The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

Thawing Out the Chilling Effect Of DMCA Section 1201

Industry Trends

Thawing Out the Chilling Effect Of DMCA Section 1201

Harley Geiger's avatar

Harley Geiger

Better Together: XDR, SOAR, Vulnerability Management, and External Threat Intelligence

Detection and Response

Better Together: XDR, SOAR, Vulnerability Management, and External Threat Intelligence

Matthew Gardiner's avatar

Matthew Gardiner

Metasploit Wrap-Up: Nov. 12, 2021

Exposure Management

Metasploit Wrap-Up: Nov. 12, 2021

Alan David Foster's avatar

Alan David Foster

Hands-On IoT Hacking: Rapid7 at DefCon 29 IoT Village, Part 4

Threat Research

Hands-On IoT Hacking: Rapid7 at DefCon 29 IoT Village, Part 4

Deral Heiland's avatar

Deral Heiland

Time to Act: Bridging the Gap in Cloud Automation Adoption

Threat Research

Time to Act: Bridging the Gap in Cloud Automation Adoption

Erica Azad's avatar

Erica Azad

Update to GLBA Security Requirements for Financial Institutions

Industry Trends

Update to GLBA Security Requirements for Financial Institutions

Harley Geiger's avatar

Harley Geiger

CVE-2021-43287 Allows Pre-Authenticated Build Takeover of GoCD Pipelines

Exposure Management

CVE-2021-43287 Allows Pre-Authenticated Build Takeover of GoCD Pipelines

Caitlin Condon's avatar

Caitlin Condon

tCell by Rapid7 Supports the Newly Released .NET 6.0

Products and Tools

tCell by Rapid7 Supports the Newly Released .NET 6.0

Bria Grangard's avatar

Bria Grangard

Opportunistic Exploitation of Zoho ManageEngine and Sitecore CVEs

Vulnerabilities and Exploits

Opportunistic Exploitation of Zoho ManageEngine and Sitecore CVEs

Caitlin Condon's avatar

Caitlin Condon

InsightIDR Was XDR Before XDR Was Even a Thing: An Origin Story

Detection and Response

InsightIDR Was XDR Before XDR Was Even a Thing: An Origin Story

Sam Adams's avatar

Sam Adams

OWASP Top 10 Deep Dive: Getting a Clear View on Vulnerable and Outdated Components

Cloud and Devops Security

OWASP Top 10 Deep Dive: Getting a Clear View on Vulnerable and Outdated Components

Amukta Nayak's avatar

Amukta Nayak

Metasploit Wrap-Up: 11/5/21

Exposure Management

Metasploit Wrap-Up: 11/5/21

Spencer McIntyre's avatar

Spencer McIntyre

New NPM library hijacks (coa and rc)

Vulnerabilities and Exploits

New NPM library hijacks (coa and rc)

Caitlin Condon's avatar

Caitlin Condon

2022 Planning: The Path to Effective Cybersecurity Maturity

Security Operations

2022 Planning: The Path to Effective Cybersecurity Maturity

Jesse Mack's avatar

Jesse Mack

Trojan Source CVE-2021-42572: No Panic Necessary

Vulnerabilities and Exploits

Trojan Source CVE-2021-42572: No Panic Necessary

boB Rudis's avatar

boB Rudis

Hands-On IoT Hacking: Rapid7 at DefCon 29 IoT Village, Part 3

Threat Research

Hands-On IoT Hacking: Rapid7 at DefCon 29 IoT Village, Part 3

Deral Heiland's avatar

Deral Heiland

Building Threat-Informed Defenses: Rapid7 Experts Share Their Thoughts on MITRE ATT&CK

Security Operations

Building Threat-Informed Defenses: Rapid7 Experts Share Their Thoughts on MITRE ATT&CK

Margaret Wei's avatar

Margaret Wei

InsightVM Scan Diagnostics: Troubleshooting Credential Issues for Authenticated Scanning

Products and Tools

InsightVM Scan Diagnostics: Troubleshooting Credential Issues for Authenticated Scanning

Greg Wiseman's avatar

Greg Wiseman

A Matter of Perspective: Agent-Based and Agentless Approaches to Cloud Security, Part 2

Cloud and Devops Security

A Matter of Perspective: Agent-Based and Agentless Approaches to Cloud Security, Part 2

Amit Bawer's avatar

Amit Bawer

Solving the Access Goldilocks Problem: RBAC for InsightAppSec Is Here

Products and Tools

Solving the Access Goldilocks Problem: RBAC for InsightAppSec Is Here

Tom Caiazza's avatar

Tom Caiazza

GitLab Unauthenticated Remote Code Execution CVE-2021-22205 Exploited in the Wild

Exposure Management

GitLab Unauthenticated Remote Code Execution CVE-2021-22205 Exploited in the Wild

Jake Baines's avatar

Jake Baines