The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

Rapid7 Analysis: CVE-2022-40684

Threat Research

Rapid7 Analysis: CVE-2022-40684

Rapid7 Labs's avatar

Rapid7 Labs

Metasploit Wrap-Up: 10/14/22

Exposure Management

Metasploit Wrap-Up: 10/14/22

Christophe De La Fuente's avatar

Christophe De La Fuente

Cloud IAM Done Right: How LPA Helps Significantly Reduce Cloud Risk

Security Operations

Cloud IAM Done Right: How LPA Helps Significantly Reduce Cloud Risk

Ryan Blanchard's avatar

Ryan Blanchard

A SIEM With a Pen Tester's Eye: How Offensive Security Helps Shape InsightIDR

Exposure Management

A SIEM With a Pen Tester's Eye: How Offensive Security Helps Shape InsightIDR

Rapid7's avatar

Rapid7

The Intelligent Listing: Cybersecurity Job Descriptions That Deliver

Security Operations

The Intelligent Listing: Cybersecurity Job Descriptions That Deliver

Jake Godgart's avatar

Jake Godgart

Rapid7 Recognized in the 2022 Gartner® Magic Quadrant™ for SIEM

Detection and Response

Rapid7 Recognized in the 2022 Gartner® Magic Quadrant™ for SIEM

Meaghan Buchanan's avatar

Meaghan Buchanan

Real-Time Risk Mitigation in Google Cloud Platform

Products and Tools

Real-Time Risk Mitigation in Google Cloud Platform

Ben Austin's avatar

Ben Austin

Patch Tuesday - October 2022

Detection and Response

Patch Tuesday - October 2022

Greg Wiseman's avatar

Greg Wiseman

Metasploit Weekly Wrap-Up: Oct. 7, 2022

Exposure Management

Metasploit Weekly Wrap-Up: Oct. 7, 2022

Grant Willcox's avatar

Grant Willcox

CVE-2022-40684: Remote Authentication Bypass Vulnerability in Fortinet Firewalls, Web Proxies

Vulnerabilities and Exploits

CVE-2022-40684: Remote Authentication Bypass Vulnerability in Fortinet Firewalls, Web Proxies

Glenn Thorpe's avatar

Glenn Thorpe

Exploitation of Unpatched Zero-Day Remote Code Execution Vulnerability in Zimbra Collaboration Suite (CVE-2022-41352)

Exposure Management

Exploitation of Unpatched Zero-Day Remote Code Execution Vulnerability in Zimbra Collaboration Suite (CVE-2022-41352)

Ron Bowes's avatar

Ron Bowes

Rapid7 Analysis: CVE-2022-41352

Threat Research

Rapid7 Analysis: CVE-2022-41352

Rapid7 Labs's avatar

Rapid7 Labs

Rapid7 Analysis: CVE-2015-1197

Threat Research

Rapid7 Analysis: CVE-2015-1197

Rapid7 Labs's avatar

Rapid7 Labs

What's New in InsightIDR: Q3 2022 in Review

Products and Tools

What's New in InsightIDR: Q3 2022 in Review

KJ McCann's avatar

KJ McCann

Velociraptor Version 0.6.6: Multi-Tenant Mode and More Let You Dig Deeper at Scale Like Never Before

Detection and Response

Velociraptor Version 0.6.6: Multi-Tenant Mode and More Let You Dig Deeper at Scale Like Never Before

Carlos Canto's avatar

Carlos Canto

Metasploit Weekly Wrap-Up: Sep. 30, 2022

Exposure Management

Metasploit Weekly Wrap-Up: Sep. 30, 2022

Dean Welch's avatar

Dean Welch

CVE-2022-41040 and CVE-2022-41082: Unpatched Zero-Day Vulnerabilities in Microsoft Exchange Server

Exposure Management

CVE-2022-41040 and CVE-2022-41082: Unpatched Zero-Day Vulnerabilities in Microsoft Exchange Server

Caitlin Condon's avatar

Caitlin Condon

[The Lost Bots] S02E04: Cyber's Most Dangerous Game — Threat Hunting

Industry Trends

[The Lost Bots] S02E04: Cyber's Most Dangerous Game — Threat Hunting

Rapid7's avatar

Rapid7

The Empty SOC Shop: Where Has All the Talent Gone?

Industry Trends

The Empty SOC Shop: Where Has All the Talent Gone?

Jake Godgart's avatar

Jake Godgart

What’s New in InsightVM and Nexpose: Q3 2022 in Review

Products and Tools

What’s New in InsightVM and Nexpose: Q3 2022 in Review

Roshnee Mistry Shah's avatar

Roshnee Mistry Shah

How to Deploy a SIEM That Actually Works

Products and Tools

How to Deploy a SIEM That Actually Works

Robert Holzer's avatar

Robert Holzer