The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

CVE-2020-0796: Microsoft SMBv3 Remote Code Execution Vulnerability Analysis

Threat Research

CVE-2020-0796: Microsoft SMBv3 Remote Code Execution Vulnerability Analysis

Bryce Abdo's avatar

Bryce Abdo

Rapid7 2020 Threat Report: Exposing Common Attacker Trends

Threat Research

Rapid7 2020 Threat Report: Exposing Common Attacker Trends

Tod Beardsley's avatar

Tod Beardsley

DOUBLEPULSAR over RDP: Baselining Badness on the Internet

Threat Research

DOUBLEPULSAR over RDP: Baselining Badness on the Internet

Tom Sellers's avatar

Tom Sellers

Active Exploitation of Citrix NetScaler (CVE-2019-19781): What You Need to Know

Threat Research

Active Exploitation of Citrix NetScaler (CVE-2019-19781): What You Need to Know

Derek Abdine's avatar

Derek Abdine

Oh, Behave! Who Made It to Rapid7 Labs' Naughty List(s) in 2019?

Threat Research

Oh, Behave! Who Made It to Rapid7 Labs' Naughty List(s) in 2019?

boB Rudis's avatar

boB Rudis

Cisco Self-Signed Certificate Expiration on Jan. 1, 2020: What You Need to Know

Threat Research

Cisco Self-Signed Certificate Expiration on Jan. 1, 2020: What You Need to Know

boB Rudis's avatar

boB Rudis

How I Shut Down a (Test) Factory with a Single Layer 2 Packet

Threat Research

How I Shut Down a (Test) Factory with a Single Layer 2 Packet

Andreas Galauner's avatar

Andreas Galauner

What a Difference a Year Makes: Revisiting Our Inaugural Fortune 500 ICER One Year Later

Threat Research

What a Difference a Year Makes: Revisiting Our Inaugural Fortune 500 ICER One Year Later

boB Rudis's avatar

boB Rudis

Rapid7 Introduces Industry Cyber-Exposure Report: Deutsche Börse Prime Standard 320

Threat Research

Rapid7 Introduces Industry Cyber-Exposure Report: Deutsche Börse Prime Standard 320

Tod Beardsley's avatar

Tod Beardsley

R7-2019-32: Denial-of-Service Vulnerabilities in Beckhoff TwinCAT PLC Environment

Threat Research

R7-2019-32: Denial-of-Service Vulnerabilities in Beckhoff TwinCAT PLC Environment

Tod Beardsley's avatar

Tod Beardsley

This One Time on a Pen Test: Our Accidental Win

Threat Research

This One Time on a Pen Test: Our Accidental Win

Ted Raffle's avatar

Ted Raffle

This One Time on a Pen Test: What’s in the Box?

Threat Research

This One Time on a Pen Test: What’s in the Box?

Ted Raffle's avatar

Ted Raffle

This One Time on a Pen Test: Nerds in the NERC

Threat Research

This One Time on a Pen Test: Nerds in the NERC

Jonathan Stines's avatar

Jonathan Stines

This One Time on a Pen Test: Missed a Spot

Threat Research

This One Time on a Pen Test: Missed a Spot

Ted Raffle's avatar

Ted Raffle

New Research: Investigating and Reversing Avionics CAN Bus Systems

Threat Research

New Research: Investigating and Reversing Avionics CAN Bus Systems

Patrick Kiley's avatar

Patrick Kiley

Attack Surface Monitoring with Project Sonar

Threat Research

Attack Surface Monitoring with Project Sonar

Jon Hart's avatar

Jon Hart

Industry Cyber-Exposure Report: FTSE 250+

Threat Research

Industry Cyber-Exposure Report: FTSE 250+

boB Rudis's avatar

boB Rudis

Extracting Firmware from Microcontrollers' 
Onboard Flash Memory, Part 3: Microchip PIC Microcontrollers

Threat Research

Extracting Firmware from Microcontrollers' Onboard Flash Memory, Part 3: Microchip PIC Microcontrollers

Deral Heiland's avatar

Deral Heiland

Extracting Firmware from Microcontrollers' 
Onboard Flash Memory, Part 2: Nordic RF Microcontrollers

Threat Research

Extracting Firmware from Microcontrollers' Onboard Flash Memory, Part 2: Nordic RF Microcontrollers

Deral Heiland's avatar

Deral Heiland

Confluence Unauthorized RCE Vulnerability (CVE-2019-3396): What You Need to Know

Threat Research

Confluence Unauthorized RCE Vulnerability (CVE-2019-3396): What You Need to Know

boB Rudis's avatar

boB Rudis

Apache HTTP Server Privilege Escalation (CVE-2019-0211): What You Need to Know

Threat Research

Apache HTTP Server Privilege Escalation (CVE-2019-0211): What You Need to Know

boB Rudis's avatar

boB Rudis