Sign in

Rapid7

@rapid7.com
241 followers 12 following 208 posts

Rapid7 is a leader in AI-powered managed cybersecurity operations, trusted to advance organizations’ cyber resilience. Unified exposure and detection enable 11,500+ customers to reduce risk and disrupt attackers. 🔗: rapid7.com

PostsRepliesMedia
Rapid7 @rapid7.com · 17/06/2026
Rapid7 researchers have identified a sophisticated malware campaign attributed to the threat actor #DroppingElephant, characterized by the use of a China-themed decoy document to deliver a heavily reworked, in-memory RAT. Technical analysis, IoCs & more: r-7.co/4va2vSF
240
Rapid7 @rapid7.com · 12/06/2026
🚨 On 6/10/26, #Oracle published a security alert for CVE-2026-35273, a critical vuln. affecting PeopleSoft Enterprise PeopleTools. The campaign has been attributed to the ShinyHunters collective, well known for data theft and extortion. More in our blog: r-7.co/4aEClz9
020
Rapid7 @rapid7.com · 11/06/2026
AI is actively embedding itself into today's criminal tradecraft – lending itself to social engineering, fraud, impersonation, identity abuse & more. Get to know tools like WormGPT and BruteforceAI, plus, how orgs should react, all in a new blog: r-7.co/4ooQFS7
010
Rapid7 @rapid7.com · 10/06/2026
🚨 On June 9, 2026, #Ivanti published a security advisory for 2 critical vulnerabilities affecting Ivanti Sentry (FKA MobileIron Sentry). CVE-2026-10520 (CVSS 10.0) is an OS command injection vuln, and CVE-2026-10523 (CVSS 9.9) is an authentication bypass vuln. Read on: r-7.co/4arpQHd
000
Rapid7 @rapid7.com · 08/06/2026
🚨 On 6/8/26, #CheckPoint published a security advisory for a critical vuln. affecting its Remote Access VPN, Mobile Access, and Spark Firewall products. CVE-2026-50751 allows an unauth. attacker to establish a VPN session without providing valid credentials. More: r-7.co/4fyoJJc
000
Rapid7 @rapid7.com · 21/05/2026
🌐 Announcing Rapid7's Threat Landscape Report for Q1, 2026. Threat actors favor 0-click vulns over social engineering, lines blur between state actors & hacktivist groups, and the cybercriminal economy splinters. Blog: r-7.co/49Ybbmw Report: r-7.co/43koLwV
000
Rapid7 @rapid7.com · 13/05/2026
Rapid7 observed a recent enterprise intrusion that began with a fake IT support Teams message, escalated via fake lock screens, Python-based RATs & a kernel exploit, then secured domain-wide credential access – all within 2 days. Get to know #ModeloRAT: r-7.co/4npcZuB
011
Rapid7 @rapid7.com · 07/05/2026
Today, Rapid7 was included in OpenAI's Trusted Access for Cyber program and new model launch announcement. To us, this partnership means equipping security teams with advanced capabilities and meaningfully improving their cyber resilience. Keep reading: r-7.co/3QNdgv9
020
Rapid7 @rapid7.com · 06/05/2026
🚨 On 5/6/26, #PaloAltoNetworks published a security advisory for a critical vuln. affecting PAN-OS PA-Series & VM-Series firewall appliances. CVE-2026-0300 carries a CVSSv4 score of 9.3 and has been confirmed as exploited in the wild by the vendor. More: r-7.co/48ML0Pf
r-7.co
Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)
On May 6, 2026, Palo Alto Networks published a security advisory for CVE-2026-0300, a critical unauthenticated buffer overflow vulnerability affecting PAN-OS PA-Series and VM-Series firewall appliance...
001
Rapid7 @rapid7.com · 06/05/2026
A sophisticated, state-sponsored intrusion observed in early 2026 appeared to be a standard Chaos ransomware attack. Forensic analysis has since unmasked it as a false flag attempt, linking the incident to the Iranian APT #MuddyWater. More in a new blog: r-7.co/4tiWod0
000
Rapid7 @rapid7.com · 29/04/2026
🚨 On 4/28/26, #cPanel issued a security update to fix a critical vuln. affecting its WHM and WP Squared products. With a CVSS score of 9.8, CVE-2026-41940 allows unauth. remote attackers to bypass authentication & gain administrative access to systems: r-7.co/4vZ0vgX
010
Reposted by Rapid7
Brian Honan @brianhonan.bsky.social · 29/04/2026
My dad told me if I'm the smartest person in a room, then I'm in the wrong room. For the @rapid7.com Global #Cybersecurity Summit I'll be in the right room as I'll be joined by @rajsamani.bsky.social @racheltobac.bsky.social & @grahamcluley.com for the Keynote Panel. Join us rapid7.brighttalk.com
rapid7.brighttalk.com
Rapid7 2026 Global Cybersecurity Summit | Virtual Event
Join Rapid7’s 2026 Global Cybersecurity Summit, a two-day virtual event on preemptive security operations, cyber resilience, MDR, and AI-driven defense.
0103
Rapid7 @rapid7.com · 27/04/2026
Fewer than 10% of vulnerabilities are exploited, but most are prioritized as urgent. Context-driven exposure prioritization is essential, combining threat intel, asset context, & control validation to focus on what’s actually exploitable. Learn more: r-7.co/4cGFFtQ
000
Rapid7 @rapid7.com · 22/04/2026
Exploited high and critical vulnerabilities are up 105% YoY. The 2026 Global Threat Landscape Report breaks down how shrinking disclosure-to-exploitation timelines are reshaping how teams assess and respond. Download it here: r-7.co/3PicnK6
012
Rapid7 @rapid7.com · 21/04/2026
🔎 During a recent IR engagement, Rapid7 recovered 2 #Kyber ransomware payloads. One targeted VMware ESXi infrastructure, and the other, Windows file servers – serving as a rare opportunity to analyze both variants side-by-side. Technical analysis here: r-7.co/4vN8PQY
000
Rapid7 @rapid7.com · 16/04/2026
🚨 On 3/30/26, a security advisory was published for CVE-2026-33032 – a critical vulnerability affecting #NginxUI. This is a missing authentication bug with a CVSS score of 9.8, and exploitation in the wild has begun. More from Rapid7: r-7.co/4mzAr7G
030
Rapid7 @rapid7.com · 16/04/2026
🔎 Rapid7 recently observed a grouping of #ClickFix events in US & EU customer environments – appearing to masquerade as an installer for #Claude, one of today's foremost AI assistants. In a new blog, find our full technical analysis, unique indicators of compromise (IoC's), and more: r-7.co/4tW4hGi
r-7.co
Rapid7 Analysis: ClickFix-style Phishing Campaign Uses Fake Claude Installer
Rapid7 Labs has observed a ClickFix-style phishing campaign impersonating a Claude installer using mshta, staged PowerShell, and process injection.
020
Rapid7 @rapid7.com · 15/04/2026
Reactive workflows can’t keep up with AI-driven attacks and expanding attack surfaces. ⏳ In under a month, Rapid7’s Global Cybersecurity Summit will show how teams are aligning exposure, MDR, and AI to anticipate and act on risk earlier. Save your spot: r-7.co/41y8aoA
000
Rapid7 @rapid7.com · 15/04/2026
At Rapid7’s Global Summit, sessions will cover how teams validate detection logic against real attack paths, correlate signals across identity and cloud, and use exposure data to drive earlier detection. More details on each cloud security session: r-7.co/4sBnoEe
000
Rapid7 @rapid7.com · 15/04/2026
At 167, vulnerability totals for #PatchTuesday are higher than usual, driven by expanding AI capabilities. Microsoft is aware of exploitation in the wild for 1, public disclosure for 1 other, & evaluates 19 more as likely to see future exploitation. 👉 r-7.co/4chSSsQ
000
Rapid7 @rapid7.com · 10/04/2026
👀 What's new in Rapid7 products & services? From our acquisition of Kenzo Security to launching Metasploit Pro 5.0.0, we got off to a 🔥 start in 2026. We round up the latest improvements to the Rapid7 Platform & Labs' top Q1 research in a new blog: r-7.co/4dFsD1X
011
Rapid7 @rapid7.com · 09/04/2026
#Anthropic's Project Glasswing is purported to have identified thousands of high-severity vulns & developed related exploits. In a new blog, Rapid7's Dir. Vuln. Intelligence poses key questions that everyone from CISOs to engineers should be considering: r-7.co/4c1jNKH
r-7.co
Project Glasswing: What Security Leaders Should Know and Do Now
Project Glasswing signals a future of faster AI-driven vulnerability discovery. Here’s what security leaders should prioritize next in response, from Rapid7's Director of Vulnerability Intelligence.
000
Rapid7 @rapid7.com · 08/04/2026
Rapid7’s IR team was recently engaged around CVE-2025-59718 – a vuln that facilitates SSO login bypass in #Fortinet FortiGate appliances. In a new blog, dive into our investigative methodology, practical detection opportunities & more: r-7.co/3Q0CMwo
r-7.co
Investigating FortiGate CVE-2025-59718 Exploitation: IR Tales from The Field
Rapid7’s Incident Response (IR) team was engaged to investigate an incident involving exploitation of CVE-2025-59718 against a vulnerable FortiGate appliance. This blog details exploitation insights, ...
021
Rapid7 @rapid7.com · 02/04/2026
New research from Rapid7 Labs has led to the discovery of 7 new BPFDoor variants, through which stateless C2 routing and ICMP relay work to bypass multi-million dollar security stacks & establish persistence in global telecoms. More in a brand new blog: r-7.co/4seMqZI
r-7.co
New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay
New research from Rapid7 Labs, involving the analysis of nearly 300 samples, has uncovered 7 new BPFDoor variants acting as a silent trapdoor. Activation allows malware to perfectly blend into the tar...
010
Rapid7 @rapid7.com · 31/03/2026
The Initial Access Broker (IAB) market is visibly maturing. In H2 2025... 📈 Asking prices (and the size of targeted orgs) rose drastically 👀 New marketplaces thrive as older forums stall or shut down 🏛️ Government the top-targeted sector For key findings, recommendations & more: r-7.co/4bVvi4Z
000
Rapid7 @rapid7.com · 26/03/2026
Rapid7 announces the acquisition of Kenzo Security to accelerate preemptive, AI-powered security operations. This expands Rapid7’s Command Platform to deliver scalable, machine-speed detection and response that disrupts attackers. Learn more: ​​r-7.co/3NORWnN
000
Rapid7 @rapid7.com · 26/03/2026
▶️ Now Playing: Telecom Sleeper Cells, SD-WAN Bypasses, & LLM Bug Bounties. In Episode 2 of Hacktics and Telemetry, Douglas McKee & @cryptocat.me continue to bring you the latest in cybersecurity news, vuln research, and actionable defensive strategies: r-7.co/4sTbDu5
021
Rapid7 @rapid7.com · 26/03/2026
Starting soon #RSAC: Christiaan Beek, VP of Cyber Intelligence, details new research that uncovered stealth “sleeper cell” access embedded in telecommunications networks by a China-nexus threat actor. This type of compromise impacts everyone - this is a conversation you don’t want to miss.
010
Reposted by Rapid7
Cyber Threat Alliance @cyberalliance.bsky.social · 26/03/2026
CTA member @rapid7.com uncovered stealth “sleeper cell” access embedded in telecommunications networks by a China-nexus threat actor. This type of compromise impacts everyone. tinyurl.com/233r7e6t #cybersecurity
tinyurl.com
BPFdoor in Telecom Networks: Sleeper Cells in the backbone
A months-long investigation by Rapid7 Labs has uncovered evidence of an advanced China-nexus threat actor placing stealthy digital sleeper cells in telecommunications networks, in order to carry out h...
021
Reposted by Rapid7
Help Net Security @helpnetsecurity.com · 26/03/2026
Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks 📖 Read more: www.helpnetsecurity.com/2026/03/26/t... #cybersecurity #cybersecuritynews #backdoor #malware #Linux @rapid7.com
helpnetsecurity.com
Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks - Help Net Security
Researchers have released a scanning script to help with detection of hard-to-spot BPFDoor implants used by Salt Typhoon.
043
Rapid7 @rapid7.com · 26/03/2026
🚨 Rapid7 Labs has uncovered stealth “sleeper cell” access embedded in telecommunications networks by a China-nexus threat actor. Telecom networks are the central nervous system of the digital world. This type of compromise impacts everyone. IoCs & more: r-7.co/3NQ7szA
141
Rapid7 @rapid7.com · 25/03/2026
Tomorrow at #RSAC: Christiaan Beek shares new research on how advanced actors establish long-term, covert access inside telecom environments, & what that means for defenders. If you’re defending critical infrastructure, this is a conversation you don’t want to miss.
000
Rapid7 @rapid7.com · 24/03/2026
Day 2 at #RSAC ✔️ From booth conversations to new threat intel, it’s already been a busy one — but the week’s not over yet. 🤖 And there's still time to enter the giveaway, your future droid is waiting! See you at Booth S-3201 tomorrow 👋
010
Rapid7 @rapid7.com · 24/03/2026
Presented at #RSAC2026 by Deral Heiland, this research breaks down how these attacks work in practice and the consistent risks observed across tested devices. If you’re on the ground at #RSAC, come find us at Booth S-3201 to talk more.
001
Rapid7 @rapid7.com · 24/03/2026
How easily can a compromised IoT device become a path into cloud and backend systems? New from Rapid7 Labs shows how attackers exploit cellular modules to move into cloud environments, exfiltrate data, & hide command channels in normal device traffic. 🔗 r-7.co/47pAMno
110
Rapid7 @rapid7.com · 24/03/2026
⏳ Starting soon: Deral Heiland, Principal Security Researcher (IoT), presents on how hardware hacking techniques exploit cellular IoT to gain trusted access and how organizations can better defend against these risks. 1:15–2:05 PM | Moscone West 2020 | Reserved seating
000
Rapid7 @rapid7.com · 24/03/2026
Christiaan Beek unveils new threat intel in “Sleeper Cells in the Telecom Backbone: Covert Ops," mapping a stealth Linux backdoor used by the China-linked Red Menshen group to infiltrate telecom backbone infrastructure. 📅 3/26 | 12:20 PM - 1:10 PM PDT | Moscone West 2018
010
Rapid7 @rapid7.com · 24/03/2026
Last night at #RSAC: Rapid7 Labs was awarded Cyber Threat Alliance's Most Valuable Early Share! The CTA’s Early Sharing Program enables near real-time sharing of threat intelligence and research to help teams stay ahead of emerging threats.
001
Rapid7 @rapid7.com · 23/03/2026
🚨 On March 23, 2026, #Citrix published a security advisory for a critical vuln. affecting their NetScaler ADC & Gateway products. CVE-2026-3055, an out-of-bounds read, allows unauthenticated remote attackers to leak information from the appliance's memory. Read on: r-7.co/41nwCJ7
r-7.co
CVE-2026-3055: Citrix NetScaler ADC and NetScaler Gateway Out-of-Bounds Read
On March 23, 2026, Citrix published a security advisory for a critical vulnerability affecting their NetScaler ADC and NetScaler Gateway products. Read more in Rapid7's latest Emergent Threat Response...
011
Rapid7 @rapid7.com · 20/03/2026
🚨 Rapid7 Labs recently identified a chain of security vulns in #Gainsight Assist, an email plugin for the popular Customer Success software. CVE-2026-31381 & CVE-2026-31382 are an info. disclosure flaw and a reflected XSS vulnerability, respectively: r-7.co/4uG8I93
r-7.co
CVE-2026-31381, CVE-2026-31382: Gainsight Assist Information Disclosure and Cross-Site Scripting (FIXED)
Rapid7 Labs recently identified a chain of security vulnerabilities in the Gainsight Assist plugin and its interactions with a certain associated domain. More in a new blog on CVE-2026-31381 and CVE-2...
010
Rapid7 @rapid7.com · 19/03/2026
☁️ Most cloud security programs still rely on static assessment, but that doesn’t show what’s actually exploitable. New capabilities in Rapid7 Exposure Command bring runtime validation and data context to help teams identify and prioritize real risk. 📰 r-7.co/479uojW
000
Rapid7 @rapid7.com · 18/03/2026
Exploited high and critical vulnerabilities increased 105% YoY‼️ Attackers are moving faster than ever, collapsing disclosure timelines, industrializing ransomware, and accelerating attacks with AI. More in the new 2026 Global Threat Landscape Report: r-7.co/4dsL49S
000
Rapid7 @rapid7.com · 17/03/2026
New updates to the Rapid7 PACT Partner Program strengthen how Rapid7 and its partners engage customers and deliver value faster. Partner tiers, streamlined deal motions, and improved program economics support scalable partner-led growth. 📰 r-7.co/4rBnvPS
001
Rapid7 @rapid7.com · 16/03/2026
Rapid7 is bringing new research and insights to RSAC. Christiaan Beek, VP of Cyber Intelligence, will present new research on how threat actors sustain covert telecom espionage using stealth Linux backdoors. More on everything Rapid7 has planned for RSAC: r-7.co/45NKu20
000
Rapid7 @rapid7.com · 16/03/2026
Social engineering via IT support impersonation is nothing new. Here, the takeaway should be that #Teams often allows any external user to message internal staff – granting threat actors a direct, high-trust channel to your end users.
001
Rapid7 @rapid7.com · 16/03/2026
🚨 Rapid7 MDR is monitoring an increase in phishing campaigns via #MicrosoftTeams, wherein threat actors are impersonating internal IT departments then persuading users to grant remote access. Find our guidance in a new blog: r-7.co/46Y0grO
r-7.co
Rapid7 Guidance on Observed Microsoft Teams Phishing Campaigns
The Rapid7 MDR team is currently monitoring an increase in phishing campaigns where threat actors (TAs) impersonate internal IT departments via Microsoft Teams. The primary objective is to persuade us...
101
Rapid7 @rapid7.com · 12/03/2026
Make room in your RSAC itinerary for Principal Researcher (IoT) Deral Heiland's session on how hardware hacking techniques exploit cellular IoT to gain trusted access & how organizations can better defend against these risks. Get the details: r-7.co/3PywfbV | @Percent_X
010
Rapid7 @rapid7.com · 12/03/2026
🎤👾 Introducing Hacktics and Telemetry, a bi-weekly video and audio podcast out of Rapid7 Labs, starring Rapid7's Doug McKee (fulmetalpackets) & Jonah Burgess (@cryptocat.me)! 🧵 Find episode 1's companion blog here: r-7.co/4di8tuH ▶️ Or dive right into the full vid on YouTube: r-7.co/3NiQfP2
022
Rapid7 @rapid7.com · 11/03/2026
Today, Rapid7 Labs published 2 advisory blogs around the conflict in Iran: 👉 Iran’s Cyber Playbook | Observed cyber activity & trends: r-7.co/4sFoP5c 👉 Detection coverage for Rapid7 customers: r-7.co/4be3vfW
000
Rapid7 @rapid7.com · 10/03/2026
Microsoft published 77 vulnerabilities for March's #PatchTuesday. 2 were publicly disclosed, though none have evidence of exploitation in the wild (yet). 🔍 Get the full analysis of what stood out this month: r-7.co/4rrySd8
010