The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

Multiple Brother Devices: Multiple Vulnerabilities (FIXED)

Vulnerabilities and Exploits

Multiple Brother Devices: Multiple Vulnerabilities (FIXED)

Stephen Fewer's avatar

Stephen Fewer

BlackSuit Continues Social Engineering Attacks in Wake of Black Basta’s Internal Conflict

Vulnerabilities and Exploits

BlackSuit Continues Social Engineering Attacks in Wake of Black Basta’s Internal Conflict

Tyler McGraw's avatar

Tyler McGraw

CVE-2025-48045, CVE-2025-48046, CVE-2025-48047: MICI NetFax Server Product Vulnerabilities (NOT FIXED)

Vulnerabilities and Exploits

CVE-2025-48045, CVE-2025-48046, CVE-2025-48047: MICI NetFax Server Product Vulnerabilities (NOT FIXED)

Anna Katarina Quinn's avatar

Anna Katarina Quinn

NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign

Vulnerabilities and Exploits

NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign

Anna Širokova's avatar
Ivan Feigl's avatar

Anna Širokova, Ivan Feigl

Multiple vulnerabilities in Ingress NGINX Controller for Kubernetes

Vulnerabilities and Exploits

Multiple vulnerabilities in Ingress NGINX Controller for Kubernetes

Stephen Fewer's avatar

Stephen Fewer

Xerox Versalink C7025 Multifunction Printer: Pass-Back Attack Vulnerabilities (FIXED)

Vulnerabilities and Exploits

Xerox Versalink C7025 Multifunction Printer: Pass-Back Attack Vulnerabilities (FIXED)

Deral Heiland's avatar

Deral Heiland

Lorex 2K Indoor Wi-Fi Security Camera: Multiple Vulnerabilities (FIXED)

Vulnerabilities and Exploits

Lorex 2K Indoor Wi-Fi Security Camera: Multiple Vulnerabilities (FIXED)

Stephen Fewer's avatar

Stephen Fewer

New “CleverSoar” Installer Targets Chinese and Vietnamese Users

Vulnerabilities and Exploits

New “CleverSoar” Installer Targets Chinese and Vietnamese Users

Natalie Zargarov's avatar

Natalie Zargarov

Malware Campaign Lures Users With Fake W2 Form

Vulnerabilities and Exploits

Malware Campaign Lures Users With Fake W2 Form

Tom Elkins's avatar

Tom Elkins

Metasploit Weekly Wrap-Up 7/19/2024

Vulnerabilities and Exploits

Metasploit Weekly Wrap-Up 7/19/2024

Christophe De La Fuente's avatar

Christophe De La Fuente

CVE-2024-4978: Backdoored Justice AV Solutions Viewer Software Used in Apparent Supply Chain Attack

Vulnerabilities and Exploits

CVE-2024-4978: Backdoored Justice AV Solutions Viewer Software Used in Apparent Supply Chain Attack

Rapid7's avatar

Rapid7

CVE-2024-0394: Rapid7 Minerva Armor Privilege Escalation (FIXED)

Vulnerabilities and Exploits

CVE-2024-0394: Rapid7 Minerva Armor Privilege Escalation (FIXED)

Dani Kamanovsky's avatar

Dani Kamanovsky

Backdoored XZ Utils (CVE-2024-3094)

Vulnerabilities and Exploits

Backdoored XZ Utils (CVE-2024-3094)

Rapid7's avatar

Rapid7

How To Hunt For UEFI Malware Using Velociraptor

Vulnerabilities and Exploits

How To Hunt For UEFI Malware Using Velociraptor

Matthew Green's avatar

Matthew Green

CVE-2023-47218: QNAP QTS and QuTS Hero Unauthenticated Command Injection (FIXED)

Vulnerabilities and Exploits

CVE-2023-47218: QNAP QTS and QuTS Hero Unauthenticated Command Injection (FIXED)

Stephen Fewer's avatar

Stephen Fewer

CVE-2023-49103 - Critical Information Disclosure in ownCloud Graph API

Vulnerabilities and Exploits

CVE-2023-49103 - Critical Information Disclosure in ownCloud Graph API

Stephen Fewer's avatar

Stephen Fewer

CVE-2023-5950 Rapid7 Velociraptor Reflected XSS

Vulnerabilities and Exploits

CVE-2023-5950 Rapid7 Velociraptor Reflected XSS

Dr. Mike Cohen's avatar

Dr. Mike Cohen

CVE-2023-47246: SysAid Zero-Day Vulnerability Exploited By Lace Tempest

Vulnerabilities and Exploits

CVE-2023-47246: SysAid Zero-Day Vulnerability Exploited By Lace Tempest

Caitlin Condon's avatar

Caitlin Condon

Rapid7-Observed Exploitation of Atlassian Confluence CVE-2023-22518

Vulnerabilities and Exploits

Rapid7-Observed Exploitation of Atlassian Confluence CVE-2023-22518

Rapid7's avatar

Rapid7

Suspected Exploitation of Apache ActiveMQ CVE-2023-46604

Vulnerabilities and Exploits

Suspected Exploitation of Apache ActiveMQ CVE-2023-46604

Rapid7's avatar

Rapid7

CVE-2023-4966: Exploitation of Citrix NetScaler Information Disclosure Vulnerability

Vulnerabilities and Exploits

CVE-2023-4966: Exploitation of Citrix NetScaler Information Disclosure Vulnerability

Rapid7's avatar

Rapid7