Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing CybercrimeJeremy Makowski
CVE-2026-0826: How an Old Bug Can Feed AI-Powered ImpersonationDouglas McKee, Director, Vulnerability Intelligence
CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)Stephen Fewer
CVE-2026-52806: Authenticated RCE via Argument Injection in Gogs (FIXED as of June 7, 2026)Jonah Burgess
Rapid7 Quarterly Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcementRapid7 Labs
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)Jonah Burgess, Stephen Fewer
The Dark Side of Efficiency: When Network Controllers Become "God Mode" for AttackersDouglas McKee, Director, Vulnerability Intelligence
CVE-2026-31381, CVE-2026-31382: Gainsight Assist Information Disclosure and Cross-Site Scripting (FIXED)Christopher O’Boyle
The Attack Cycle is Accelerating: Announcing the Rapid7 2026 Global Threat Landscape ReportRapid7 Labs
When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer OperationMilan Spinka