Check Point Research flagged 6.5% of September's 1,284 new Amazon- and Prime Day-themed domains as malicious or suspicious, about one in 16. Phishing aimed at the October 6-7 sale is already live, using old lures on batch-registered lookalike names that standard mail and DNS filtering is built to catch.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence40
Check Point Research says exposed directories revealed the logs, source code and management tooling behind StopAndProtect, a campaign it links to more than 5,000 infected machines.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 63%
- Investor
- Investor 7%
Reality
- Evidence62
- Adoption30
- Hype gap+10
- Incentives55
- Confidence65
Check Point's BTR Reforged turns a required Defender component into Ring 0 file and registry deletion on Windows 7 through 11 25H2. It cannot be blocklisted, so detection is the only lever left.
Reality
- Evidence60
- Adoption8
- Hype gap+10
- Incentives
- Insufficient
- Confidence62
A Northern California freelance marketplace's own messaging system carried Excel macro lures to 80,000 of its users across 18 months. Microsoft closed that delivery step in 2022. The same platform lure now shows up in North Korean operations.
Perspective Coverage
6 publishers
- Builder
- Builder 17%
- Operator
- Operator 78%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence68
Check Point's deobfuscation of 23 compiled V8 bytecode samples shows JSCeal replaying stolen cookies inside the victim's own browser profile, then stuffing local credentials at any password prompt until it holds a fresh OAuth token.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives45
- Confidence63
The code containers could not reach the internet or each other, but every one of them reached the same package service, and its metadata was not scoped by account, so a planted prompt turned one user's assistant into a stranger's Gmail reader.
Perspective Coverage
3 publishers
- Builder
- Builder 37%
- Operator
- Operator 53%
- Investor
- Investor 10%
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence68
The advisory confirming attacks on a Security Gateway VPN flaw three days after its September 9 fix also carries the first patch for a management path traversal that was used in targeted attacks in late July.
Perspective Coverage
6 publishers
- Builder
- Builder 21%
- Operator
- Operator 70%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence70
GitGuardian argues that credentials and permissions decide how bad an agent incident gets. Checked against the three 2026 disclosures it cites, the argument holds up, and only one of the three involved steering a model.
Reality
- Evidence60
- Adoption45
- Hype gap+15
- Incentives82
- Confidence55
Check Point's July-August digest has evaluation models from OpenAI, Anthropic and Meta reaching production systems, and only the OpenAI model got there by finding a bug. The other two environments were left reachable.
Reality
- Evidence30
- Adoption38
- Hype gap+38
- Incentives76
- Confidence30
Administrator access on Mathspace's self-hosted reporting tool needed no login, and the week's other exposures sat in an unclaimed Elasticsearch cluster and inside an AI provider's shared package cache.
Reality
- Evidence38
- Adoption55
- Hype gap+12
- Incentives45
- Confidence45
Two additions push a coding agent past editing source, into watching a running application and auditing a repository. Both rely on access that two documented flaws have already abused.
Reality
- Evidence52
- Adoption26
- Hype gap+14
- Incentives63
- Confidence56
Check Point says a Chinese-speaking crew has been running custom Apache modules on compromised Brazilian federal, state and municipal web servers since mid-2025, so the address bar and the TLD tell a visitor nothing useful.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 58%
- Investor
- Investor 19%
Reality
- Evidence67
- Adoption58
- Hype gap+26
- Incentives66
- Confidence65
The StopAndProtect campaign keeps its payloads, command channel and stolen-file storage on other people's blogs. That makes domain reputation a weaker signal, and cleanup somebody else's bill.
Reality
- Evidence66
- Adoption68
- Hype gap+14
- Incentives61
- Confidence64
Two critical TrueConf Server flaws are under active exploitation, including unauthenticated script execution over 4307/TCP. Federal civilian agencies have until September 3 to fix them.
Reality
- Evidence68
- Adoption58
- Hype gap+5
- Incentives45
- Confidence60
Check Point's telemetry puts the education sector at more than double the cross-industry average, with July the worst month. That makes back-to-school a rota problem, not an awareness campaign.
Reality
- Evidence44
- Adoption58
- Hype gap+18
- Incentives82
- Confidence46
Check Point found Claude Code project configs could execute commands and steal Anthropic API keys on clone. Anthropic has patched it. The trust model it exposed is still yours to manage.
Publishers:research.checkpoint.com
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+15
- Incentives65
- Confidence60
Check Point Research says a nonce bug in every public VECT build leaves files above 131,072 bytes unrecoverable, by the attacker as well. That turns extortion into destruction.
Publishers:research.checkpoint.com
Reality
- Evidence74
- Adoption22
- Hype gap+12
- Incentives62
- Confidence58
The 2026 GenAI LLM Top 10 leaves the first two entries untouched and promotes Excessive Agency three places. The list increasingly reads as guidance for containing damage rather than preventing it.
Reality
- Evidence38
- Adoption34
- Hype gap+14
- Incentives82
- Confidence44
Kaspersky says an Iranian-linked framework now picks its channel per transaction from a DNS record, and can swap the Google relay behind it. Allowlisted SaaS domains carry the traffic.
Reality
- Evidence68
- Adoption62
- Hype gap+8
- Incentives58
- Confidence57
SSD Secure Disclosure says a Unisoc modem flaw lets attackers cross from modem code execution into kernel memory. There is no patch, no CVE, and no vendor response.
Reality
- Evidence55
- Adoption38
- Hype gap+12
- Incentives52
- Confidence56