Skip to content

company

Check Point Research

Check Point Research is the threat-intelligence division of Check Point Software Technologies, tracking malware, phishing, and vulnerabilities.

Known aliases

  • Check Point
  • Check Point Software Technologies
  • CPR

Relationships

No evidence-backed relationships are recorded.

Current stories

security1 publisher

Check Point flags one in 16 new Amazon-themed domains as malicious or suspicious before Prime Day

Check Point Research flagged 6.5% of September's 1,284 new Amazon- and Prime Day-themed domains as malicious or suspicious, about one in 16. Phishing aimed at the October 6-7 sale is already live, using old lures on batch-registered lookalike names that standard mail and DNS filtering is built to catch.

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives70
Confidence40
security6 publishers

DOJ extradites a Russian accused of pushing macro malware through 255 fake marketplace accounts

A Northern California freelance marketplace's own messaging system carried Excel macro lures to 80,000 of its users across 18 months. Microsoft closed that delivery step in 2022. The same platform lure now shows up in North Korean operations.

Perspective Coverage

6 publishers
Builder
Builder 17%
Operator
Operator 78%
Investor
Investor 5%

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence68
security3 publishers

Check Point passed a task between two ChatGPT accounts through OpenAI's internal package service

The code containers could not reach the internet or each other, but every one of them reached the same package service, and its metadata was not scoped by account, so a planted prompt turned one user's assistant into a stranger's Gmail reader.

Perspective Coverage

3 publishers
Builder
Builder 37%
Operator
Operator 53%
Investor
Investor 10%

Reality

Evidence64
Adoption
Insufficient
Hype gap+15
Incentives55
Confidence68
security6 publishers

Check Point patches a Security Management zero-day it saw exploited on July 23

The advisory confirming attacks on a Security Gateway VPN flaw three days after its September 9 fix also carries the first patch for a management path traversal that was used in targeted attacks in late July.

Perspective Coverage

6 publishers
Builder
Builder 21%
Operator
Operator 70%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives60
Confidence70
build1 publisher

The credential an agent inherits sets the ceiling on the damage

GitGuardian argues that credentials and permissions decide how bad an agent incident gets. Checked against the three 2026 disclosures it cites, the argument holds up, and only one of the three involved steering a model.

Publishers:dev.to

Reality

Evidence60
Adoption45
Hype gap+15
Incentives82
Confidence55
security3 publishers

Gambling Goblin turns .gov.br servers into invisible reverse proxies for app-store phishing

Check Point says a Chinese-speaking crew has been running custom Apache modules on compromised Brazilian federal, state and municipal web servers since mid-2025, so the address bar and the TLD tell a visitor nothing useful.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 58%
Investor
Investor 19%

Reality

Evidence67
Adoption58
Hype gap+26
Incentives66
Confidence65

Earlier coverage

  1. One console, two businesses: Broadcom says Jewelbug runs espionage and crypto fraud together

    Security · August 14, 2026 · 1 publisher

  2. A 160MB Attacker Workspace Is the First Real Parts List for Autonomous Intrusion

    Build · August 14, 2026 · 1 publisher