Fighting cyber threats one research at a time. News from Check Point’s (@checkpointSW) Research team.

The Internet
Can you detect adversarial prompts with just a quick LLM and an eye for Base64, Morse code, and similar artifacts? We show the answer is no: some plain English prompts mean one thing to a quick LLM and a completely different thing to a high-reasoning model. research.checkpoint.com/2026…
1
13
43
9,186
⚒️ BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive ⚠ Trusted Remediation Primitives with Undocumented Internals. 🔓 15+ years. Unchanged. Unblockable. 🤔 What if an attacker learned its language? We did. 👇 research.checkpoint.com/2026…
3
25
58
26,072
#StopAndProtect blends ransomware, data theft and hands-on keyboard control. 🥷OPSEC failures reveals logs from over 6,000 victim IPs 📰Thousands of hacked WordPress websites used to lure victims and host operation infrastructure 📱 Custom stealer uses WhatsApp web and desktop to search & exfiltrate results Read more 👇: research.checkpoint.com/2026…
1
16
28
5,919
0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : research.checkpoint.com/2026…
2
83
310
36,214
FrostFalak, a Yemen-based threat actor targeting Israeli OT networks, uses Israeli VPN exit nodes and compromised network appliances to conceal its activity while targeting construction, transportation and building management organizations.
2
5
16
5,835
OPSEC failure revealed the attacker's IP : 176[.]123.22.88 (Yemen[.]net, YE)
1
3
3,230
Good Luck @vinopaljiri , We're proud of you!
I'm super excited to be speaking at Black Hat USA 2026, delivering my research "BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive" 🤗💪 Big thanks @_CPResearch_ & @BlackHatEvents! 💯 Join me: app.ingo.me/q/ktqyt #BHUSA #cybersecurity
12
6,711
🇮🇷 Cavern Manticore: Exposing Iran-Linked Modular C2 Framework CP<r> reveals: 🎯 Israeli Gov & IT sector targeted 🧩 Novel modular "Cavern" C2 framework, 3 .NET formats 🕵️ Iran-nexus; MOIS ties to MuddyWater & Lyceum 👻 Most samples: zero VT hits research.checkpoint.com/2026…
2
14
55
17,842
🚪 Foothold via abused RMM tools already deployed 🧬 Dissection traces evolution "Cav3rn" (non-modular) ➡️ modular "Cavern" 🛠️ New IDA plugin & how-to for NativeAOT malware 🤬 Full code structure + cursing errors & typos: a human, not an AI bot
1
5
4,400
Lookalike Ghidra, dnSpy, and other download sites turned trusted clicks into TDS redirects. CPR found click hijacking, gated routing, and multiple malware families downstream — including an evasive, previously undocumented framework we call SessionGate. research.checkpoint.com/2026……
1
24
42
10,081