Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

NICER Protocol Deep Dive: Internet Exposure of MySQL

Threat Research

NICER Protocol Deep Dive: Internet Exposure of MySQL

Tod Beardsley's avatar

Tod Beardsley

2021 Detection and Response Planning, Part 4: Planning for Success with a Cloud SIEM

Detection and Response

2021 Detection and Response Planning, Part 4: Planning for Success with a Cloud SIEM

Meaghan Buchanan's avatar

Meaghan Buchanan

Patch Tuesday - November 2020

Detection and Response

Patch Tuesday - November 2020

Richard Tsang's avatar

Richard Tsang

VMware ESXi OpenSLP Remote Code Execution Vulnerability (CVE-2020-3992 and CVE-2019-5544): What You Need To Know

Exposure Management

VMware ESXi OpenSLP Remote Code Execution Vulnerability (CVE-2020-3992 and CVE-2019-5544): What You Need To Know

boB Rudis's avatar

boB Rudis

Rapid7 Analysis: CVE-2020-3992 — ESXi OpenSLP remote code execution vulnerability

Threat Research

Rapid7 Analysis: CVE-2020-3992 — ESXi OpenSLP remote code execution vulnerability

Rapid7 Labs's avatar

Rapid7 Labs

SaltStack Pre-Authenticated Remote Root (CVE-2020-16846 and CVE-2020-25592): What You Need to Know

Threat Research

SaltStack Pre-Authenticated Remote Root (CVE-2020-16846 and CVE-2020-25592): What You Need to Know

boB Rudis's avatar

boB Rudis

Visualizing Network Traffic Data to Drive Action

Detection and Response

Visualizing Network Traffic Data to Drive Action

Darragh Delaney's avatar

Darragh Delaney

Rapid7 Analysis: CVE-2020-16846 — SaltStack Unauthenticated Shell Injection

Threat Research

Rapid7 Analysis: CVE-2020-16846 — SaltStack Unauthenticated Shell Injection

Rapid7 Labs's avatar

Rapid7 Labs

Rapid7 Analysis: CVE-2020-25592 — SaltStack Authentication Bypass and Salt SSH Command Execution

Threat Research

Rapid7 Analysis: CVE-2020-25592 — SaltStack Authentication Bypass and Salt SSH Command Execution

Rapid7 Labs's avatar

Rapid7 Labs

Advance Your Career: Life as a Rapid7 Belfast Software Engineer

Rapid7 Blog

Advance Your Career: Life as a Rapid7 Belfast Software Engineer

Rapid7's avatar

Rapid7

Metasploit Wrap-Up: Nov. 6, 2020

Exposure Management

Metasploit Wrap-Up: Nov. 6, 2020

Matthew Kienow's avatar

Matthew Kienow

This One Time on a Pen Test: How I Hacked a Self-Driving Car

Threat Research

This One Time on a Pen Test: How I Hacked a Self-Driving Car

Jonathan Stines's avatar

Jonathan Stines

tCell by Rapid7 Now Available for the European Region

Products and Tools

tCell by Rapid7 Now Available for the European Region

Rapid7's avatar

Rapid7

Rapid7 Analysis: CVE-2020-14871

Threat Research

Rapid7 Analysis: CVE-2020-14871

Rapid7 Labs's avatar

Rapid7 Labs

NICER Protocol Deep Dive: Internet Exposure of Citrix ADC/NetScaler

Threat Research

NICER Protocol Deep Dive: Internet Exposure of Citrix ADC/NetScaler

Tod Beardsley's avatar

Tod Beardsley

The Story Behind Security Breaches

Exposure Management

The Story Behind Security Breaches

Laurel Marotta's avatar

Laurel Marotta

Overview of Content Security Policies (CSPs) on the Web

Products and Tools

Overview of Content Security Policies (CSPs) on the Web

Curt Barnard's avatar

Curt Barnard

Rapid7 Analysis: CVE-2020-17087 Windows Kernel local privilege escalation 0day

Threat Research

Rapid7 Analysis: CVE-2020-17087 Windows Kernel local privilege escalation 0day

Rapid7 Labs's avatar

Rapid7 Labs

Metasploit Wrap-Up 10/30/20

Products and Tools

Metasploit Wrap-Up 10/30/20

Christopher Granleese's avatar

Christopher Granleese

National Cybersecurity Awareness Month: Security Pros Offer Top Tips for Staying Safe Online

Industry Trends

National Cybersecurity Awareness Month: Security Pros Offer Top Tips for Staying Safe Online

Rapid7's avatar

Rapid7

Oracle WebLogic Unauthenticated Complete Takeover (CVE-2020-14882/CVE-2020-14750): What You Need to Know

Vulnerabilities and Exploits

Oracle WebLogic Unauthenticated Complete Takeover (CVE-2020-14882/CVE-2020-14750): What You Need to Know

boB Rudis's avatar

boB Rudis