#Rapid7
7 stories taggedRapid7.

Patching Once a Month Is No Longer Enough, Rapid7 Warns
Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

North Korean IT Worker Infiltrated a Federal Agency, Boeing 737 Security Flaws Explored, and Refrigeration Systems Found Vulnerable
A roundup of three security stories that deserve more attention: a suspected North Korean operative who got hired at a US government agency, researchers who probed the computers aboard a Boeing 737, and critical flaws in industrial refrigeration controllers.

Careless malware crew leaves 1,048-file toolkit exposed on the open web
Rapid7 researchers grabbed the lot after the operators forgot to lock their delivery server. Inside: AI-written lures, dropper experiments and a live infostealer campaign hitting Windows users in Mexico.

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed
A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

The Security Researcher Who Took On the US Legal System and Won an MBE Doing It
Jen Ellis started out running PR for a cybersecurity firm. She ended up testifying before Congress, brokering a peace deal between hackers and the Justice Department, and picking up a royal honour along the way.

Root on Your Conference Phone: HP Poly Flaw Turns VoIP Hardware Into an AI Deepfake Feed
A CVSS 9.2 stack overflow in HP Poly's ICE implementation hands attackers unauthenticated root — and a front-row seat to every executive call.

Critical Argument Injection Flaw in Gogs Remains Unpatched
Authenticated users can exploit a critical flaw in Gogs, posing security risks for internal Git deployments.