The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

CVE-2021-3198 and CVE-2021-3540: MobileIron Shell Escape Privilege Escalation Vulnerabilities

Threat Research

CVE-2021-3198 and CVE-2021-3540: MobileIron Shell Escape Privilege Escalation Vulnerabilities

Tod Beardsley's avatar

Tod Beardsley

Rapid7's 2021 ICER Takeaways: Vulnerability Disclosure Programs Among the Fortune 500

Threat Research

Rapid7's 2021 ICER Takeaways: Vulnerability Disclosure Programs Among the Fortune 500

Tod Beardsley's avatar

Tod Beardsley

Rapid7 Releases New Industry Cyber-Exposure Report (ICER): ASX 200

Threat Research

Rapid7 Releases New Industry Cyber-Exposure Report (ICER): ASX 200

Tod Beardsley's avatar

Tod Beardsley

Insider-Assisted Attacks Prove Costly for Telecoms

Threat Research

Insider-Assisted Attacks Prove Costly for Telecoms

Paul Prudhomme's avatar

Paul Prudhomme

Rapid7 Releases New Industry Cyber-Exposure Report (ICER): FTSE 350

Threat Research

Rapid7 Releases New Industry Cyber-Exposure Report (ICER): FTSE 350

Tod Beardsley's avatar

Tod Beardsley

CVE-2021-26908 and CVE-2021-26909: Automox Agent Information Disclosure (FIXED)

Threat Research

CVE-2021-26908 and CVE-2021-26909: Automox Agent Information Disclosure (FIXED)

Tod Beardsley's avatar

Tod Beardsley

Rapid7 Releases New Industry Cyber-Exposure Report (ICER): Fortune 500

Threat Research

Rapid7 Releases New Industry Cyber-Exposure Report (ICER): Fortune 500

Tod Beardsley's avatar

Tod Beardsley

SonicWall SNWLID-2021-0001 Zero-Day and SolarWinds’ 2021 CVE Trifecta: What You Need to Know

Threat Research

SonicWall SNWLID-2021-0001 Zero-Day and SolarWinds’ 2021 CVE Trifecta: What You Need to Know

boB Rudis's avatar

boB Rudis

NICER Protocol Deep Dive: Internet Exposure of HTTP and HTTPS

Threat Research

NICER Protocol Deep Dive: Internet Exposure of HTTP and HTTPS

Tod Beardsley's avatar

Tod Beardsley

NICER Protocol Deep Dive: Internet Exposure of NTP

Threat Research

NICER Protocol Deep Dive: Internet Exposure of NTP

Tod Beardsley's avatar

Tod Beardsley

NICER Protocol Deep Dive: Internet Exposure of DNS-over-TLS

Threat Research

NICER Protocol Deep Dive: Internet Exposure of DNS-over-TLS

Tod Beardsley's avatar

Tod Beardsley

NICER Protocol Deep Dive: Internet Exposure of DNS

Threat Research

NICER Protocol Deep Dive: Internet Exposure of DNS

Tod Beardsley's avatar

Tod Beardsley

Sending the All-Clear Signal: The Implications of WhatsApp’s New Data Privacy Policy

Threat Research

Sending the All-Clear Signal: The Implications of WhatsApp’s New Data Privacy Policy

Chris Strand's avatar

Chris Strand

3 Security Regulations Automotive Companies Need to Know

Threat Research

3 Security Regulations Automotive Companies Need to Know

Chris Strand's avatar

Chris Strand

NICER Protocol Deep Dive: Internet Exposure of memcached

Threat Research

NICER Protocol Deep Dive: Internet Exposure of memcached

Tod Beardsley's avatar

Tod Beardsley

Rapid7 Recognized as a Strong Performer Among Security Analytics Providers by Leading Industry Report

Threat Research

Rapid7 Recognized as a Strong Performer Among Security Analytics Providers by Leading Industry Report

Meaghan Buchanan's avatar

Meaghan Buchanan

NICER Protocol Deep Dive: Internet Exposure of Microsoft SQL Server (MS SQL) (UDP/1434)

Threat Research

NICER Protocol Deep Dive: Internet Exposure of Microsoft SQL Server (MS SQL) (UDP/1434)

Tod Beardsley's avatar

Tod Beardsley

Don’t Put It on the Internet: Tesla Backup Gateway Edition

Threat Research

Don’t Put It on the Internet: Tesla Backup Gateway Edition

Derek Abdine's avatar

Derek Abdine

NICER Protocol Deep Dive: Internet Exposure of MySQL

Threat Research

NICER Protocol Deep Dive: Internet Exposure of MySQL

Tod Beardsley's avatar

Tod Beardsley

SaltStack Pre-Authenticated Remote Root (CVE-2020-16846 and CVE-2020-25592): What You Need to Know

Threat Research

SaltStack Pre-Authenticated Remote Root (CVE-2020-16846 and CVE-2020-25592): What You Need to Know

boB Rudis's avatar

boB Rudis

This One Time on a Pen Test: How I Hacked a Self-Driving Car

Threat Research

This One Time on a Pen Test: How I Hacked a Self-Driving Car

Jonathan Stines's avatar

Jonathan Stines