Rapid7のMetasploit Frameworkに、 PaperCut MFおよびPaperCut NGに影響を与える、現在悪用されている一連の脆弱性を標的とするエクスプロイトモジュールが追加される予定です。この追加により、印刷管理サーバーに関わるセキュリテ...
提案されているモジュールは、攻撃者が脆弱なPaperCutアプリケーションサーバー上でリモートコード実行を実現するために悪用できる2つの脆弱性、CVE-2026-81578とCVE-2026-82078を対象としています。
Rapid7のMetasploit Frameworkに、 PaperCut MFおよびPaperCut NGに影響を与える、現在悪用されている一連の脆弱性を標的とするエクスプロイトモジュールが追加される予定です。この追加により、印刷管理サーバーに関わるセキュリテ...
提案されているモジュールは、攻撃者が脆弱なPaperCutアプリケーションサーバー上でリモートコード実行を実現するために悪用できる2つの脆弱性、CVE-2026-81578とCVE-2026-82078を対象としています。
CVE ID : CVE-2026-97228
Published : Sept. 25, 2026, 10:25 a.m. | 34 minutes ago
Description : Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injecti...
CVE ID : CVE-2026-97228
Published : Sept. 25, 2026, 10:25 a.m. | 34 minutes ago
Description : Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injecti...
📊 2.7/10
🏢 Rapid7
📝 Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86930
#cybersecurity #infosec #cve #euvd
📊 2.7/10
🏢 Rapid7
📝 Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86930
#cybersecurity #infosec #cve #euvd
An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Wi...
https://www.thehackerwire.com/vulnerability/CVE-2026-89325/
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Wi...
https://www.thehackerwire.com/vulnerability/CVE-2026-89325/
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
📊 7.8/10
🏢 Rapid7
📝 An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbit...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86404
#cybersecurity #infosec #cve #euvd
📊 7.8/10
🏢 Rapid7
📝 An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbit...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86404
#cybersecurity #infosec #cve #euvd
📊 3.6/10
🏢 Rapid7
📝 Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85881
#cybersecurity #infosec #cve #euvd
📊 3.6/10
🏢 Rapid7
📝 Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85881
#cybersecurity #infosec #cve #euvd
📊 6.5/10
🏢 Rapid7
📝 Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85882
#cybersecurity #infosec #cve #euvd
📊 6.5/10
🏢 Rapid7
📝 Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85882
#cybersecurity #infosec #cve #euvd
📊 9.9/10
🏢 Rapid7
📝 Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the f...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85870
#cybersecurity #infosec #cve #euvd
📊 9.9/10
🏢 Rapid7
📝 Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the f...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85870
#cybersecurity #infosec #cve #euvd
In Velociraptor, a user with the investigator role can change an internal setting that lets them run any query on the server, bypassing normal permission checks. This means…
Too many irrelevant or confusing CVEs? Use stackflag.com
#velociraptor #rapid7 #CVE #infosec
In Velociraptor, a user with the investigator role can change an internal setting that lets them run any query on the server, bypassing normal permission checks. This means…
Too many irrelevant or confusing CVEs? Use stackflag.com
#velociraptor #rapid7 #CVE #infosec
Attackers who'd already breached the servers recompiled HAProxy with a hidden backdoor, because a healthy-looking load balancer draws less suspicion.
Read more: www.haproxy.com/blog/how-to-...
Attackers who'd already breached the servers recompiled HAProxy with a hidden backdoor, because a healthy-looking load balancer draws less suspicion.
Read more: www.haproxy.com/blog/how-to-...
CVE-2026-19490(CVSSスコア9.3)として追跡されているこの重大なバグは、代替パスを使用した認証バイパスとして説明されており、ゲートウェイ(SSL VPN、ICAプロキシ、CVPN、RDPプロキシ)またはAAA仮想サーバーとして構成されたNetScalerアプライアンスに影響を与えます。
サイバーセキュリティ企業のRapid7によると、この脆弱性は、ユーザーの操作なしに、遠隔地の認証されていない攻撃者によって悪用される可能性があるという。
Citrixの勧告によると...
CVE-2026-19490(CVSSスコア9.3)として追跡されているこの重大なバグは、代替パスを使用した認証バイパスとして説明されており、ゲートウェイ(SSL VPN、ICAプロキシ、CVPN、RDPプロキシ)またはAAA仮想サーバーとして構成されたNetScalerアプライアンスに影響を与えます。
サイバーセキュリティ企業のRapid7によると、この脆弱性は、ユーザーの操作なしに、遠隔地の認証されていない攻撃者によって悪用される可能性があるという。
Citrixの勧告によると...
📰: https://bit.ly/4h07Ibg
#NHLBruins | @rapid7
📰: https://bit.ly/4h07Ibg
#NHLBruins | @rapid7
More Day 1 reaction ➡️ https://bit.ly/4yABkBK
#NHLBruins | @rapid7
More Day 1 reaction ➡️ https://bit.ly/4yABkBK
#NHLBruins | @rapid7
https://www.stocktitan.net/news/RPD/rapid7-reports-inducement-grants-under-nasdaq-listing-rule-5635-c-bfeglvwcq5h3.html?utm_source=stocktitan-bluesky&utm_medium=social
https://www.stocktitan.net/news/RPD/rapid7-reports-inducement-grants-under-nasdaq-listing-rule-5635-c-bfeglvwcq5h3.html?utm_source=stocktitan-bluesky&utm_medium=social
The strongest version of this narrative is that the cybersecurity industry is maturing; moving from "checkbox security" (having the tool) to "outcome security" (reducing actual risk). By integrating e…
The strongest version of this narrative is that the cybersecurity industry is maturing; moving from "checkbox security" (having the tool) to "outcome security" (reducing actual risk). By integrating e…
Rapid7 emphasized its product strategy during the Piper Sandler conference. The company is focusing on a turna…
https://newsstocks.live/news/rapid7-product-push-highlights-turnaround-at-piper-sandler-conference #Finance #Markets
Rapid7 emphasized its product strategy during the Piper Sandler conference. The company is focusing on a turna…
https://newsstocks.live/news/rapid7-product-push-highlights-turnaround-at-piper-sandler-conference #Finance #Markets
Duration: 31m.
Duration: 31m.
"Command Platform Dashboard Degradition"
Affects: User Interface, User Interface
Live timeline → https://pingoru.io/providers/rapid7/incidents/11061348
#Rapid7 #Rapid7Down
"Command Platform Dashboard Degradition"
Affects: User Interface, User Interface
Live timeline → https://pingoru.io/providers/rapid7/incidents/11061348
#Rapid7 #Rapid7Down
韓国の自動車・メディア企業を狙った巧妙な攻撃により、あるスパイ活動グループが被害者のネットワークへのアクセスを獲得していたことが判明しました。一部のケースでは、2025年初頭からアクセスが継続していたとみられています。Rapid7が今週公開した分析によると、同社はこの攻撃を北朝鮮の高度持続的脅威(APT)グループによる
韓国の自動車・メディア企業を狙った巧妙な攻撃により、あるスパイ活動グループが被害者のネットワークへのアクセスを獲得していたことが判明しました。一部のケースでは、2025年初頭からアクセスが継続していたとみられています。Rapid7が今週公開した分析によると、同社はこの攻撃を北朝鮮の高度持続的脅威(APT)グループによる