The Rapid7 Blog:
Your Signal in the Security Noise
Insights, stories, and guidance from our global security and research teams.
Featured posts
3928 Results

Threat Research
NICER Protocol Deep Dive: Internet Exposure of Microsoft SQL Server (MS SQL) (UDP/1434)
Tod Beardsley

Exposure Management
Metasploit Wrap-Up: 11/20/20
Adam Cammack

Products and Tools
Announcing the 2020 December Metasploit Community CTF
Alan David Foster

Exposure Management
This One Time on a Pen Test: CSRF to Password Reset Phishing
Ted Raffle

Detection and Response
Congress unanimously passes federal IoT security law
Harley Geiger

Exposure Management
Behind the Scenes: Under the Hoodie 2020 Video Series
Bri Hand

Threat Research
Don’t Put It on the Internet: Tesla Backup Gateway Edition
Derek Abdine

Security Operations
Defining Vulnerability Risk Management (and How to Build a Modern VRM Program)
Vivian Ma

Exposure Management
Metasploit Wrap-Up: 11/13/20
Shelby Pace

Threat Research
NICER Protocol Deep Dive: Internet Exposure of MySQL
Tod Beardsley

Detection and Response
2021 Detection and Response Planning, Part 4: Planning for Success with a Cloud SIEM
Meaghan Buchanan

Detection and Response
Patch Tuesday - November 2020
Richard Tsang

Exposure Management
VMware ESXi OpenSLP Remote Code Execution Vulnerability (CVE-2020-3992 and CVE-2019-5544): What You Need To Know
boB Rudis

Threat Research
Rapid7 Analysis: CVE-2020-3992 — ESXi OpenSLP remote code execution vulnerability
Rapid7 Labs

Threat Research
SaltStack Pre-Authenticated Remote Root (CVE-2020-16846 and CVE-2020-25592): What You Need to Know
boB Rudis

Detection and Response
Visualizing Network Traffic Data to Drive Action
Darragh Delaney

Threat Research
Rapid7 Analysis: CVE-2020-16846 — SaltStack Unauthenticated Shell Injection
Rapid7 Labs

Threat Research
Rapid7 Analysis: CVE-2020-25592 — SaltStack Authentication Bypass and Salt SSH Command Execution
Rapid7 Labs

Rapid7 Blog
Advance Your Career: Life as a Rapid7 Belfast Software Engineer
Rapid7

Exposure Management
Metasploit Wrap-Up: Nov. 6, 2020
Matthew Kienow

Threat Research
This One Time on a Pen Test: How I Hacked a Self-Driving Car
Jonathan Stines

