Sign in

Raj Samani

@rajsamani.bsky.social
260 followers 22 following 52 posts

Chief Scientist @Rapid7 (ex @McAfee) | @cloudsa | Co-author of @CyberGridBook & CSA Guide to Cloud | Advisor @EC3Europol bsky.app/profile/rajsamani.bsky.soc…

PostsRepliesMedia
Reposted by Raj Samani
Graham Cluley @grahamcluley.com · 14/04/2026
I'm speaking at Rapid7's 2026 Global Cybersecurity Summit, May 12-13. Come hear me chat about how modern attacks actually start, and the reality of running a SOC in 2026 - alongside @racheltobac.bsky.social, @rajsamani.bsky.social, and @brianhonan.bsky.social rapid7.brighttalk.com?utm_source=r...
rapid7.brighttalk.com
Rapid7 2026 Global Cybersecurity Summit | Virtual Event
Join Rapid7’s 2026 Global Cybersecurity Summit, a two-day virtual event on preemptive security operations, cyber resilience, MDR, and AI-driven defense.
073
Reposted by Raj Samani
Brian Honan @brianhonan.bsky.social · 29/04/2026
My dad told me if I'm the smartest person in a room, then I'm in the wrong room. For the @rapid7.com Global #Cybersecurity Summit I'll be in the right room as I'll be joined by @rajsamani.bsky.social @racheltobac.bsky.social & @grahamcluley.com for the Keynote Panel. Join us rapid7.brighttalk.com
rapid7.brighttalk.com
Rapid7 2026 Global Cybersecurity Summit | Virtual Event
Join Rapid7’s 2026 Global Cybersecurity Summit, a two-day virtual event on preemptive security operations, cyber resilience, MDR, and AI-driven defense.
0103
Raj Samani @rajsamani.bsky.social · 30/01/2026
What the first 24 hours of a cyber incident should look like New blog by me, details the evolving nature of #cybersecurity operations in light of escalating capabilities of threat groups: www.information-age.com/what-the-fir... #infosec #metasploit
information-age.com
What the first 24 hours of a cyber incident should look like - Information Age
The early stages following a cyber incident are arguably the most important. Here's how to manage it and learn from it
010
Raj Samani @rajsamani.bsky.social · 30/10/2025
Delighted to share that Vulnerability Intelligence is now incorporated within our @rapid7.com - sharing contextual indicators including which CVEs are actively exploited, by whom, and what impact they have. More details available within our announcement: www.rapid7.com/blog/post/pt... #infosec
rapid7.com
Defend Smarter, Not Harder, with Rapid7: The Power of Curated Vulnerability Intelligence
Rapid7 delivers actionable intelligence through Intelligence Hub; identifying the vulnerabilities that actually matter, rather than relying on generic security ratings – or trying to decipher whether ...
011
Reposted by Raj Samani
Cyber Threat Alliance @cyberalliance.bsky.social · 30/07/2025
The @cyberalliance.bsky.social thrilled to welcome @rajsamani.bsky.social to our Board of Directors. His expertise and vision will be a huge asset to our journey ahead. ✨ Get to know more about Raj in our spotlight feature! www.cyberthreatalliance.org/cta-board-of... #cybersecurity #EmpoweringCTA
cyberthreatalliance.org
CTA Board of Directors Spotlight: Raj Samani, Rapid7 - Cyber Threat Alliance
Welcome to the CTA board of directors. We are delighted to have you on the board. What inspired you to want to be on the CTA board? I have been engaged with the CTA from its inception, having seen the...
043
Raj Samani @rajsamani.bsky.social · 04/07/2025
Our latest @rapid7.com advisory details a threat briefing including TTPs into the Scattered Spider threat group: www.rapid7.com/blog/post/sc... #infosec #cybersecurity
rapid7.com
Rapid7
Scattered Spider is a cybercrime group known for targeting enterprises via social engineering. Learn their TTPs, defenses, and more in our latest blog.
001
Raj Samani @rajsamani.bsky.social · 25/06/2025
Our latest @rapid7.com vuln disclosure details eight vulnerabilities into multi-function printers impacts 742 models across 4 vendors. The most serious of the findings is the authentication bypass CVE-2024-51978. www.rapid7.com/blog/post/mu... H/T @stephenfewer.bsky.social
001
Raj Samani @rajsamani.bsky.social · 19/06/2025
Our latest @rapid7.com analysis details a critical remote code execution (RCE) vulnerability tracked as CVE-2025-23121 within Veeam Backup & Replication. more details here: www.rapid7.com/blog/post/et... #infosec #cybersecurity
rapid7.com
Rapid7
On Tuesday, June 17, 2025, backup and recovery software provider #Veeam published a security advisory for a critical remote code execution (RCE) vulnerability, tracked as CVE-2025-23121. Read more in ...
001
Raj Samani @rajsamani.bsky.social · 04/06/2025
Our latest @rapid7.com analysis reveals the most common initial access vector for observed incidents were valid account credentials, and yes no MFA in place! www.rapid7.com/blog/post/20... #infosec #cybersecurity
001
Raj Samani @rajsamani.bsky.social · 27/05/2025
We have published analysis into CVE-2024-58136 on #AttackerKB - This new CVE is a patch bypass of CVE-2024-4990 and exploited in the wild by threat actors, particularly in regard to CraftCMS, where this vulnerability was used to trigger RCE. attackerkb.com/topics/U2Ddo... #infosec #cybersecurity
attackerkb.com
CVE-2024-58136 | AttackerKB
Yii framework is a component-based MVC web application framework, providing developers with the building blocks to create complex web applications including mo…
000
Raj Samani @rajsamani.bsky.social · 20/05/2025
Our latest @rapid7.com analysis does a deep dive into CVE-2025-32756 which is exploited in the Wild, Affecting Multiple Fortinet Products. H/T @stephenfewer.bsky.social www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Multiple Fortinet products CVE-2025-32756 exploited in the wild | Rapid7 Blog
On 5/13/25, Fortinet disclosed CVE-2025-32756, an unauthenticated stack-based buffer overflow affecting multiple FortiNet products. Learn more!
000
Raj Samani @rajsamani.bsky.social · 12/05/2025
Our latest @rapid7.com analysis details three new vulnerabilities affecting SonicWall Secure Mobile Access (“SMA”) 100 series appliances courtesy of @booleanblind.bsky.social are tracked as CVE-2025-32819, CVE-2025-32820, and CVE-2025-32821 www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Multiple Vulnerabilities in SonicWall SMA 100 Series (FIXED) | Rapid7 Blog
In April 2025, Rapid7 discovered and disclosed three new vulnerabilities affecting SonicWall Secure Mobile Access ("SMA") 100 series appliances. Learn more!
011
Raj Samani @rajsamani.bsky.social · 06/05/2025
Our latest #Metasploit weekly wrap up details a a new module “exploit/multi/http/wondercms_rce” which exploits CVE-2023-41425 - a file upload vulnerability. The module will authenticate against the vulnerable WonderCMS instance. More details available here: www.rapid7.com/blog/post/20... #infosec
rapid7.com
Metasploit Wrap-Up 05/02/2025 | Rapid7 Blog
010
Raj Samani @rajsamani.bsky.social · 23/04/2025
From noise to action: Introducing Intelligence Hub. Delighted to share details of our latest @rapid7.com release, intelligence Hub. Details of our curated intelligence platform now available here: www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
From Noise to Action: Introducing Intelligence Hub | Rapid7 Blog
We are delighted to announce the availability of Intelligence Hub, an evolution in threat intelligence delivery that is designed to provide meaningful context and actionable insights integrated with t...
011
Raj Samani @rajsamani.bsky.social · 21/04/2025
Our latest #Metasploit weekly wrap up details new modules including an unauthenticated remote code execution in BentoML (CVE-2025-27520). For more details including an enhancement to the fetch payload feature available here: www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Wrap-Up 04/18/2025 | Rapid7 Blog
000
Raj Samani @rajsamani.bsky.social · 09/04/2025
Our latest @rapid7.com analysis does a deep dive into the #ransomware eco-system revealing "80 active groups in Q1, 16 of them new since January 1. There are also 13 groups that were active in Q4, 2024, but have thus far been silent in 2025" www.rapid7.com/blog/post/20... #malware #cybersecurity
027
Raj Samani @rajsamani.bsky.social · 07/04/2025
Analysis confirms that babuk.exe, advertised in the Babuk 2.0 #Ransomware Affiliates Telegram channel, is actually based entirely on LockBit 3.0 source code—not Babuk. More details in our @rapid7.com analysis here: www.rapid7.com/blog/post/20... #infosec #malware
rapid7.com
A Rebirth of a Cursed Existence? - The Babuk Locker 2.0 | Rapid7 Blog
In early 2025, we came across a channel promoting itself as Babuk Locker. Since the original group had shut down in 2021, we decided to investigate whether this was a rebrand or a new threat.
122
Raj Samani @rajsamani.bsky.social · 04/04/2025
Our latest @rapid7.com analysis details CVE-2025-22457 a critical severity vulnerability affecting Ivanti Connect Secure, Pulse Connect Secure, Policy Secure, and ZTA Gateways (exploited in wild). Links and confirmation of content coverage detailed here: www.rapid7.com/blog/post/20... #infosec
rapid7.com
Ivanti Connect Secure CVE-2025-22457 exploited in the wild | Rapid7 Blog
001
Reposted by Raj Samani
Caitlin Condon @catc0n.bsky.social · 31/03/2025
Full technical analysis of CrushFTP CVE-2025-2825 now available in @rapid7.com's AttackerKB, c/o @booleanblind.bsky.social: attackerkb.com/topics/k0Egi...
attackerkb.com
CVE-2025-2825 | AttackerKB
On Friday, March 21, 2025, CrushFTP, a managed file transfer solution vendor, announced a new vulnerability to customers via email. This vulnerability was late…
021
Raj Samani @rajsamani.bsky.social · 27/03/2025
Our latest @rapid7.com analysis details two notable (unrelated) vulnerabilities in Next.js, a React framework for building web applications, and CrushFTP, a file transfer technology that has previously been targeted by adversaries. www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Notable vulnerabilities in Next.js (CVE-2025-29927) and CrushFTP | Rapid7 Blog
000
Raj Samani @rajsamani.bsky.social · 26/03/2025
Our latest @rapid7.com analysis details Notable vulnerabilities in Next.js (CVE-2025-29927) and CrushFTP. These (unrelated) vulns in Next.js, a React framework for building web apps, and CrushFTP, has previously been targeted by adversaries. www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Notable vulnerabilities in Next.js (CVE-2025-29927) and CrushFTP | Rapid7 Blog
010
Reposted by Raj Samani
Caitlin Condon @catc0n.bsky.social · 25/03/2025
Good context on Next.js CVE-2025-29927 here from @rapid7.com's research crew — long story short, while patching = good, we're not quite sold on the world-ending nature of this bug. We're also highlighting an unrelated vulnerability in file transfer software CrushFTP. www.rapid7.com/blog/post/20...
rapid7.com
Notable vulnerabilities in Next.js (CVE-2025-29927) and CrushFTP | Rapid7 Blog
002
Raj Samani @rajsamani.bsky.social · 24/03/2025
I wanted to thank the team at Cyber Daily for the opportunity to discuss details of our latest research in which we do a deep dive into prevalent #ransomware groups, and the evolving TTPs of APT groups. www.cyberdaily.au/digital-tran... #infosec #cybersecurity
cyberdaily.au
PODCAST: Nation-state cyber threats – how Australian organisations must prepare, with Rapid7’s Raj Samani
In this episode of the Cyber Uncut podcast, Raj Samani, senior vice president and chief scientist at Rapid7, joins host Liam Garman to unpack how nation-state threats are actively targeting Australian...
023
Raj Samani @rajsamani.bsky.social · 20/03/2025
Our latest @rapid7.com analysis into Apache Tomcat CVE-2025-24813, note this has reportedly been exploited in the wild; we are unable to confirm any successful exploitation occurring against real-world production environments: www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Apache Tomcat CVE-2025-24813: What You Need to Know | Rapid7 Blog
011
Raj Samani @rajsamani.bsky.social · 17/03/2025
Our latest #Metasploit weekly wrap-up details a deserialization module for CVE-2024-55556, exploiting unauthenticated PHP deserialization vulnerability in InvoiceShelf. More details plus plenty more here: www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Weekly Wrap-Up: 03/14/25 | Rapid7 Blog
This Metasploit Weekly Wrap-Up saw a deserialization module for CVE-2024-55556, exploiting unauthenticated PHP deserialization vulnerability in InvoiceShelf.
021
Raj Samani @rajsamani.bsky.social · 13/03/2025
Here is a video interview I did with the team #Saepio with their "In Conversation" series to discuss the trends, threats, and strategies impacting all of us within the #cybersecurity industry. www.youtube.com/watch?v=Qfuw...
youtube.com
Ep.1 In Conversation with Raj Samani
YouTube video by Saepio Information Security
140
Raj Samani @rajsamani.bsky.social · 10/03/2025
Our latest #Metasploit weekly wrap up details an auxiliary module which performs the retrieval of Network Access Account (NAA) credentials from an System Center Configuration Manager (SCCM) server. www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Wrap-Up 03/06/2025 | Rapid7 Blog
000
Raj Samani @rajsamani.bsky.social · 06/03/2025
Now available courtesy of Matt Green and Herbert Bärschneider is an artifact that hunts for Remote Monitoring and Management (RMM) tools using the LolRMM project. The goal is to detect installed or running instances. github.com/mgreen27/Det... #Velociraptor #DFIR #infosec
github.com
000
Raj Samani @rajsamani.bsky.social · 03/03/2025
A number of new modules detailed within our #Metasploit wrap up including a module which adds credential harvesting for MySCADA MyPro Manager using CVE-2025-24865 and CVE-2025-22896. More details here: www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Weekly Wrap-Up: 02/28/2025 | Rapid7 Blog
This week's Metasploit Weekly Wrap-Up saw 5 new modules. One module adds credential harvesting for MySCADA MyPro Manager using CVE-2025-24865 & CVE-2025-22896.
000
Raj Samani @rajsamani.bsky.social · 24/02/2025
Our latest @metasploit weekly wrap up details a new module for an unauthenticated remote code execution bug in NetAlertX (CVE-2024-46506 plus more... rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Weekly Wrap-Up: 02/14/2025 | Rapid7 Blog
This Metasploit weekly wrap-up saw two new module content; one being a new module for an authenticated remote code execution bug in NetAlertx.
000
Raj Samani @rajsamani.bsky.social · 14/02/2025
Our latest @rapid7.com analysis details the discovery of a high-severity SQL injection vulnerability, CVE-2025-1094, affecting the PostgreSQL interactive tool psql. More details available in our write-up here: www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
CVE-2025-1094: PostgreSQL psql SQL injection (FIXED) | Rapid7 Blog
010
Raj Samani @rajsamani.bsky.social · 10/02/2025
Our weekly #metasploit wrap-up details a module which exploits CVE-2018-15745, an unauthenticated directory traversal leading to file disclosure in Argus Surveillance DVR 4.0.0.0. www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Weekly Wrap-Up: 02/07/2025 | Rapid7 Blog
This week's release includes 2 new auxiliary modules targeting Argus Surveillance DVR and Ivanti Connect Secure. Learn more!
021
Raj Samani @rajsamani.bsky.social · 04/02/2025
Our latest metasploit weekly wrap up details a new exploit module for Craft CMS, when the attacker can use malicious FTP server to gain remote code execution www.rapid7.com/blog/post/20... CVE-2024-56145 #infosec #cybersecurity
rapid7.com
Metasploit Weekly Wrap-Up 01/31/25 | Rapid7 Blog
000
Raj Samani @rajsamani.bsky.social · 28/01/2025
Our latest @rapid7.com analysis details the 2024 #ransomware landscape. Including the 10 most prolific ransomware groups in 2024, ranked by the number of posts on leak sites: www.rapid7.com/blog/post/20... #cybersecurity #infosec #malware
021
Raj Samani @rajsamani.bsky.social · 27/01/2025
Our latest #metasploit weekly wrap-up includes a new module for exploiting CVE-2024-51092, an authenticated command injection in LibreNMS. It allows the attacker to run system commands and gain remote code execution (RCE) www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Weekly Wrap-Up: 01/24/2025 | Rapid7 Blog
This week the Metasploit Framework was blessed with an authenticated RCE module in LibreNMS, an autodiscovering PHP / MySQL-based network monitoring system.
000
Raj Samani @rajsamani.bsky.social · 21/01/2025
Our latest @metasploit weekly wrap-up includes an exploit module for CVE-2024-55956, an unauthenticated file write vulnerability affecting Cleo LexiCom, VLTrader, and Harmony versions 5.8.0.23 and below. www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Wrap Up: 01/17/2025 | Rapid7 Blog
Three new Metasploit exploit modules released, including a module targeting Cleo File Transfer Software (CVE-2024-55956). Learn more!
021
Raj Samani @rajsamani.bsky.social · 17/01/2025
Our latest @rapid7.com analysis details CVE-2024-55591, an authentication bypass vulnerability in FortiOS and FortiProxy www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Fortinet firewalls hit with new zero-day attack, older data leak | Rapid7 Blog
000
Reposted by Raj Samani
Vladimir Jirasek @jirasek.uk · 17/01/2025
New article by me published on Help Net Security: “A humble proposal: The InfoSec CIA triad should be expanded” www.helpnetsecurity.com/2025/01/16/i...
helpnetsecurity.com
A humble proposal: The InfoSec CIA triad should be expanded - Help Net Security
Vladimir Jirasek analyzes the CIA triad, highlights its flaws, and suggests standardizing terms while adding two new elements.
001
Raj Samani @rajsamani.bsky.social · 13/01/2025
Our latest metasploit weekly wrap up includes multiple new modules including an exploit module for an unauthenticated arbitrary file read vulnerability, tracked as CVE-2024-45309, which affects OneDev versions <= 11.0.8. www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Wrap-Up: 1/10/2025 | Rapid7 Blog
This Metasploit Weekly saw 4 new module contents. Adds a module for CVE-2023-2640 & CVE-2023-32629, among others. Learn more!
010
Raj Samani @rajsamani.bsky.social · 09/01/2025
Our latest @rapid7.com advisory details CVE-2025-0282: Ivanti Connect Secure zero-day which has been exploited in the wild: www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
CVE-2025-0282: Ivanti Connect Secure zero-day exploited in the wild | Rapid7 Blog
000
Raj Samani @rajsamani.bsky.social · 06/01/2025
Our metasploit 2024 wrap-up details the most notable improvements and modules including expanded support for Active Directory Certificate Services AD CS attacks. More details here: www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit 2024 Annual Wrap-Up | Rapid7 Blog
011
Raj Samani @rajsamani.bsky.social · 02/01/2025
My latest article is now published on @SCmagazineUK detailing the challenges in dealing with a #ransomware attack, and technical and ethical challenges this poses: insight.scmagazineuk.com/ransomware-r... #malware #cybersecurity
insight.scmagazineuk.com
Ransomware Reality Check: Are You Ready To Face Organised Cybercrime?
013
Reposted by Raj Samani
Brian Honan @brianhonan.bsky.social · 23/12/2024
I enjoyed taking part in this webinar with @rajsamani.bsky.social and Sabeen Malik from @rapid7.com to discuss our #cybersecurity predictions for 2025. What trends you see happening next year in #cybersecurity information.rapid7.com/Security-Pre...
information.rapid7.com
Top Security Predictions for 2025
053
Raj Samani @rajsamani.bsky.social · 20/12/2024
Our technical analysis now available in AttackerKb on CVE-2024-53677, a flawed upload logic vuln in Apache Struts 2 which permits an attacker to override internal file upload variables in apps using Apache Struts 2 File Upload Interceptor. attackerkb.com/topics/Yfjep... #infosec #cybersecurity
attackerkb.com
CVE-2024-53677 | AttackerKB
File upload logic is flawed vulnerability in Apache Struts. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to vers…
010
Raj Samani @rajsamani.bsky.social · 18/12/2024
As we close out 2024, @rapid7.com Labs reflects on a year of critical insights from #ransomware trends to exploited CVEs and #malware strains. Details of the most notable access vectors, common malware strains plus links to critical resources available here: www.rapid7.com/blog/post/20...
rapid7.com
2024 Threat Landscape Statistics: Ransomware Activity, Vulnerability Exploits, and Attack Trends | Rapid7 Blog
In this blog, the global experts across our Rapid7 Labs and Managed Services teams share real-time vulnerability insights and threat intelligence so that our customers can anticipate and prevent breac...
141
Raj Samani @rajsamani.bsky.social · 17/12/2024
Now available on AttackerKb is our Rapid7 analysis of #Cleo CVE-2024-55956 - this is a new vuln, not a patch bypass of CVE-2024-50623. IoCs included here: attackerkb.com/topics/geR0H... #infosec H/T @stephenfewer.bsky.social
attackerkb.com
CVE-2024-55956 | AttackerKB
On December 9, 2024, multiple security firms began privately reporting exploitation in the wild targeting the Cleo file transfer products LexiCom, VLTrader, an…
000
Raj Samani @rajsamani.bsky.social · 16/12/2024
Our latest metasploit weekly wrap-up details RCEs for Moodle e-Learning platform, Primefaces, WordPress Really Simple SSL and CyberPanel along with two modules to change password through LDAP and SMB. www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Weekly Wrap-Up: 12/13/2024 | Rapid7 Blog
This weekly release includes RCEs for Moodle e-Learning platform, Primefaces, WordPress Really Simple SSL & CyberPanel along with two other modules.
010
Raj Samani @rajsamani.bsky.social · 12/12/2024
While investigating incidents related to Cleo software exploitation, we observed a multi-stage attack that deploys an encoded Java Archive payload part of a modular, Java-based Remote Access Trojan (RAT). More details inc IoCs here: www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Modular Java backdoor dropped in Cleo exploitation campaign | Rapid7 Blog
While investigating Cleo software exploitation, Rapid7 Labs and MDR discovered a novel multi-stage attack that deploys an encoded JAR payload.
021
Raj Samani @rajsamani.bsky.social · 10/12/2024
Our latest Rapid7 analysis details Widespread exploitation of Cleo file transfer software (CVE-2024-50623) - with links to detection/mitigation guidance included: www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Widespread exploitation of Cleo file transfer software (CVE-2024-50623) | Rapid7 Blog
001
Raj Samani @rajsamani.bsky.social · 09/12/2024
Our latest metasploit weekly wrap-up details a number of new modules, including "an exploit module for a CRLF injection vulnerability in Ivanti Connect Secure to achieve remote code execution" www.rapid7.com/blog/post/20... #infosec #cybersecurity
rapid7.com
Metasploit Weekly Wrap-Up: 12/06/2024 | Rapid7 Blog
This week's release adds 9 new modules. A big thank you to the community for this awesome release. Learn more about the post-Thanksgiving big release!
151