Posts tagged Labs

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

Vulnerabilities and Exploits

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

Jonah Burgess's avatar

Jonah Burgess

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Vulnerabilities and Exploits

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Rapid7's avatar

Rapid7

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

Vulnerabilities and Exploits

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

Rapid7's avatar

Rapid7

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)

Vulnerabilities and Exploits

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)

Stephen Fewer's avatar

Stephen Fewer

CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild

Vulnerabilities and Exploits

CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild

Rapid7's avatar

Rapid7

From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

Threat Research

From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

Anna Širokova's avatar
Jan Recinsky's avatar

Anna Širokova, Jan Recinsky

Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)

Vulnerabilities and Exploits

Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)

Rapid7's avatar

Rapid7

Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain

Threat Research

Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain

Anna Širokova's avatar

Anna Širokova

Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime

Threat Research

Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime

Jeremy Makowski's avatar

Jeremy Makowski

Rapid7 Quarterly Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement

Threat Research

Rapid7 Quarterly Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement

Rapid7 Labs's avatar

Rapid7 Labs

CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)

Vulnerabilities and Exploits

CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)

Jonah Burgess's avatar
Stephen Fewer's avatar

Jonah Burgess, Stephen Fewer

When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise

Threat Research

When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise

Anna Širokova's avatar

Anna Širokova

Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware

Threat Research

Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware

Alexandra Blia's avatar
Ivan Feigl's avatar

Alexandra Blia, Ivan Feigl

Experts on Experts: The 2026 Threat Landscape is Moving Faster than Defenders Expect

Industry Trends

Experts on Experts: The 2026 Threat Landscape is Moving Faster than Defenders Expect

Craig Adams's avatar

Craig Adams

What’s New in Rapid7 Products and Services: Q1 2026 in Review

Products and Tools

What’s New in Rapid7 Products and Services: Q1 2026 in Review

Ed Montgomery's avatar

Ed Montgomery

New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay

Threat Research

New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay

Rapid7 Labs's avatar

Rapid7 Labs

Initial Access Brokers have Shifted to High-Value Targets and Premium Pricing

Threat Research

Initial Access Brokers have Shifted to High-Value Targets and Premium Pricing

Rapid7 Labs's avatar

Rapid7 Labs

BPFdoor in Telecom Networks: Sleeper Cells in the Backbone

Threat Research

BPFdoor in Telecom Networks: Sleeper Cells in the Backbone

Rapid7 Labs's avatar

Rapid7 Labs

The Attack Cycle is Accelerating: Announcing the Rapid7 2026 Global Threat Landscape Report

Threat Research

The Attack Cycle is Accelerating: Announcing the Rapid7 2026 Global Threat Landscape Report

Rapid7 Labs's avatar

Rapid7 Labs

Rapid7 Analysis: CVE-2026-20127

Threat Research

Rapid7 Analysis: CVE-2026-20127

Rapid7 Labs's avatar

Rapid7 Labs

When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation

Threat Research

When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation

Milan Spinka's avatar

Milan Spinka