
Iran-backed actors scanned Check Point gateways as pre-attack reconnaissance in July 2024
Iran-based cyber actors conducted systematic IP-range scans of Check Point Security Gateways in July 2024, according to CISA advisory published August 2024. The reconnaissance activity, a standard precursor to exploitation, targeted devices reachable on management and VPN ports. Organizations running unpatched versions or exposing gateway interfaces to public internet face elevated risk. Nation-state scanning campaigns of this precision do not persist indefinitely; defenders should assume activity continues beyond disclosure.
Published