#Rapid7
10 stories taggedRapid7.

Rapid7 Caught Hackers Hitting SonicWall Remote Access Boxes Before the Patch
A perfect-10 flaw in SonicWall's SMA1000 gateways was already under attack when the vendor shipped its July 14 hotfix. Here is what the filing actually says.

Hackers Built Malware That Perfectly Mimics Korean and Taiwanese Email Security Boxes
Rapid7 has documented a set of Linux implants so well-tailored to their target appliances that they impersonate specific product files, ports, and processes used in real telecom environments across South Korea and Taiwan.

OnePlus phones leak text messages to any installed app, researchers warn
A flaw tracked as CVE-2025-10184 lets any app on affected OxygenOS handsets read SMS content and metadata silently, breaking one-time code security.

CISA Warns of Active Attacks on Critical NetScaler Flaw
Federal agencies have three days to patch CVE-2026-19490 after CISA confirmed criminals are actively exploiting the high-severity flaw in Citrix's widely used network gateway software.

Patching Once a Month Is No Longer Enough, Rapid7 Warns
Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

North Korean IT Worker Infiltrated a Federal Agency, Boeing 737 Security Flaws Explored, and Refrigeration Systems Found Vulnerable
A North Korean operative got hired at a US government agency, researchers found exploitable weaknesses in Boeing 737 onboard systems, and serious flaws turned up in industrial refrigeration controllers. Here's what each finding means in practice.

Careless malware crew leaves 1,048-file toolkit exposed on the open web
Rapid7 researchers grabbed the lot after the operators forgot to lock their delivery server. Inside: AI-written lures, dropper experiments and a live infostealer campaign hitting Windows users in Mexico.

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed
A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

The Security Researcher Who Took On the US Legal System and Won an MBE Doing It
Jen Ellis started out running PR for a cybersecurity firm. She ended up testifying before Congress, brokering a peace deal between hackers and the Justice Department, and picking up a royal honour along the way.

Root on Your Conference Phone: HP Poly Flaw Turns VoIP Hardware Into an AI Deepfake Feed
A CVSS 9.2 stack overflow in HP Poly's ICE implementation hands attackers unauthenticated root and a front-row seat to every executive call.