- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Q&A and slides below the video.
Released on 29 December 2025 via https://support.checkpoint.com/results/sk/sk183506
PPAK (a.k.a. Performance Pack) is another name for SecureXL. Historically, this has run in kernel mode (KPPAK), though we started implementing this in userspace (UPPAK). In R82.10, UPPAK will be the only mode supported. All features not supported in UPPAK on earlier releases are expected to be supported in R82.10.
This issue should be addressed in R82 JHF and is expected to be in R82.10.
Separate installers, yes, however the underlying code is exactly the same.
There are very few FP in Zero Phishing, mainly because it’s not only uses reputation feeds to determine website’s maliciousness, but doing live rendering and emulation of the website as well, in addition to using Check Point’s multiple URLX prevention engines.
Zero Phishing blade works in the gateway for website browsing.
email anti phishing is done in HEC (Harmony Email and Collaboration)
We take additional steps to verify the SNI, as described in sk163594.
SNI is still widely used. That said, we're are working on other methods that will not even need SNI.
We use multiple ways to fingerprint an application. SNI, DNS, known IPs, caching and many more. When we introduced SD-WAN we enahced application detection to be on the first SYN packet.
Yes, under R82 Admin guide, there is a section for “Getting Started with HTTPS Inspection”
https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Cont...
See also our Deep Dive session on HTTPS Inspection: https://community.checkpoint.com/t5/CheckMates-Events/Americas-Deep-Dive-HTTPS-Inspection-Best-Pract...
We are exploring multiple ways to detect malicious traffic without decrypting the content.
To activate it does require infinity services, however the day to day operation is via SmartConsole.
HTTPS Categorization uses the URL Filtering database, which is less threat focused. Anti-Phising using ThreatCloud AI as the backend.
ERM recommendations will appear in Threat Prevention Insights. Admins can chose to accept the recommendation. It will not be applied automatically.
Yes, VSnext and ElasticXL are supported on 3900 models with this release.
As of now, Threat Prevention Insight is relevant for the traditional TP configuration, not for autonomous.
Threat Prevention Insight will work with MGMT on R82.10 and on all GW releases (that can be mangaed byR82.10 MGMT), there are some insights that are version depdent but most are relevant for all.
Yes, that is correct
The firewall is aware of the ERM scans and communicates back to the ERM system. We added special tagging to identify which firewall was the one protecting the asset that was scanned
Yes
Two main options, part of TP Insight or a dedicated dashboard created for Adaptive IPS.
Adaptive IPS is per signature and also considers the actual traffic and policy. The bypass under load is more blunt -- it disables IPS all together on any signature.
Yes, it requires HTTPS Inspection.
We are able to inspect Web Socket Secure with Gen AI Protect.
It will work with applications as well.
AI tools used via MCP are now being presented. We are adding visibility and control in R82.10
Yes, we plan to support desktop applications as well?
Not for the Browser plug-in, but for GenAI protect on the gateway.
Yes, we plan to have the same visibility when using GenAI Protect in Quantum as well.
If you are refering to GenAI Protect, yes it is via usercheck.
ISPR and SD-WAN ultimately do the same thing (steer traffic) and are not designed to operate together.
You can change PDP only
|
Topic |
Notes |
|
GenAI Protect for Quantum & CloudGuard Network |
JHF in 2026 (Sign up / Questions via EA alias) |
|
Infinity Identity |
Requires ‘Premium’ Package Security Management License |
|
Threat Prevention Insights |
Requires ‘Complete’ Package Security Management License |
|
Phishing Protection without HTTPS Inspection |
Requires SandBlast license (SNBT/NGTX software package) |
|
Unified Internet Access Policy for SASE & Firewalls |
Currently in EA |
Excellent session.
By the way, pdf file you attached also shows virus scan in progress, cant open it : - (
This is a problem with all newly uploaded attachments on the community at current...should be fixed soon.
I thought it was me the other day, but then I saw others having same issue.
woohoo, looks like all fixed now!
Great session, lots of enthusiasm and energy. @PhoneBoy keeps looking younger at each webinar. 😉
Amazing webinar, lots of super useful info!
I've always been young at heart. 😜
Truth be told, thats what MATTERS 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 8 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Tue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY