Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)Rapid7
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectorsRapid7 Intelligence
Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)Stephen Fewer
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on RailsRapid7 Intelligence
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)Rapid7
From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery LabAnna Širokova, Jan Recinsky
Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)Rapid7
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader ChainAnna Širokova
Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing CybercrimeJeremy Makowski
Rapid7 Quarterly Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcementRapid7 Intelligence
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)Jonah Burgess, Stephen Fewer