Rapid7
20 articles
What the BPFDoor backdoor tells us about attacks on the network edge
A backdoor that makes no noise is hard to catch, and that’s the point of BPFDoor. The Linux malware waits for a special “magic packet” before it acts.
New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic
Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan
SMTP is the key: BPFDoor and AVERAT hitting the network edge
Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a n...
Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
When Business Email Compromise Starts Rewriting Reality
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultima...
Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDR
The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detec...
CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)
Overview While conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulner...
North Korea-linked Hackers Hide a Backdoor Inside HAProxy
North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean...
New Linux toolkit found in trojanized HAProxy targeting South Korean organizations
The implant, identified by Rapid7 Labs with medium confidence as originating from North Korean state-sponsored actors, targets entities in South Korea's auto...
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal d...
Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG...
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents
Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record.
Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America
Cássio De Alcântara is Director, LATAM Sales at Rapid7. Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive inno...
AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize e...
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
You can’t patch everything. So what do you fix first?
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The ser...
Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology
Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use...
Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology
Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use...