Posts tagged Research

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Threat Research

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7 Labs's avatar

Rapid7 Labs

AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?

Artificial Intelligence

AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?

Rapid7's avatar

Rapid7

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Vulnerabilities and Exploits

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Stephen Fewer's avatar

Stephen Fewer

What’s New in Rapid7 Products and Services: Q2 2026 in Review

Products and Tools

What’s New in Rapid7 Products and Services: Q2 2026 in Review

Ed Montgomery's avatar

Ed Montgomery

Sunsetting the Public AttackerKB Platform

Vulnerabilities and Exploits

Sunsetting the Public AttackerKB Platform

Douglas McKee, Director, Vulnerability Intelligence's avatar

Douglas McKee, Director, Vulnerability Intelligence

CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

Vulnerabilities and Exploits

CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

Stephen Fewer's avatar

Stephen Fewer

Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime

Threat Research

Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime

Jeremy Makowski's avatar

Jeremy Makowski

CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation

Vulnerabilities and Exploits

CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation

Douglas McKee, Director, Vulnerability Intelligence's avatar

Douglas McKee, Director, Vulnerability Intelligence

CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)

Vulnerabilities and Exploits

CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)

Stephen Fewer's avatar

Stephen Fewer

CVE-2026-52806: Authenticated RCE via Argument Injection in Gogs (FIXED as of June 7, 2026)

Vulnerabilities and Exploits

CVE-2026-52806: Authenticated RCE via Argument Injection in Gogs (FIXED as of June 7, 2026)

Jonah Burgess's avatar

Jonah Burgess

Rapid7 Quarterly Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement

Threat Research

Rapid7 Quarterly Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement

Rapid7 Labs's avatar

Rapid7 Labs

CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)

Vulnerabilities and Exploits

CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)

Jonah Burgess's avatar
Stephen Fewer's avatar

Jonah Burgess, Stephen Fewer

The Dark Side of Efficiency: When Network Controllers Become "God Mode" for Attackers

Vulnerabilities and Exploits

The Dark Side of Efficiency: When Network Controllers Become "God Mode" for Attackers

Douglas McKee, Director, Vulnerability Intelligence's avatar

Douglas McKee, Director, Vulnerability Intelligence

When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise

Threat Research

When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise

Anna Širokova's avatar

Anna Širokova

New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay

Threat Research

New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay

Rapid7 Labs's avatar

Rapid7 Labs

BPFdoor in Telecom Networks: Sleeper Cells in the Backbone

Threat Research

BPFdoor in Telecom Networks: Sleeper Cells in the Backbone

Rapid7 Labs's avatar

Rapid7 Labs

New Whitepaper: Exploiting Cellular-based IoT Devices

Threat Research

New Whitepaper: Exploiting Cellular-based IoT Devices

Deral Heiland's avatar

Deral Heiland

CVE-2026-31381, CVE-2026-31382: Gainsight Assist Information Disclosure and Cross-Site Scripting (FIXED)

Vulnerabilities and Exploits

CVE-2026-31381, CVE-2026-31382: Gainsight Assist Information Disclosure and Cross-Site Scripting (FIXED)

Christopher O’Boyle's avatar

Christopher O’Boyle

The Attack Cycle is Accelerating: Announcing the Rapid7 2026 Global Threat Landscape Report

Threat Research

The Attack Cycle is Accelerating: Announcing the Rapid7 2026 Global Threat Landscape Report

Rapid7 Labs's avatar

Rapid7 Labs

Rapid7 Analysis: CVE-2026-20127

Threat Research

Rapid7 Analysis: CVE-2026-20127

Rapid7 Labs's avatar

Rapid7 Labs

When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation

Threat Research

When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation

Milan Spinka's avatar

Milan Spinka