<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point ThreatCloud flags whole cloudfront.net as phishing in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271776#M45541</link>
    <description>&lt;P&gt;That was an AV signature, which only exists in ThreatCloud (not in downloaded signatures).&lt;BR /&gt;Given I saw no other reports of this internally, I have to assume this was caught and addressed quickly.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Feb 2026 20:26:38 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2026-02-23T20:26:38Z</dc:date>
    <item>
      <title>Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271664#M45533</link>
      <description>&lt;P&gt;False positives can happen and do happen from time to time. Normally I would not create a CheckMates post for that.&lt;/P&gt;
&lt;P&gt;But today, we got a quite big problem:&lt;/P&gt;
&lt;P&gt;The original&amp;nbsp;Check Point ThreatCloud feeds flagged the the whole&amp;nbsp;cloudfront.net domain (not just specific sub domains) as phishing with confidence level set to high.&lt;/P&gt;
&lt;P&gt;This results in huge problems:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Our DNS recursive resolvers were not able to resolve a quite large part of the internet anymore, because cloudfront is that common these days (in CNAMEs).&lt;/LI&gt;
&lt;LI&gt;Even more problematic was the the problem, that our gateways could not reach the Check Point TP feed URLs anymore, because even Check Point uses Cloudfront for that. That means the problem does not correct itself by just waiting until Check Point or its supplier fixes this false positive.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We added TP exceptions, did TP policy install and everthing starts to recover.&lt;/P&gt;
&lt;P&gt;We will now wait until CP delivers fixed feeds before removing our exception again.&lt;/P&gt;
&lt;P&gt;Please see screenshot. The Action=detect was after we added the exception:&lt;/P&gt;
&lt;DIV id="tinyMceEditorTobias_Moritz_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-02-23 112639.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33450i57B6198411232B82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2026-02-23 112639.png" alt="Screenshot 2026-02-23 112639.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-02-23 113042.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33452i32921BCDCA88F3D8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2026-02-23 113042.png" alt="Screenshot 2026-02-23 113042.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;The problem started first in our logs at 23.02.2026 08:00 UTC and is still occuring about two hours later (covered by our exception).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2026 10:37:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271664#M45533</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2026-02-23T10:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271776#M45541</link>
      <description>&lt;P&gt;That was an AV signature, which only exists in ThreatCloud (not in downloaded signatures).&lt;BR /&gt;Given I saw no other reports of this internally, I have to assume this was caught and addressed quickly.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2026 20:26:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271776#M45541</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-02-23T20:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271807#M45543</link>
      <description>&lt;P&gt;Thanks for that clarification, Dameon. So I was wrong about the "won't fix itself", because the broken signature download had no side effect to the correction of the wrong classification.&lt;/P&gt;
&lt;P&gt;However,&amp;nbsp;23.02.2026 08:22 UTC (first log entry) and&amp;nbsp;23.02.2026 12:48 UTC (last log entry) means aprox. 4,5 hours of blocking of one of the top 1000 domains, at least for customers who use ThreatCloud for DNS filtering.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 06:56:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271807#M45543</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2026-02-24T06:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271829#M45544</link>
      <description>&lt;P&gt;Unfortunalty, the problem is back. Today, starting 24.02.2026 09:16 UTC, Check Point Thread Cloud is again classifying cloudfront.net as phishing. It still is, while I'm writing this.&lt;/P&gt;
&lt;P&gt;What's going? Such a major false-positive two days in a row?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 11:39:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271829#M45544</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2026-02-24T11:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271831#M45545</link>
      <description>&lt;P&gt;We don't see this. Do you have IoC configured?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 11:58:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271831#M45545</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-02-24T11:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271841#M45546</link>
      <description>&lt;P&gt;We have indicators (custom IOC feeds) configured, but as you see in the screenshot in my first post, the vendor list is "Check Point ThreatCloud". When we have matches within our custom IOC feeds, we see the reference to that feed in the log card. But this one seems to be native from Check Point. The matching protection name today is the same like yesterday in my screenshot: "Phishing.TC.d16ePthE"&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 13:36:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271841#M45546</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2026-02-24T13:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271850#M45547</link>
      <description>&lt;DIV class=""&gt;I’m seeing the same behavior on my end. I had to add an exception because even the CP community wasn’t accessible.&lt;/DIV&gt;</description>
      <pubDate>Tue, 24 Feb 2026 14:07:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271850#M45547</guid>
      <dc:creator>mp2012</dc:creator>
      <dc:date>2026-02-24T14:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271887#M45552</link>
      <description>&lt;P&gt;I have not seen any other reports of this issue, including in TAC cases.&amp;nbsp;&lt;BR /&gt;I would get the TAC involved at this point.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Feb 2026 00:04:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/271887#M45552</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-02-25T00:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/272552#M45691</link>
      <description>&lt;P&gt;Can confirm I also have a customer facing the same problems!&lt;BR /&gt;Like you said, major dns domains accross the internet are beeing blocked since a few days!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 10:24:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/272552#M45691</guid>
      <dc:creator>Fabian1307</dc:creator>
      <dc:date>2026-03-05T10:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/272670#M45713</link>
      <description>&lt;P&gt;As Dameon suggest, I opened a TAC case and currently, it looks like a bug:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;cloudfront.net&amp;nbsp;is clean in ThreatCloud, and URL Filtering currently categorizes it as&amp;nbsp;&lt;STRONG&gt;Computers / Internet&lt;/STRONG&gt;&amp;nbsp;with&amp;nbsp;&lt;STRONG&gt;Low Risk&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;The detection seen in the screenshot is tied to a&amp;nbsp;&lt;STRONG&gt;specific CloudFront subdomain&lt;/STRONG&gt;:&amp;nbsp;d2zvg5qlc6mxlr[.]cloudfront[.]net, which triggered&amp;nbsp;&lt;STRONG&gt;Phishing.TC.d16ePthE&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;When you take a look at the screenshots, you see that it blocks cloudfront.net and not d2zvg5qlc6mxlr[.]cloudfront[.]net. This should not happen.&amp;nbsp;This blocking occurs, when our recursive DNS server tries to resolve for example &lt;A href="http://www.checkpoint.com" target="_blank"&gt;www.checkpoint.com&lt;/A&gt; over the root chain, because this a CNAME to d4epvaz4tpdrm.cloudfront.net and we have DNS-Sec enabled so our resolver asks for type=DS Name=cloudfront.net. This DS-Request for cloudfront.net is blocked by the protection Phishing.TC.d16ePthE.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;From the PCAP, we can confirm that the traffic shown is a standard DNSSEC validation step: a DS query for cloudfront.net sent from the recursive resolver to a .net TLD server, with a normal DNSSEC response (NSEC3/RRSIG) returned. In the corresponding log overview (matching minutes/seconds), the Anti-Virus blade shows a Prevent action for a DNS query to cloudfront.net, triggered by protection Phishing.TC.d16ePthE.&lt;BR /&gt;Based on the behavior observed, this appears to be a technical issue related to how the Anti-Virus blade applies the reputation decision during DNS resolution (specifically at the DNSSEC/DS validation stage), resulting in the block being enforced at the cloudfront.net level rather than only at the specific malicious subdomain.&lt;BR /&gt;For further investigation, this is now escalated to RnD&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;So lets see, what RnD says. If I get a resolution for this problem, I will share it here with you folks.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2026 09:47:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/272670#M45713</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2026-03-06T09:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/272735#M45722</link>
      <description>&lt;P&gt;Thanks for the details on this and definitely keep us posted!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2026 18:12:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/272735#M45722</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-03-06T18:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/272815#M45725</link>
      <description>&lt;P&gt;Checkpoint TAC reported the same to me.&lt;/P&gt;&lt;P&gt;Looks like we need to wait until RnD is done.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2026 07:10:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/272815#M45725</guid>
      <dc:creator>Fabian1307</dc:creator>
      <dc:date>2026-03-09T07:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ThreatCloud flags whole cloudfront.net as phishing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/273873#M45858</link>
      <description>&lt;P&gt;Any updates from your side?&lt;BR /&gt;We are asked to provide a lot of data which may lead to downtime. By that it is not possible for us to provide..&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 08:39:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-ThreatCloud-flags-whole-cloudfront-net-as-phishing/m-p/273873#M45858</guid>
      <dc:creator>Fabian1307</dc:creator>
      <dc:date>2026-03-20T08:39:57Z</dc:date>
    </item>
  </channel>
</rss>

