No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security
From the source: Check Point Software BlogIn this article Nineteen Check Point AI Security R&D teams spent two days on one prompt: build the demo customers would ask to see twice. Three of the results tell a single story about securing AI agents, and none of it starts with an attacker. →an autonomous agent took dangerous actions with no attacker involved, it simply hit a wall and improvised →a single poisoned file in a code repository…
Read the full story on Check Point Software BlogHave you worked with this?
The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.
More from Check Point Software
Recent updates from Check Point Software, so you can tell whether this is a one-off or part of a pattern.
Goals Are Not Enough: Securing AI Agents with NVIDIA OpenShell
In this article An agent’s goal rarely says how the agent may reach it, and capable agents are good at finding routes nobody planned for. →NVIDIA Open Agent Safety Platform puts the boundary in the infrastructure, outside the agent’s reach →Check Point semantic monitoring judges whether each step still fits the task →the two already work together in a beta integration with NVIDIA OpenShell →the…
Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right
Cyber Asset Attack Surface Management (CAASM) solved a significant problem. Security teams can now say with confidence what they own. But, two things separate a CAASM tool that stops there from one that actually moves the needle on risk. The first is what the inventory itself carries. The second is what it connects to. 1. An inventory needs to do more than list what exists A list of assets is…
A Decision Model Breaks Like Any Other Language Model: A First Look at Jev
A new kind of AI model returns decisions instead of text. We spent a day trying to change its mind. It cost about 50 cents. In this article Jev is a new kind of AI model that returns typed decisions instead of text, built for software to call rather than for people to read. We put it inside a realistic application and tried to change its verdict from the outside. →every configuration we tested…
More in Security
What other companies in Security are doing. The category page shows who’s active, side by side.
Threat Actors Use Google Ads To Target Ledger Users
In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…
The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches
A routine package install can open the door to a cloud breach. Learn how attackers exploit developer credentials. Discover practical steps to contain exposure and protect your cloud environment.
Next.js applications, powered by Vite: introducing Vinext 1.0
Vinext 1.0 graduates from an AI experiment to a production-ready framework, letting developers run Next.js apps on Vite. This release brings advanced cache warming, broader compatibility, and an automated testing pipeline.
Introducing cf: the agentic CLI for the entire Cloudflare API
We are releasing cf, our new command-line tool that mirrors the entire Cloudflare API and supports programmatic TypeScript configuration. We are also open-sourcing Forge, our internal SDK generator.

