Entry Thumbnail

Antide’s Law

A friend of mine, namely Antide “xarkes” Petit, came up with a pretty good rule of thumb that I think should be elevated into a law, Antide’s Law: > If it’s unclear what a cyber-security company is doing, what they’re doing is pretty clear. For example, take a look at […]

Posted by
Entry Thumbnail

Amaranth-Dragon: Weaponizing CVE-2025-8088 for Targeted Espionage in the Southeast Asia

**Check Point Research** has identified several campaigns targeting multiple countries in the **Southeast Asian region**. These related activities have been collectively categorized under the codename “ **Amaranth-Dragon**”. The campaigns demonstrate a clear focus on **government entities** across the region, suggesting a motivated threat actor with a strong interest in **geopolitical […]

Posted by
Entry Thumbnail

How Mercari strengthened mobile security for millions of users with Oversecured

# How Mercari strengthened mobile security for millions of users with Oversecured # CUSTOMER SUCCESS STORY ## How Mercari strengthened mobile security for millions of users with Oversecured ### Case Study Summary **Company:** Mercari – Japan’s largest marketplace app **Industry:** E-commerce, FinTech, Mobile Marketplace **Challenge:** Securing mobile applications handling cryptocurrency, […]

Posted by
Entry Thumbnail

Beyond ACLs: Mapping Windows Privilege Escalation Paths with BloodHound

# Beyond ACLs: Mapping Windows Privilege Escalation Paths with BloodHound Windows privileges are special rights that grant processes the ability to perform sensitive operations. Some privileges allow bypassing standard Access Control List (ACL) checks, which can lead to significant security implications. While privileges like SeDebugPrivilege, SeImpersonatePrivilege or SeBackupPrivilege are frequently […]

Posted by
Entry Thumbnail

Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)

# Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 – pre-auth Remote Command Execution vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) solution – we sighed with relief. Clearly, the universe had decided […]

Posted by
Entry Thumbnail

Cyber Security Report 2026

Check Point Research continuously investigates real-world attacks, vulnerabilities, attackers’ infrastructure, and emerging techniques across global networks and environments. The Cyber Security Report 2026 consolidates our research efforts throughout 2025 to deliver a clear, data-driven view of the current threat landscape and its trajectory in 2026. As Check Point’s flagship annual […]

Posted by