Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Read the full story on Rapid7 BlogHave you worked with this?
The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.
More from Rapid7
Recent updates from Rapid7, so you can tell whether this is a one-off or part of a pattern.
When Business Email Compromise Starts Rewriting Reality
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets. This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details…
How dynamic application security testing validates risk at runtime
Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it? Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them. The IDC…
CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM
Overview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted…
More in Security
What other companies in Security are doing. The category page shows who’s active, side by side.
Threat Actors Use Google Ads To Target Ledger Users
In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…
Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right
Cyber Asset Attack Surface Management (CAASM) solved a significant problem. Security teams can now say with confidence what they own. But, two things separate a CAASM tool that stops there from one that actually moves the needle on risk. The first is what the inventory itself carries. The second is what it connects to. 1. An inventory needs to do more than list what exists A list of assets is…
Agents can now set up your website’s security with Turnstile Spin
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.
Darktrace / SECURE AI: Behavioral Security for the AI enterprise
Discover how Darktrace / SECURE AI applies behavioral security to AI usage, prompts, agents, and development to help organizations adopt AI securely.


