The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

Understanding the Ecosystem of Smart Cities for the Purpose of Security Testing

Industry Trends

Understanding the Ecosystem of Smart Cities for the Purpose of Security Testing

Deral Heiland's avatar

Deral Heiland

Refreshing Rapid7's Coordinated Vulnerability Disclosure Policy

Vulnerabilities and Exploits

Refreshing Rapid7's Coordinated Vulnerability Disclosure Policy

Tod Beardsley's avatar

Tod Beardsley

The 2022 Naughty and Nice List

Industry Trends

The 2022 Naughty and Nice List

Tom Caiazza's avatar

Tom Caiazza

Hallmark Channel: Securing the Season

Cloud and Devops Security

Hallmark Channel: Securing the Season

Aaron Wells's avatar

Aaron Wells

Cloud Security and Compliance Best Practices: Highlights From The CSA Cloud Controls Matrix

Products and Tools

Cloud Security and Compliance Best Practices: Highlights From The CSA Cloud Controls Matrix

Rapid7's avatar

Rapid7

CVE-2022-41080, CVE-2022-41082: Rapid7 Observed Exploitation of `OWASSRF` in Exchange for RCE

Vulnerabilities and Exploits

CVE-2022-41080, CVE-2022-41082: Rapid7 Observed Exploitation of `OWASSRF` in Exchange for RCE

Glenn Thorpe's avatar

Glenn Thorpe

Cengage LTI Session Management Leakage

Vulnerabilities and Exploits

Cengage LTI Session Management Leakage

Tod Beardsley's avatar

Tod Beardsley

ICYMI: 10 Cybersecurity Acronyms You Should Know in 2023

Industry Trends

ICYMI: 10 Cybersecurity Acronyms You Should Know in 2023

Drew Burton's avatar

Drew Burton

[The Lost Bots] S02E06: Play “Experts or Scuttlebutt?” With Us

Industry Trends

[The Lost Bots] S02E06: Play “Experts or Scuttlebutt?” With Us

Rapid7's avatar

Rapid7

Metasploit Weekly Wrap-Up: 12/16/22

Exposure Management

Metasploit Weekly Wrap-Up: 12/16/22

Brendan Watters's avatar

Brendan Watters

Spoiler Alert: Your Favorite Content Might Not Be Secure

Cloud and Devops Security

Spoiler Alert: Your Favorite Content Might Not Be Secure

Aaron Wells's avatar

Aaron Wells

Cloud Audit: Compliance + Automation

Products and Tools

Cloud Audit: Compliance + Automation

Aaron Wells's avatar

Aaron Wells

CVE-2022-27518: Critical Fix Released for Exploited Citrix ADC, Gateway Vulnerability

Exposure Management

CVE-2022-27518: Critical Fix Released for Exploited Citrix ADC, Gateway Vulnerability

Glenn Thorpe's avatar

Glenn Thorpe

Patch Tuesday - December 2022

Detection and Response

Patch Tuesday - December 2022

Greg Wiseman's avatar

Greg Wiseman

Tis the Season to Be Wary: Three Holiday Shopping Scams To Watch For

Industry Trends

Tis the Season to Be Wary: Three Holiday Shopping Scams To Watch For

Marla Rosner's avatar

Marla Rosner

CVE-2022-42475: Critical Unauthenticated Remote Code Execution Vulnerability in FortiOS; Exploitation Reported

Vulnerabilities and Exploits

CVE-2022-42475: Critical Unauthenticated Remote Code Execution Vulnerability in FortiOS; Exploitation Reported

Glenn Thorpe's avatar

Glenn Thorpe

Rapid7 Recognized as a Top Place to Work for 11th Consecutive Year

Rapid7 Blog

Rapid7 Recognized as a Top Place to Work for 11th Consecutive Year

Rapid7's avatar

Rapid7

Metasploit Wrap-Up: 12/9/22

Exposure Management

Metasploit Wrap-Up: 12/9/22

Zachary Goldman's avatar

Zachary Goldman

AWS Graviton Processor Support on Insight Agent

Cloud and Devops Security

AWS Graviton Processor Support on Insight Agent

Marco Botros's avatar

Marco Botros

2023 Cybersecurity Industry Predictions

Detection and Response

2023 Cybersecurity Industry Predictions

Tom Caiazza's avatar

Tom Caiazza

About Anomalous Data Transfer detection in InsightIDR

Products and Tools

About Anomalous Data Transfer detection in InsightIDR

Shivangi Pandey's avatar

Shivangi Pandey