Rapid7

@rapid7.com

Rapid7 is a leader in AI-powered managed cybersecurity operations, trusted to advance organizations’ cyber resilience. Unified exposure and detection enable 11,500+ customers to reduce risk and disrupt attackers. 🔗: rapid7.com

Rapid7 researchers have identified a sophisticated malware campaign attributed to the threat actor #DroppingElephant, characterized by the use of a China-themed decoy document to deliver a heavily reworked, in-memory RAT. Technical analysis, IoCs & more: r-7.co/4va2vSF

BildBildBild

🚨 On 6/10/26, #Oracle published a security alert for CVE-2026-35273, a critical vuln. affecting PeopleSoft Enterprise PeopleTools. The campaign has been attributed to the ShinyHunters collective, well known for data theft and extortion. More in our blog: r-7.co/4aEClz9

AI is actively embedding itself into today's criminal tradecraft – lending itself to social engineering, fraud, impersonation, identity abuse & more. Get to know tools like WormGPT and BruteforceAI, plus, how orgs should react, all in a new blog: r-7.co/4ooQFS7

BildBild

🚨 On June 9, 2026, #Ivanti published a security advisory for 2 critical vulnerabilities affecting Ivanti Sentry (FKA MobileIron Sentry). CVE-2026-10520 (CVSS 10.0) is an OS command injection vuln, and CVE-2026-10523 (CVSS 9.9) is an authentication bypass vuln. Read on: r-7.co/4arpQHd

🚨 On 6/8/26, #CheckPoint published a security advisory for a critical vuln. affecting its Remote Access VPN, Mobile Access, and Spark Firewall products. CVE-2026-50751 allows an unauth. attacker to establish a VPN session without providing valid credentials. More: r-7.co/4fyoJJc

🌐 Announcing Rapid7's Threat Landscape Report for Q1, 2026. Threat actors favor 0-click vulns over social engineering, lines blur between state actors & hacktivist groups, and the cybercriminal economy splinters. Blog: r-7.co/49Ybbmw Report: r-7.co/43koLwV

Bild

Rapid7 observed a recent enterprise intrusion that began with a fake IT support Teams message, escalated via fake lock screens, Python-based RATs & a kernel exploit, then secured domain-wide credential access – all within 2 days. Get to know #ModeloRAT: r-7.co/4npcZuB

Bild

Today, Rapid7 was included in OpenAI's Trusted Access for Cyber program and new model launch announcement. To us, this partnership means equipping security teams with advanced capabilities and meaningfully improving their cyber resilience. Keep reading: r-7.co/3QNdgv9

Bild

🚨 On 5/6/26, #PaloAltoNetworks published a security advisory for a critical vuln. affecting PAN-OS PA-Series & VM-Series firewall appliances. CVE-2026-0300 carries a CVSSv4 score of 9.3 and has been confirmed as exploited in the wild by the vendor. More: r-7.co/48ML0Pf

Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)

On May 6, 2026, Palo Alto Networks published a security advisory for CVE-2026-0300, a critical unauthenticated buffer overflow vulnerability affecting PAN-OS PA-Series and VM-Series firewall appliance...

r-7.co

A sophisticated, state-sponsored intrusion observed in early 2026 appeared to be a standard Chaos ransomware attack. Forensic analysis has since unmasked it as a false flag attempt, linking the incident to the Iranian APT #MuddyWater. More in a new blog: r-7.co/4tiWod0

BildBild

🚨 On 4/28/26, #cPanel issued a security update to fix a critical vuln. affecting its WHM and WP Squared products. With a CVSS score of 9.8, CVE-2026-41940 allows unauth. remote attackers to bypass authentication & gain administrative access to systems: r-7.co/4vZ0vgX

Fewer than 10% of vulnerabilities are exploited, but most are prioritized as urgent. Context-driven exposure prioritization is essential, combining threat intel, asset context, & control validation to focus on what’s actually exploitable. Learn more: https://r-7.co/4cGFFtQ

BildBild

Exploited high and critical vulnerabilities are up 105% YoY. The 2026 Global Threat Landscape Report breaks down how shrinking disclosure-to-exploitation timelines are reshaping how teams assess and respond. Download it here: https://r-7.co/3PicnK6

🔎 During a recent IR engagement, Rapid7 recovered 2 #Kyber ransomware payloads. One targeted VMware ESXi infrastructure, and the other, Windows file servers – serving as a rare opportunity to analyze both variants side-by-side. Technical analysis here: r-7.co/4vN8PQY

BildBildBild

🚨 On 3/30/26, a security advisory was published for CVE-2026-33032 – a critical vulnerability affecting #NginxUI. This is a missing authentication bug with a CVSS score of 9.8, and exploitation in the wild has begun. More from Rapid7: r-7.co/4mzAr7G

🔎 Rapid7 recently observed a grouping of #ClickFix events in US & EU customer environments – appearing to masquerade as an installer for #Claude, one of today's foremost AI assistants. In a new blog, find our full technical analysis, unique indicators of compromise (IoC's), and more: r-7.co/4tW4hGi

Rapid7 Analysis: ClickFix-style Phishing Campaign Uses Fake Claude Installer

Rapid7 Labs has observed a ClickFix-style phishing campaign impersonating a Claude installer using mshta, staged PowerShell, and process injection.

r-7.co

Reactive workflows can’t keep up with AI-driven attacks and expanding attack surfaces. ⏳ In under a month, Rapid7’s Global Cybersecurity Summit will show how teams are aligning exposure, MDR, and AI to anticipate and act on risk earlier. Save your spot: https://r-7.co/41y8aoA

At Rapid7’s Global Summit, sessions will cover how teams validate detection logic against real attack paths, correlate signals across identity and cloud, and use exposure data to drive earlier detection. More details on each cloud security session: https://r-7.co/4sBnoEe

👀 What's new in Rapid7 products & services? From our acquisition of Kenzo Security to launching Metasploit Pro 5.0.0, we got off to a 🔥 start in 2026. We round up the latest improvements to the Rapid7 Platform & Labs' top Q1 research in a new blog: r-7.co/4dFsD1X

BildBild

#Anthropic's Project Glasswing is purported to have identified thousands of high-severity vulns & developed related exploits. In a new blog, Rapid7's Dir. Vuln. Intelligence poses key questions that everyone from CISOs to engineers should be considering: r-7.co/4c1jNKH

Project Glasswing: What Security Leaders Should Know and Do Now

Project Glasswing signals a future of faster AI-driven vulnerability discovery. Here’s what security leaders should prioritize next in response, from Rapid7's Director of Vulnerability Intelligence.

r-7.co

Rapid7’s IR team was recently engaged around CVE-2025-59718 – a vuln that facilitates SSO login bypass in #Fortinet FortiGate appliances. In a new blog, dive into our investigative methodology, practical detection opportunities & more: r-7.co/3Q0CMwo

Investigating FortiGate CVE-2025-59718 Exploitation: IR Tales from The Field

Rapid7’s Incident Response (IR) team was engaged to investigate an incident involving exploitation of CVE-2025-59718 against a vulnerable FortiGate appliance. This blog details exploitation insights, ...

r-7.co

New research from Rapid7 Labs has led to the discovery of 7 new BPFDoor variants, through which stateless C2 routing and ICMP relay work to bypass multi-million dollar security stacks & establish persistence in global telecoms. More in a brand new blog: r-7.co/4seMqZI

New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay

New research from Rapid7 Labs, involving the analysis of nearly 300 samples, has uncovered 7 new BPFDoor variants acting as a silent trapdoor. Activation allows malware to perfectly blend into the tar...

r-7.co

The Initial Access Broker (IAB) market is visibly maturing. In H2 2025... 📈 Asking prices (and the size of targeted orgs) rose drastically 👀 New marketplaces thrive as older forums stall or shut down 🏛️ Government the top-targeted sector For key findings, recommendations & more: r-7.co/4bVvi4Z

Bild

Rapid7 announces the acquisition of Kenzo Security to accelerate preemptive, AI-powered security operations. This expands Rapid7’s Command Platform to deliver scalable, machine-speed detection and response that disrupts attackers. Learn more: ​​r-7.co/3NORWnN

Starting soon #RSAC: Christiaan Beek, VP of Cyber Intelligence, details new research that uncovered stealth “sleeper cell” access embedded in telecommunications networks by a China-nexus threat actor. This type of compromise impacts everyone - this is a conversation you don’t want to miss.