Tag

#Rapid7

10 stories taggedRapid7.

Illustration: a rack-mounted network security appliance in a dim server room, status LEDs glowing amber and red
Vulnerabilities

Rapid7 Caught Hackers Hitting SonicWall Remote Access Boxes Before the Patch

A perfect-10 flaw in SonicWall's SMA1000 gateways was already under attack when the vendor shipped its July 14 hotfix. Here is what the filing actually says.

3 min read
Illustration: the interior of a server rack inside a dimly lit data centre
Threat Intelligence

Hackers Built Malware That Perfectly Mimics Korean and Taiwanese Email Security Boxes

Rapid7 has documented a set of Linux implants so well-tailored to their target appliances that they impersonate specific product files, ports, and processes used in real telecom environments across South Korea and Taiwan.

5 min read
Illustration: a modern black Android smartphone lying face up on a dark matte surface
Vulnerabilities

OnePlus phones leak text messages to any installed app, researchers warn

A flaw tracked as CVE-2025-10184 lets any app on affected OxygenOS handsets read SMS content and metadata silently, breaking one-time code security.

4 min read
Federal cybersecurity operations center with urgent alert banners across multiple screens displaying NetScaler vulnerability information, patch deployment timel
Vulnerabilities

CISA Warns of Active Attacks on Critical NetScaler Flaw

Federal agencies have three days to patch CVE-2026-19490 after CISA confirmed criminals are actively exploiting the high-severity flaw in Citrix's widely used network gateway software.

3 min read
A calendar showing traditional monthly patch days with a rapidly growing pile of unpatched vulnerabilities cascading across subsequent weeks, visualized as an o
Vulnerabilities

Patching Once a Month Is No Longer Enough, Rapid7 Warns

Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

3 min read
Federal agency office building exterior at dusk with security perimeter visible, simultaneous image inset showing Boeing 737 cockpit avionics systems and separa
Threat Intelligence

North Korean IT Worker Infiltrated a Federal Agency, Boeing 737 Security Flaws Explored, and Refrigeration Systems Found Vulnerable

A North Korean operative got hired at a US government agency, researchers found exploitable weaknesses in Boeing 737 onboard systems, and serious flaws turned up in industrial refrigeration controllers. Here's what each finding means in practice.

3 min read
Illustration: a dimly lit server rack in a small unmarked room, one door left ajar with light spilling into a corridor
Threat Intelligence

Careless malware crew leaves 1,048-file toolkit exposed on the open web

Rapid7 researchers grabbed the lot after the operators forgot to lock their delivery server. Inside: AI-written lures, dropper experiments and a live infostealer campaign hitting Windows users in Mexico.

3 min read
A network security dashboard displayed across multiple monitors showing warning alerts and breach notifications, with a keyboard and mouse in the foreground sug
Vulnerabilities

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed

A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

3 min read
Illustration: an empty wood-panelled congressional hearing room, rows of microphones on a long curved dais
Policy & Regulation

The Security Researcher Who Took On the US Legal System and Won an MBE Doing It

Jen Ellis started out running PR for a cybersecurity firm. She ended up testifying before Congress, brokering a peace deal between hackers and the Justice Department, and picking up a royal honour along the way.

4 min read
Illustration: a modern black IP conference phone sitting on a polished corporate boardroom table
Vulnerabilities

Root on Your Conference Phone: HP Poly Flaw Turns VoIP Hardware Into an AI Deepfake Feed

A CVSS 9.2 stack overflow in HP Poly's ICE implementation hands attackers unauthenticated root and a front-row seat to every executive call.

3 min read
© 2026 Threat Vectr