The Rapid7 Blog:
Your Signal in the Security Noise
Insights, stories, and guidance from our global security and research teams.
Featured posts
3933 Results

Products and Tools
Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it
Conor McCormick

Exposure Management
Patch Tuesday - September 2026

Vulnerabilities and Exploits
CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)
Stephen Fewer

Threat Research
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Labs

Vulnerabilities and Exploits
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
Rapid7

Products and Tools
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
The Metasploit Team

Vulnerabilities and Exploits
PaperCut NG/MF Critical Zero-Day Exploited in the Wild
Rapid7

Threat Research
Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs
Alexandra Blia, Maor Weinberger

Vulnerabilities and Exploits
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Stephen Fewer

Vulnerabilities and Exploits
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
Rapid7

Culture
Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America
Cássio De Alcântara
.png?width=3840&quality=75)
Threat Research
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
Rapid7 Labs

Threat Research
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Anna Širokova, Jan Recinsky

Culture
Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology
Gopan Sivasankaran

Products and Tools
Metasploit Wrap Up: Lot of summer shells and fit http profiles
Rapid7 Labs

Artificial Intelligence
AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?
Rapid7

Exposure Management
Patch Tuesday - August 2026
Adam Barnett

Vulnerabilities and Exploits
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
Stephen Fewer

Vulnerabilities and Exploits
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
Stephen Fewer

Vulnerabilities and Exploits
Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
Stephen Fewer

Vulnerabilities and Exploits
CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
Rapid7

