Rapid7 researchers have identified a sophisticated malware campaign attributed to the threat actor #DroppingElephant, characterized by the use of a China-themed decoy document to deliver a heavily reworked, in-memory RAT. Technical analysis, IoCs & more: r-7.co/4va2vSF
Rapid7
@rapid7.com
Rapid7 is a leader in AI-powered managed cybersecurity operations, trusted to advance organizations’ cyber resilience. Unified exposure and detection enable 11,500+ customers to reduce risk and disrupt attackers. 🔗: rapid7.com
🚨 On 6/10/26, #Oracle published a security alert for CVE-2026-35273, a critical vuln. affecting PeopleSoft Enterprise PeopleTools. The campaign has been attributed to the ShinyHunters collective, well known for data theft and extortion. More in our blog: r-7.co/4aEClz9
AI is actively embedding itself into today's criminal tradecraft – lending itself to social engineering, fraud, impersonation, identity abuse & more. Get to know tools like WormGPT and BruteforceAI, plus, how orgs should react, all in a new blog: r-7.co/4ooQFS7
🚨 On June 9, 2026, #Ivanti published a security advisory for 2 critical vulnerabilities affecting Ivanti Sentry (FKA MobileIron Sentry). CVE-2026-10520 (CVSS 10.0) is an OS command injection vuln, and CVE-2026-10523 (CVSS 9.9) is an authentication bypass vuln. Read on: r-7.co/4arpQHd
🚨 On 6/8/26, #CheckPoint published a security advisory for a critical vuln. affecting its Remote Access VPN, Mobile Access, and Spark Firewall products. CVE-2026-50751 allows an unauth. attacker to establish a VPN session without providing valid credentials. More: r-7.co/4fyoJJc
🌐 Announcing Rapid7's Threat Landscape Report for Q1, 2026. Threat actors favor 0-click vulns over social engineering, lines blur between state actors & hacktivist groups, and the cybercriminal economy splinters. Blog: r-7.co/49Ybbmw Report: r-7.co/43koLwV
Rapid7 observed a recent enterprise intrusion that began with a fake IT support Teams message, escalated via fake lock screens, Python-based RATs & a kernel exploit, then secured domain-wide credential access – all within 2 days. Get to know #ModeloRAT: r-7.co/4npcZuB
Today, Rapid7 was included in OpenAI's Trusted Access for Cyber program and new model launch announcement. To us, this partnership means equipping security teams with advanced capabilities and meaningfully improving their cyber resilience. Keep reading: r-7.co/3QNdgv9
🚨 On 5/6/26, #PaloAltoNetworks published a security advisory for a critical vuln. affecting PAN-OS PA-Series & VM-Series firewall appliances. CVE-2026-0300 carries a CVSSv4 score of 9.3 and has been confirmed as exploited in the wild by the vendor. More: r-7.co/48ML0Pf
Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)
On May 6, 2026, Palo Alto Networks published a security advisory for CVE-2026-0300, a critical unauthenticated buffer overflow vulnerability affecting PAN-OS PA-Series and VM-Series firewall appliance...
r-7.co
A sophisticated, state-sponsored intrusion observed in early 2026 appeared to be a standard Chaos ransomware attack. Forensic analysis has since unmasked it as a false flag attempt, linking the incident to the Iranian APT #MuddyWater. More in a new blog: r-7.co/4tiWod0
🚨 On 4/28/26, #cPanel issued a security update to fix a critical vuln. affecting its WHM and WP Squared products. With a CVSS score of 9.8, CVE-2026-41940 allows unauth. remote attackers to bypass authentication & gain administrative access to systems: r-7.co/4vZ0vgX
My dad told me if I'm the smartest person in a room, then I'm in the wrong room. For the @rapid7.com Global #Cybersecurity Summit I'll be in the right room as I'll be joined by @rajsamani.bsky.social @racheltobac.bsky.social & @grahamcluley.com for the Keynote Panel. Join us rapid7.brighttalk.com
Rapid7 2026 Global Cybersecurity Summit | Virtual Event
Join Rapid7’s 2026 Global Cybersecurity Summit, a two-day virtual event on preemptive security operations, cyber resilience, MDR, and AI-driven defense.
rapid7.brighttalk.com
Fewer than 10% of vulnerabilities are exploited, but most are prioritized as urgent. Context-driven exposure prioritization is essential, combining threat intel, asset context, & control validation to focus on what’s actually exploitable. Learn more: https://r-7.co/4cGFFtQ
Exploited high and critical vulnerabilities are up 105% YoY. The 2026 Global Threat Landscape Report breaks down how shrinking disclosure-to-exploitation timelines are reshaping how teams assess and respond. Download it here: https://r-7.co/3PicnK6
🔎 During a recent IR engagement, Rapid7 recovered 2 #Kyber ransomware payloads. One targeted VMware ESXi infrastructure, and the other, Windows file servers – serving as a rare opportunity to analyze both variants side-by-side. Technical analysis here: r-7.co/4vN8PQY
🚨 On 3/30/26, a security advisory was published for CVE-2026-33032 – a critical vulnerability affecting #NginxUI. This is a missing authentication bug with a CVSS score of 9.8, and exploitation in the wild has begun. More from Rapid7: r-7.co/4mzAr7G
🔎 Rapid7 recently observed a grouping of #ClickFix events in US & EU customer environments – appearing to masquerade as an installer for #Claude, one of today's foremost AI assistants. In a new blog, find our full technical analysis, unique indicators of compromise (IoC's), and more: r-7.co/4tW4hGi
Rapid7 Analysis: ClickFix-style Phishing Campaign Uses Fake Claude Installer
Rapid7 Labs has observed a ClickFix-style phishing campaign impersonating a Claude installer using mshta, staged PowerShell, and process injection.
r-7.co
Reactive workflows can’t keep up with AI-driven attacks and expanding attack surfaces. ⏳ In under a month, Rapid7’s Global Cybersecurity Summit will show how teams are aligning exposure, MDR, and AI to anticipate and act on risk earlier. Save your spot: https://r-7.co/41y8aoA
At Rapid7’s Global Summit, sessions will cover how teams validate detection logic against real attack paths, correlate signals across identity and cloud, and use exposure data to drive earlier detection. More details on each cloud security session: https://r-7.co/4sBnoEe
At 167, vulnerability totals for #PatchTuesday are higher than usual, driven by expanding AI capabilities. Microsoft is aware of exploitation in the wild for 1, public disclosure for 1 other, & evaluates 19 more as likely to see future exploitation. 👉 https://r-7.co/4chSSsQ
👀 What's new in Rapid7 products & services? From our acquisition of Kenzo Security to launching Metasploit Pro 5.0.0, we got off to a 🔥 start in 2026. We round up the latest improvements to the Rapid7 Platform & Labs' top Q1 research in a new blog: r-7.co/4dFsD1X
#Anthropic's Project Glasswing is purported to have identified thousands of high-severity vulns & developed related exploits. In a new blog, Rapid7's Dir. Vuln. Intelligence poses key questions that everyone from CISOs to engineers should be considering: r-7.co/4c1jNKH
Project Glasswing: What Security Leaders Should Know and Do Now
Project Glasswing signals a future of faster AI-driven vulnerability discovery. Here’s what security leaders should prioritize next in response, from Rapid7's Director of Vulnerability Intelligence.
r-7.co
Rapid7’s IR team was recently engaged around CVE-2025-59718 – a vuln that facilitates SSO login bypass in #Fortinet FortiGate appliances. In a new blog, dive into our investigative methodology, practical detection opportunities & more: r-7.co/3Q0CMwo
Investigating FortiGate CVE-2025-59718 Exploitation: IR Tales from The Field
Rapid7’s Incident Response (IR) team was engaged to investigate an incident involving exploitation of CVE-2025-59718 against a vulnerable FortiGate appliance. This blog details exploitation insights, ...
r-7.co
New research from Rapid7 Labs has led to the discovery of 7 new BPFDoor variants, through which stateless C2 routing and ICMP relay work to bypass multi-million dollar security stacks & establish persistence in global telecoms. More in a brand new blog: r-7.co/4seMqZI
New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay
New research from Rapid7 Labs, involving the analysis of nearly 300 samples, has uncovered 7 new BPFDoor variants acting as a silent trapdoor. Activation allows malware to perfectly blend into the tar...
r-7.co
The Initial Access Broker (IAB) market is visibly maturing. In H2 2025... 📈 Asking prices (and the size of targeted orgs) rose drastically 👀 New marketplaces thrive as older forums stall or shut down 🏛️ Government the top-targeted sector For key findings, recommendations & more: r-7.co/4bVvi4Z
Rapid7 announces the acquisition of Kenzo Security to accelerate preemptive, AI-powered security operations. This expands Rapid7’s Command Platform to deliver scalable, machine-speed detection and response that disrupts attackers. Learn more: r-7.co/3NORWnN
▶️ Now Playing: Telecom Sleeper Cells, SD-WAN Bypasses, & LLM Bug Bounties. In Episode 2 of Hacktics and Telemetry, Douglas McKee & @cryptocat.me continue to bring you the latest in cybersecurity news, vuln research, and actionable defensive strategies: https://r-7.co/4sTbDu5
Starting soon #RSAC: Christiaan Beek, VP of Cyber Intelligence, details new research that uncovered stealth “sleeper cell” access embedded in telecommunications networks by a China-nexus threat actor. This type of compromise impacts everyone - this is a conversation you don’t want to miss.
CTA member @rapid7.com uncovered stealth “sleeper cell” access embedded in telecommunications networks by a China-nexus threat actor. This type of compromise impacts everyone. tinyurl.com/233r7e6t #cybersecurity
BPFdoor in Telecom Networks: Sleeper Cells in the backbone
A months-long investigation by Rapid7 Labs has uncovered evidence of an advanced China-nexus threat actor placing stealthy digital sleeper cells in telecommunications networks, in order to carry out h...
tinyurl.com
Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks 📖 Read more: www.helpnetsecurity.com/2026/03/26/t... #cybersecurity #cybersecuritynews #backdoor #malware #Linux @rapid7.com
Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks - Help Net Security
Researchers have released a scanning script to help with detection of hard-to-spot BPFDoor implants used by Salt Typhoon.
helpnetsecurity.com