#Ciberseguridad #ElSalto En este artículo se habla de que las administraciones públicas del País Vasco tienen contratadas herramientas de ciberseguridad con las firmas israelíes #Checkpoint y #CyberArk. De hecho, no solamente contratan a estas dos empresas en Euskadi, también en organizaciones públicas muy "centrales" en Madrid.
https://www.elsaltodiario.com/genocidio/administraciones-vascas-gastan-332-533-euros-software-israeli-inicio-del-genocidio-gaza
La administración vasca gasta 335.533 euros en software israelí desde el inicio del genocidio en Gaza

Trece contratos públicos adjudicados por el Gobierno Vasco, IZFE, ITELAZPI, EITB, NEIKER y los ayuntamientos de Bilbao y Getxo hacia servicios en ciberseguridad de Check Point, CyberArk y una sociedad agritech israelí desde 7 de octubre de 2023. El grueso del gasto se ejecuta a través de integradores como Thales S21Sec.

El Salto Diario

From Check Point Research: Nimbus Manticore Targets the US

#CheckPoint Research has revealed new campaigns of #Nimbus #Manticore, an IRGC-linked group that resurfaced during Operation #EpicFury with upgraded techniques. The campaigns use SEO poisoning and career-themed phishing across the United States, Europe, and the Middle East, and then delivered a new #MiniFast #backdoor.

https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/

Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research

Key Findings Introduction During the recent geopolitical tensions in the Middle East, we reported on multiple Iran-nexus threat actors advancing Iran’s strategic objectives through cyber operations. These activities included targeting internet-connected cameras, conducting destructive attacks against US and Israeli entities, and exfiltrating data from cloud environments to support broader kinetic and intelligence-gathering efforts. Nimbus Manticore (also tracked as UNC1549) is an IRGC-affiliated threat […]

Check Point Research

From Check Mates: Bridge the CAASM Gap with Exposure Management

#CAASM is no longer a standalone tool. For #CheckPoint, it's a unified layer of Exposure Management, feeding asset, ownership, and control context into the platform that drives prioritization and safe remediation. We'll walk through what that means in practice for the way you run discovery, prioritization, and remediation workflows.

Join us on June 3 at 5 PM CET | 11 AM EST.

Register here: https://checkpoint.zoom.us/webinar/register/3017794861244/WN_EKY8ZilXQ_GKuUsW1PB_MQ#/registration

Welcome! You are invited to join a webinar: Bridge the CAASM Gap with Exposure Management. After registering, you will receive a confirmation email about joining the webinar.

CAASM is no longer a standalone tool. For Check Point, it's a unified layer of Exposure Management, feeding asset, ownership, and control context into the platform that drives prioritization and safe remediation. We'll walk through what that means in practice for the way you run discovery, prioritization, and remediation workflows. What we'll cover: - How CAASM-based discovery surfaces assets, CVEs, and unauthorized software that scanners miss - Building a real-time asset inventory from the security, IT, and cloud tools you already run - How unified asset, owner, and control context sharpens prioritization and feeds safe remediation

Zoom

For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin from #CheckPoint Research.

https://research.checkpoint.com/2026/18th-may-threat-intelligence-report/

18th May – Threat Intelligence Report - Check Point Research

For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to GitHub files through compromised third-party development software, while stating that […]

Check Point Research

From #CheckPoint Research: World Cup 2026 Attacks

Check Point Research have quantified a #WorldCup 2026-driven surge in cyber activity, with weekly attacks per organization rising in Mexico, Canada, and the United States in April, across the media, hospitality, transportation and travel sectors. #FIFA-themed domains reached 9,741 in April, and by early May, one in 41 were malicious.

https://blog.checkpoint.com/research/before-the-first-whistle-how-cyber-criminals-are-targeting-world-cup-2026/

Before the First Whistle: How Cyber Criminals Are Targeting World Cup 2026 - Check Point Blog World Cup 2026 Scams Surge: Fake FIFA Sites, Phishing & Cyber Threats Exposed

The FIFA World Cup 2026 is one of the most anticipated sporting events in history, and cyber criminals are already capitalizing on excitement. As matches Cyber criminals are targeting FIFA World Cup 2026 with fake stores, betting scams, and phishing campaigns. New data reveals rising attacks across the US, Canada, and Mexico—here’s how to stay safe.

Check Point Blog

From #CheckPoint Research: Behind the Scenes of The Gentlemen

Check Point Research has analyzed an internal leak from The Gentlemen #ransomware operation, exposing chats, infrastructure details, affiliate roles, and ransom negotiations. The report links the zeta88 account to the administrator, maps 8 affiliate TOX IDs, and details the use of #Fortinet and #Cisco vulnerabilities as well as NTLM relay and OWA/M365 for initial access in attacks.

https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/

Thus Spoke…The Gentlemen - Check Point Research

Key Points Introduction The Gentlemen ransomware‑as‑a‑service (RaaS) operation is a relatively new group that emerged around mid‑2025. Its operators advertise the service across multiple underground forums, promoting their ransomware platform and inviting penetration testers and other technically skilled actors to join as affiliates. In 2026, based on victims listed on the data leak site (DLS), […]

Check Point Research

From #CheckPoint blog:

The Network Security Problem No One Could Solve – Until Now.

Networks used to be simple. A perimeter. A data center. A set of rules a single engineer could hold in their head. That world is long gone.

https://blog.checkpoint.com/security/the-network-security-problem-no-one-could-solve-until-now/

From #CheckPoint Research: The State of Ransomware - Q1

Check Point Research has summarized Q1 2026 #ransomware trends, recording 2,122 leak-site victims, which is the second-highest Q1 on record, and renewed consolidation. The top 10 groups were responsible for 71% of victims. Qilin led with 338 victims, The Gentlemen rose to third, and LockBit 5.0 returned with 163 victims.

https://blog.checkpoint.com/research/q1-2026-ransomware-report-fewer-groups-higher-impact/

Q1 2026 Ransomware Report: Fewer Groups, Higher Impact

Check Point Blog

Please read this important update from #CheckPoint:

Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)

https://support.checkpoint.com/results/sk/sk184928

#copyfail #dirtyfrag #fragnesia

sk184928 - Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)

Applies to: Security Gateways, Security Management