Posts tagged Research
.png?width=3840&quality=75)
Threat Research
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
Rapid7 Labs

Artificial Intelligence
AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?
Rapid7

Vulnerabilities and Exploits
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
Stephen Fewer

Products and Tools
What’s New in Rapid7 Products and Services: Q2 2026 in Review
Ed Montgomery

Vulnerabilities and Exploits
Sunsetting the Public AttackerKB Platform
Douglas McKee, Director, Vulnerability Intelligence

Vulnerabilities and Exploits
CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
Stephen Fewer

Threat Research
Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime
Jeremy Makowski

Vulnerabilities and Exploits
CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation
Douglas McKee, Director, Vulnerability Intelligence

Vulnerabilities and Exploits
CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)
Stephen Fewer

Vulnerabilities and Exploits
CVE-2026-52806: Authenticated RCE via Argument Injection in Gogs (FIXED as of June 7, 2026)
Jonah Burgess

Threat Research
Rapid7 Quarterly Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement
Rapid7 Labs

Vulnerabilities and Exploits
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
Jonah Burgess, Stephen Fewer

Vulnerabilities and Exploits
The Dark Side of Efficiency: When Network Controllers Become "God Mode" for Attackers
Douglas McKee, Director, Vulnerability Intelligence

Threat Research
When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise
Anna Širokova

Threat Research
New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay
Rapid7 Labs

Threat Research
BPFdoor in Telecom Networks: Sleeper Cells in the Backbone
Rapid7 Labs

Threat Research
New Whitepaper: Exploiting Cellular-based IoT Devices
Deral Heiland

Vulnerabilities and Exploits
CVE-2026-31381, CVE-2026-31382: Gainsight Assist Information Disclosure and Cross-Site Scripting (FIXED)
Christopher O’Boyle

Threat Research
The Attack Cycle is Accelerating: Announcing the Rapid7 2026 Global Threat Landscape Report
Rapid7 Labs

Threat Research
Rapid7 Analysis: CVE-2026-20127
Rapid7 Labs

Threat Research
When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation
Milan Spinka