The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

Reducing Cloud Chaos: Rapid7 Partners with ARMO to Deliver Cloud Runtime Security

Cloud and Devops Security

Reducing Cloud Chaos: Rapid7 Partners with ARMO to Deliver Cloud Runtime Security

Joel Alcon's avatar

Joel Alcon

Patch Tuesday - January 2026

Exposure Management

Patch Tuesday - January 2026

Adam Barnett's avatar

Adam Barnett

Metasploit Wrap-Up 01/09/2026

Products and Tools

Metasploit Wrap-Up 01/09/2026

Spencer McIntyre's avatar

Spencer McIntyre

Beyond the Device: Exploring the New Security Risks of Interconnected IoT at CES 2026

Threat Research

Beyond the Device: Exploring the New Security Risks of Interconnected IoT at CES 2026

Deral Heiland's avatar

Deral Heiland

Ni8mare and N8scape flaws among multiple critical vulnerabilities affecting n8n

Vulnerabilities and Exploits

Ni8mare and N8scape flaws among multiple critical vulnerabilities affecting n8n

Rapid7's avatar

Rapid7

Key Takeaways and Top Cybersecurity Predictions for 2026

Industry Trends

Key Takeaways and Top Cybersecurity Predictions for 2026

Rapid7's avatar

Rapid7

Metasploit 2025 Annual Wrap-Up

Products and Tools

Metasploit 2025 Annual Wrap-Up

Spencer McIntyre's avatar

Spencer McIntyre

What’s New in Rapid7 Products & Services: H2 2025 in Review

Products and Tools

What’s New in Rapid7 Products & Services: H2 2025 in Review

Margaret Wei's avatar

Margaret Wei

MongoBleed CVE-2025-14847: Critical Memory Leak in MongoDB Allowing Attackers to Extract Sensitive Data

Vulnerabilities and Exploits

MongoBleed CVE-2025-14847: Critical Memory Leak in MongoDB Allowing Attackers to Extract Sensitive Data

Rapid7's avatar

Rapid7

Metasploit Wrap-Up 12/19/2025

Products and Tools

Metasploit Wrap-Up 12/19/2025

Spencer McIntyre's avatar

Spencer McIntyre

CVE-2025-37164: Critical unauthenticated RCE affecting Hewlett Packard Enterprise OneView

Vulnerabilities and Exploits

CVE-2025-37164: Critical unauthenticated RCE affecting Hewlett Packard Enterprise OneView

Rapid7's avatar

Rapid7

Critical vulnerabilities in Fortinet CVE-2025-59718, CVE-2025-59719, CVE-2026-24858 exploited in the wild

Vulnerabilities and Exploits

Critical vulnerabilities in Fortinet CVE-2025-59718, CVE-2025-59719, CVE-2026-24858 exploited in the wild

Rapid7's avatar

Rapid7

Test for React2Shell with Application Security using New Functionality

Products and Tools

Test for React2Shell with Application Security using New Functionality

Rapid7's avatar

Rapid7

Dynamic EASM Discovery: Continuous Discovery for a Changing Attack Surface

Products and Tools

Dynamic EASM Discovery: Continuous Discovery for a Changing Attack Surface

Ed Montgomery's avatar

Ed Montgomery

SantaStealer is Coming to Town: A New, Ambitious Infostealer Advertised on Underground Forums

Threat Research

SantaStealer is Coming to Town: A New, Ambitious Infostealer Advertised on Underground Forums

Milan Spinka's avatar

Milan Spinka

Metasploit Wrap-Up 12/12/2025

Products and Tools

Metasploit Wrap-Up 12/12/2025

Spencer McIntyre's avatar

Spencer McIntyre

New Research: Multifunction Printer (MFP) Security Concerns within the Enterprise Business Environment

Vulnerabilities and Exploits

New Research: Multifunction Printer (MFP) Security Concerns within the Enterprise Business Environment

Deral Heiland's avatar
Sam Moses's avatar

Deral Heiland, Sam Moses

Geopolitics and Cyber Risk: How Global Tensions Shape the Attack Surface

Industry Trends

Geopolitics and Cyber Risk: How Global Tensions Shape the Attack Surface

Jeremy Makowski's avatar

Jeremy Makowski

Patch Tuesday - December 2025

Exposure Management

Patch Tuesday - December 2025

Adam Barnett's avatar

Adam Barnett

CVE-2025-10573: Ivanti EPM Unauthenticated Stored Cross-Site Scripting (Fixed)

Vulnerabilities and Exploits

CVE-2025-10573: Ivanti EPM Unauthenticated Stored Cross-Site Scripting (Fixed)

Ryan Emmons's avatar

Ryan Emmons

Metasploit Wrap-Up 12/05/2025

Products and Tools

Metasploit Wrap-Up 12/05/2025

Jack Heysel's avatar

Jack Heysel