#rapid7
Some IOCs for the Notepad++ backdoors from Rapid7, they're good. www.rapid7.com/blog/post/tr...

I will drop more later.
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit
Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom.
www.rapid7.com
February 2, 2026 at 6:50 PM
Rapid7 did a write-up on the Notepad++ compromise. Rapid7 released the paper fast af boi

How?
1. They sat on it
or...
2. Called in all the malware analysis schizos for lock the fuck in time

tldr ya prolly China lol

www.rapid7.com/blog/post/tr...
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit
Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom.
www.rapid7.com
February 2, 2026 at 5:22 PM
Just Rapid7 firing employees via email as they arrive in Vegas for Black Hat/BSides/DEF CON...

https://www.rapid7.com/blog/post/2023/08/08/a-message-from-rapid7-ceo-corey-thomas/
August 10, 2023 at 12:19 AM
we found a nasty one: "the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server"
Rapid7 and Microsoft disclose CVE-2026-63520, a new SharePoint Remote Code Execution vulnerability
Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code e...
www.rapid7.com
August 11, 2026 at 1:46 PM
My dad told me if I'm the smartest person in a room, then I'm in the wrong room. For the @rapid7.com Global #Cybersecurity Summit I'll be in the right room as I'll be joined by @rajsamani.bsky.social @racheltobac.bsky.social & @grahamcluley.com for the Keynote Panel.

Join us
rapid7.brighttalk.com
Rapid7 2026 Global Cybersecurity Summit | Virtual Event
Join Rapid7’s 2026 Global Cybersecurity Summit, a two-day virtual event on preemptive security operations, cyber resilience, MDR, and AI-driven defense.
rapid7.brighttalk.com
April 29, 2026 at 12:45 PM
fake captchas (usually leading to clickfix or bunnyloader malware) is one of the most common attacks we see in our incident response data and has been the case basically forever. one of the most recent:
June 20, 2026 at 9:20 AM
I'm speaking at Rapid7's 2026 Global Cybersecurity Summit, May 12-13.

Come hear me chat about how modern attacks actually start, and the reality of running a SOC in 2026 - alongside @racheltobac.bsky.social, @rajsamani.bsky.social, and @brianhonan.bsky.social

rapid7.brighttalk.com?utm_source=r...
Rapid7 2026 Global Cybersecurity Summit | Virtual Event
Join Rapid7’s 2026 Global Cybersecurity Summit, a two-day virtual event on preemptive security operations, cyber resilience, MDR, and AI-driven defense.
rapid7.brighttalk.com
April 14, 2026 at 12:33 PM
here is a deep technical dive into Notepad++ hack, including files that are identified as suspicious www.rapid7.com/blog/post/tr...
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit
Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom.
www.rapid7.com
February 3, 2026 at 9:26 AM
my first ever blogpost for @rapid7.com: a deep-dive into the threat of rogue employees. i explain how they bypass your security measures from screening to onboarding, what they want from your organization after being hired, and what you can do to stop them www.rapid7.com/blog/post/20...
How to Mitigate the Risk of Rogue Employees | Rapid7 Blog
Rapid7 threat researchers & penetration testers are actively observing how malicious actors exploit hiring pipelines to infiltrate businesses. Learn more!
www.rapid7.com
January 21, 2025 at 7:13 PM
And then there were those who simply didn't offer anything in response:

Akamai, Cisco, Cloudflare, CrowdStrike, Deloitte, Dragos, Gen Digital, IBM, Palo Alto Networks, SailPoint, Recorded Future, Arctic Wolf, EY, PWC, Leidos, CyberArk, CommonVault, Varonis, Rapid7, Booz Allen (among others).
April 11, 2025 at 5:03 PM
For folks looking for Notepad++ IoCs, @rapid7.com just dropped a write-up. www.rapid7.com/blog/post/tr...
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit
Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom.
www.rapid7.com
February 2, 2026 at 4:52 PM
Rapid7 has discovered a second PostgreSQL zero-day exploited in the BeyondTrust hack last year.

The initial patch blocks both zero-days, although the second one wasn't publicly known (CVE-2025-1094).

www.rapid7.com/blog/post/20...
CVE-2025-1094: PostgreSQL psql SQL injection (FIXED) | Rapid7 Blog
www.rapid7.com
February 14, 2025 at 2:56 PM
You think ransomware is bad now? Wait until it infects CPUs
You think ransomware is bad now? Wait until it infects CPUs
Rapid7 threat hunter told The Reg wrote a PoC. No he's not releasing it RSAC  If Rapid7's Christiaan Beek decided to change careers and become a ransomware criminal, he knows exactly how he'd innovate: CPU ransomware.…
dlvr.it
May 11, 2025 at 8:27 PM
We now have a (draft) @metasploit-r7.bsky.social exploit module for the recent Fortinet FortiWeb vulns, chaining CVE-2025-64446 (auth bypass) + CVE-2025-58034 (command injection) to achieve unauthenticated RCE with root privileges: github.com/rapid7/metas...
November 21, 2025 at 1:29 PM
wow, wishing the best for all those I know working in Rapid7
August 12, 2026 at 1:48 PM
Stoked to announce I've joined the @rapid7.com team 😀
August 25, 2025 at 8:37 AM
Presenting the top stops of March 🛑

#NHLBruins | @rapid7
April 1, 2026 at 9:58 PM
Microsoft getting ready to SWAT rapid7 and their github account. /s
May 28, 2026 at 1:42 PM
@rapid7.com hey man can you work once like ever? thanks!!!!!!
January 2, 2026 at 4:47 PM
We have business solutions for this. First thing we do is bring in professional services. Crowdstrike, Rapid7, and many others offer audit and forensic capabilities that are "neutral and truthful." Since it appears that security controls were breached, a third party audit team is key.
February 10, 2025 at 5:59 AM
Want my thoughts on Anthropic's Mythos risk vs hype, how I use AI to bypass identity verification systems now, & more?
Tune in for my Rapid7's 2026 Global Cybersecurity Summit keynote panel 5/12 with Graham Cluley, Raj Samani,
Brian Honan!
Join me here: rapid7.brighttalk.com
April 15, 2026 at 3:08 PM
Wise man. I forgot about Rapid7 announcing during Black Hat.
August 3, 2025 at 2:39 PM
our Q1 2025 incident response findings blog is now live!

* most popular initial access vectors
* investigations covered include SEO poisoning cases and exposed RMM tooling
* commonly observed attacker behaviours and targeted orgs
* BunnyLoader. lots of BunnyLoader
Rapid7 Q1 2025 Incident Response Findings | Rapid7 Blog
Rapid7’s 2025Q1 incident response data highlights several key IAV trends, shares salient examples of incidents investigated by the Rapid7 IR team, and digs into threat data by industry as well as some...
www.rapid7.com
June 4, 2025 at 10:23 AM
PSA: If you own that indestructible Brother laser printer that The Wirecutter recommends (or any other Brother printer, scanner, all-in-one, or label maker), today is a great day to update its firmware and change the default admin password.

www.rapid7.com/blog/post/mu...
Rapid7
Rapid7 conducted a zero-day research project into multifunction printers (MFP) from Brother Industries, Ltd. — discovering 8 new vulnerabilities. Learn more!
www.rapid7.com
June 27, 2025 at 2:04 PM