The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

Maximize Your VM Investment: Fix Vulnerabilities Faster With Automox + Rapid7

Industry Trends

Maximize Your VM Investment: Fix Vulnerabilities Faster With Automox + Rapid7

Nicholas Colyer's avatar

Nicholas Colyer

Metasploit Weekly Wrap-Up: 5/13/22

Exposure Management

Metasploit Weekly Wrap-Up: 5/13/22

Erin Bleiweiss's avatar

Erin Bleiweiss

Update for CIS Google Cloud Platform Foundation Benchmarks - Version 1.3.0

Products and Tools

Update for CIS Google Cloud Platform Foundation Benchmarks - Version 1.3.0

Ryan Blanchard's avatar

Ryan Blanchard

CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection

Vulnerabilities and Exploits

CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection

Jake Baines's avatar

Jake Baines

Patch Tuesday - May 2022

Detection and Response

Patch Tuesday - May 2022

Greg Wiseman's avatar

Greg Wiseman

What's Changed for Cybersecurity in Banking and Finance: New Study

Exposure Management

What's Changed for Cybersecurity in Banking and Finance: New Study

Jesse Mack's avatar

Jesse Mack

Active Exploitation of F5 BIG-IP iControl REST CVE-2022-1388

Exposure Management

Active Exploitation of F5 BIG-IP iControl REST CVE-2022-1388

Ron Bowes's avatar

Ron Bowes

[Infographic] Cloud Misconfigurations: Don't Become a Breach Statistic

Threat Research

[Infographic] Cloud Misconfigurations: Don't Become a Breach Statistic

Rapid7's avatar

Rapid7

Metasploit Wrap-Up: May 6, 2022

Exposure Management

Metasploit Wrap-Up: May 6, 2022

Alan David Foster's avatar

Alan David Foster

Rapid7’s first comic: XDR vs. Exploito

Detection and Response

Rapid7’s first comic: XDR vs. Exploito

Amy Hunt's avatar

Amy Hunt

XSS in JSON: Old-School Attacks for Modern Applications

Cloud and Devops Security

XSS in JSON: Old-School Attacks for Modern Applications

Julius Callahan's avatar

Julius Callahan

Is Your Kubernetes Cluster Ready for Version 1.24?

Cloud and Devops Security

Is Your Kubernetes Cluster Ready for Version 1.24?

Alon Berger's avatar

Alon Berger

MDR, MEDR, SOCaaS: Which Is Right for You?

Security Operations

MDR, MEDR, SOCaaS: Which Is Right for You?

Aaron Wells's avatar

Aaron Wells

Cloud-Native Application Protection (CNAPP): What's Behind the Hype?

Products and Tools

Cloud-Native Application Protection (CNAPP): What's Behind the Hype?

Jesse Mack's avatar

Jesse Mack

Metasploit Wrap-Up: 4/29/22

Products and Tools

Metasploit Wrap-Up: 4/29/22

Shelby Pace's avatar

Shelby Pace

Widespread Exploitation of VMware Workspace ONE Access CVE-2022-22954

Exposure Management

Widespread Exploitation of VMware Workspace ONE Access CVE-2022-22954

Caitlin Condon's avatar

Caitlin Condon

How to Strategically Scale Vendor Management and Supply Chain Security

Detection and Response

How to Strategically Scale Vendor Management and Supply Chain Security

AJ Debole's avatar

AJ Debole

Velociraptor Version 0.6.4: Dead Disk Forensics and Better Path Handling Let You Dig Deeper

Detection and Response

Velociraptor Version 0.6.4: Dead Disk Forensics and Better Path Handling Let You Dig Deeper

Carlos Canto's avatar

Carlos Canto

Opportunistic Exploitation of WSO2 CVE-2022-29464

Exposure Management

Opportunistic Exploitation of WSO2 CVE-2022-29464

Jake Baines's avatar

Jake Baines

Metasploit Weekly Wrap-Up: 4/22/22

Exposure Management

Metasploit Weekly Wrap-Up: 4/22/22

Dean Welch's avatar

Dean Welch

Rapid7 Named a Visionary in 2022 Magic Quadrant™ for Application Security Testing Second Year in a Row

Products and Tools

Rapid7 Named a Visionary in 2022 Magic Quadrant™ for Application Security Testing Second Year in a Row

Bria Grangard's avatar

Bria Grangard