in cyber research for the week of 16th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES United States-based medical technology company Stryker has suffered a cyberattack that caused a global disruption to its environment. The company said its surgical robotics, clinical communications platform, and life support monitors are […] The post 16th March – Threat Intelligence R…
Read original ↗https://research.checkpoint.com/2026/16th-march-threat-intelligence-reportcheckpoint_research · tlp:amber · 3/12/2026, 5:21:23 PM
“Handala Hack” – Unveiling Group’s Modus Operandi Key Findings Introduction Handala Hack, also tracked by Check Point Research as Void Manticore, is an Iranian threat actor that is known for multiple destructive wiping attacks combined with “hack and leak” operations. The threat actor operates several online personas, with the most prominent among them being Homeland Justice, maintained from mid-2022 specifically for multiple attacks […] The post “Handala Hack” &#…
Read original ↗https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandicheckpoint_research · tlp:amber · 3/10/2026, 4:54:53 PM
Iranian MOIS Actors & the Cyber Crime Connection Key Points Iran-linked actors are increasingly engaging with the cyber crime ecosystem. Their activity suggests a growing reliance on criminal tools, services, and operational models in support of state objectives. Iranian actors have long used cyber crime and hacktivism as cover for destructive activity, but the trend now suggests direct engagement with the criminal ecosystem. […] The post Iranian MOIS Actors & the …
Read original ↗https://research.checkpoint.com/2026/iranian-mois-actors-the-cyber-crime-connection