Skip to content

company

Rapid7

Cybersecurity company that makes vulnerability management and threat detection tools like InsightVM and InsightIDR, and researches security flaws.

Known aliases

  • blog.rapid7.com
  • Rapid7 Inc.
  • Rapid7 Labs
  • Rapid7 Research
  • Rapid7 Vulnerability Research

Relationships

No evidence-backed relationships are recorded.

Current stories

security14 publishers

Investigators say a 16-year-old ran KillSec, an extortion crew that exploited weakly secured cloud storage

Eurojust says a 16-year-old is the suspected main operator of KillSec, a group it blames for almost 1,000 data-theft extortion attacks since 2024. Both published accounts say its favoured way in was poorly secured access to victims' cloud storage.

Perspective Coverage

14 publishers
Builder
Builder 16%
Operator
Operator 75%
Investor
Investor 9%

Reality

Evidence78
Adoption
Insufficient
Hype gap+25
Incentives45
Confidence76
security12 publishers

Attackers reach admin on Cisco Catalyst SD-WAN Manager by encoding one URL character

Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.

Perspective Coverage

12 publishers
Builder
Builder 14%
Operator
Operator 76%
Investor
Investor 10%

Reality

Evidence85
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence80
security3 publishers

Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric

Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.

Perspective Coverage

3 publishers
Builder
Builder 12%
Operator
Operator 76%
Investor
Investor 12%

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives70
Confidence60
security5 publishers

NetScaler auth bypass at 9.3: the box is the perimeter, so patch it this week

CVE-2026-19490 lets an unauthenticated attacker past NetScaler gateway and AAA virtual servers. Rapid7 has seen no exploitation yet and expects it shortly.

Perspective Coverage

5 publishers
Builder
Builder 14%
Operator
Operator 73%
Investor
Investor 13%

Reality

Evidence78
Adoption62
Hype gap+10
Incentives38
Confidence75
security10 publishers

Chained PaperCut flaws let unauthenticated requests load attacker Java into the server process

Huntress has seen exploitation in two customer environments. One flaw hands over PaperCut's configuration without a login, the second turns that configuration into a class loader, so patching and config review are one job.

Perspective Coverage

10 publishers
Builder
Builder 27%
Operator
Operator 60%
Investor
Investor 13%

Reality

Evidence85
Adoption70
Hype gap−10
Incentives40
Confidence78
security13 publishers

CISA's seven new KEV entries put SonicWall gateways and Artifactory on one patch clock

SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.

Perspective Coverage

13 publishers
Builder
Builder 24%
Operator
Operator 63%
Investor
Investor 13%

Reality

Evidence72
Adoption30
Hype gap+15
Incentives55
Confidence68
security5 publishers

DPRK operators compiled their backdoor into the victim's own HAProxy build

Rapid7 says the ted backdoor is built into the victim's existing HAProxy 2.8.12 and hooks its filter API, so the load balancer keeps balancing normally while it logs cookies and injects scripts for selected clients.

Perspective Coverage

5 publishers
Builder
Builder 42%
Operator
Operator 53%
Investor
Investor 5%

Reality

Evidence70
Adoption10
Hype gap+20
Incentives35
Confidence66
security7 publishers

CVE-2026-86218 gives unauthenticated attackers code execution on N-able N-central consoles

N-able shipped N-central 2026.3 HF4 on Saturday and says nothing confirms production exploitation, while Huntress calls the bug a possible zero-day and has one compromised customer console whose logs had already rotated.

Perspective Coverage

7 publishers
Builder
Builder 17%
Operator
Operator 75%
Investor
Investor 8%

Reality

Evidence72
Adoption40
Hype gap+10
Incentives55
Confidence70
security4 publishers

A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV

CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.

Perspective Coverage

4 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence70
security6 publishers

Attackers are running code on BIG-IP APM boxes configured as OAuth authorization servers

F5 disclosed CVE-2026-94127 on September 22 with hotfixes and evidence of exploitation. It is a data plane heap overflow, so a locked-down management interface still leaves the system exploitable, and federal agencies had until September 25.

Perspective Coverage

6 publishers
Builder
Builder 19%
Operator
Operator 64%
Investor
Investor 17%

Reality

Evidence78
Adoption40
Hype gap+10
Incentives30
Confidence75
security16 publishers

Cisco patches an ISE authentication bypass attackers used before the fix existed

CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.

Perspective Coverage

16 publishers
Builder
Builder 18%
Operator
Operator 64%
Investor
Investor 18%

Reality

Evidence82
Adoption58
Hype gap−8
Incentives62
Confidence80

Earlier coverage

  1. Takedowns pushed fraud buyers into smaller specialised shops, Rapid7 says

    Security · September 11, 2026 · 1 publisher

  2. CVE-2026-15409 handed one operator 534 Active Directory accounts through SonicWall WorkPlace portals

    Security · September 11, 2026 · 1 publisher

  3. Rapid7 scan engines now ask credentialed hosts for their own listening port list

    Security · September 9, 2026 · 1 publisher

  4. Attackers seized MSP N-central servers through the bypass N-able's incomplete fix left open

    Security · September 9, 2026 · 1 publisher

  5. A backdoor built as an HAProxy filter suppresses the log lines that would show it

    Build · September 8, 2026 · 1 publisher

  6. Two chained N-central bugs hand an unauthenticated caller a System administrator account

    Security · September 8, 2026 · 1 publisher

  7. Rapid7 carries CVE-2026-66066 from a Rails upload to Kernel#spawn

    Security · September 1, 2026 · 1 publisher

  8. Fulfilment breach exposes data of 13,689 Trezor customers, opening door to phishing

    Invest · August 30, 2026 · 1 publisher

  9. Sixteen Metasploit modules reduce this quarter's advisories to one-command checks

    Security · August 28, 2026 · 1 publisher

  10. Rapid7 counts 476 executive SSN records across three dark web markets

    Security · August 27, 2026 · 1 publisher

  11. Honeypots logged a SharePoint JWT bypass hunting for a Business Data Catalog sink

    Build · August 27, 2026 · 1 publisher

  12. AWS detection gets a shortlist: seven ATT&CK tactics, and only what has been seen in the wild

    Build · August 24, 2026 · 1 publisher

  13. Copilot built the fake Ledger app. A human still only made 20 lookups in two weeks.

    Invest · August 20, 2026 · 1 publisher

  14. Prompts, shell history, a jailbreak: AI assistants turn up inside a crypto-fraud build pipeline

    Security · August 18, 2026 · 1 publisher

  15. A North Korean IT worker got hired by a federal agency. Vetting is a security control now.

    Security · August 14, 2026 · 1 publisher

  16. Thirteen new Metasploit modules close the patch window on SonicWall SMA1000, Ghost CMS and Langflow

    Security · August 14, 2026 · 1 publisher

  17. SharePoint flaw went from PoC to honeypot hits in a day, and Microsoft's advisory is still silent

    Security · August 14, 2026 · 1 publisher