Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

CVE-2022-22977: VMware Guest Authentication Service LPE (FIXED)

Exposure Management

CVE-2022-22977: VMware Guest Authentication Service LPE (FIXED)

Jake Baines's avatar

Jake Baines

A Year on from the Ransomware Task Force Report

Industry Trends

A Year on from the Ransomware Task Force Report

Jen Ellis's avatar

Jen Ellis

DFIR Without Limits: Moving Beyond the “Sucker's Choice” of Today’s Breach Response Services

Detection and Response

DFIR Without Limits: Moving Beyond the “Sucker's Choice” of Today’s Breach Response Services

Jake Godgart's avatar

Jake Godgart

Metasploit Weekly Wrap-Up: 5/20/22

Exposure Management

Metasploit Weekly Wrap-Up: 5/20/22

Christophe De La Fuente's avatar

Christophe De La Fuente

Are You in the 2.5% Who Meet This Cybersecurity Job Requirement?

Security Operations

Are You in the 2.5% Who Meet This Cybersecurity Job Requirement?

Amy Hunt's avatar

Amy Hunt

CVE-2022-22972: Critical Authentication Bypass in VMware Workspace ONE Access, Identity Manager, and vRealize Automation

Exposure Management

CVE-2022-22972: Critical Authentication Bypass in VMware Workspace ONE Access, Identity Manager, and vRealize Automation

Jake Baines's avatar

Jake Baines

Find, Fix, and Report ​OWASP Top 10 Vulnerabilities in InsightAppSec

Products and Tools

Find, Fix, and Report ​OWASP Top 10 Vulnerabilities in InsightAppSec

Adrian Stewart's avatar

Adrian Stewart

Maximize Your VM Investment: Fix Vulnerabilities Faster With Automox + Rapid7

Industry Trends

Maximize Your VM Investment: Fix Vulnerabilities Faster With Automox + Rapid7

Nicholas Colyer's avatar

Nicholas Colyer

Metasploit Weekly Wrap-Up: 5/13/22

Exposure Management

Metasploit Weekly Wrap-Up: 5/13/22

Erin Bleiweiss's avatar

Erin Bleiweiss

Update for CIS Google Cloud Platform Foundation Benchmarks - Version 1.3.0

Products and Tools

Update for CIS Google Cloud Platform Foundation Benchmarks - Version 1.3.0

Ryan Blanchard's avatar

Ryan Blanchard

Rapid7 Analysis: CVE-2022-30525

Threat Research

Rapid7 Analysis: CVE-2022-30525

Rapid7 Labs's avatar

Rapid7 Labs

CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection

Vulnerabilities and Exploits

CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection

Jake Baines's avatar

Jake Baines

Rapid7 Analysis: CVE-2022-1388

Threat Research

Rapid7 Analysis: CVE-2022-1388

Rapid7 Labs's avatar

Rapid7 Labs

Patch Tuesday - May 2022

Detection and Response

Patch Tuesday - May 2022

Greg Wiseman's avatar

Greg Wiseman

What's Changed for Cybersecurity in Banking and Finance: New Study

Exposure Management

What's Changed for Cybersecurity in Banking and Finance: New Study

Jesse Mack's avatar

Jesse Mack

Active Exploitation of F5 BIG-IP iControl REST CVE-2022-1388

Exposure Management

Active Exploitation of F5 BIG-IP iControl REST CVE-2022-1388

Ron Bowes's avatar

Ron Bowes

[Infographic] Cloud Misconfigurations: Don't Become a Breach Statistic

Threat Research

[Infographic] Cloud Misconfigurations: Don't Become a Breach Statistic

Rapid7's avatar

Rapid7

Metasploit Wrap-Up: May 6, 2022

Exposure Management

Metasploit Wrap-Up: May 6, 2022

Alan David Foster's avatar

Alan David Foster

Rapid7’s first comic: XDR vs. Exploito

Detection and Response

Rapid7’s first comic: XDR vs. Exploito

Amy Hunt's avatar

Amy Hunt

Rapid7 Analysis: CVE-2022-29799 "Nimbuspwn"

Threat Research

Rapid7 Analysis: CVE-2022-29799 "Nimbuspwn"

Rapid7 Labs's avatar

Rapid7 Labs

XSS in JSON: Old-School Attacks for Modern Applications

Cloud and Devops Security

XSS in JSON: Old-School Attacks for Modern Applications

Julius Callahan's avatar

Julius Callahan