#rapid7
8 articles
From April to August 2026, ZCyberNews published 19 articles tagged rapid7, covering high and critical severity vulnerabilities across enterprise, financial services, government, technology, and banking sectors globally, with specific reports from Egypt, Europe, Kenya, and Nigeria. Threat actors ClickFix, KongTuke, and Kyber were observed in these campaigns. Key vulnerabilities included CVE-2026-20127, CVE-2026-20182, CVE-2025-59718, CVE-2026-41940, and CVE-2023-30253. Coverage comprised four high, four critical, and five informational reports, detailing exploits and remediation guidance for affected organizations.

Africa's Cyber Challenge: Skills Gap Outweighs Tech Access
Rapid7 expands StarLink partnership across Egypt, Nigeria, South Africa, Kenya, but warns more tech won't fix security ops — teams lack time, context, and specialist capacity.
HIGHExposed WebDAV Malware Lab Reveals AI-Driven Delivery Pipeline
Rapid7 MDR found an exposed server with 1,048 artifacts — LNK lures, WebDAV scripts, CVE-2025-33053 tests — revealing attackers using generative AI to systematize malware delivery.
HIGHMetasploit Adds Vim Plugin Persistence, Exploits for Three CVEs
Rapid7's Metasploit Framework adds Vim plugin persistence, exploits for CVE-2025-6793 (Marvell QConvergeConsole), CVE-2024-48760 (GestioIP), and CVE-2023-30253 (Dolibarr).
CRITICALCisco Catalyst SD-WAN Controller Flaw CVE-2026-20182 Scores Perfect
Rapid7 discovered CVE-2026-20182, a 10.0-CVSS authentication bypass in Cisco Catalyst SD-WAN Controller. Unauthenticated attackers can inject SSH keys and issue NETCONF commands.
CRITICALModeloRAT Campaign Abuses Microsoft Teams for Enterprise Intrusion
Rapid7 dissects an April 2026 intrusion where a fake IT Support Teams message delivered ModeloRAT via Dropbox, leading to privilege escalation, credential theft, and lateral...
CRITICALcPanel & WHM Authentication Bypass CVE-2026-41940: CVSS 9.8
CVE-2026-41940: Unauthenticated remote attackers can bypass authentication in cPanel & WHM and WP Squared. CVSS 9.8. Patch released April 28, 2026.
CRITICALFortiGate SSO Bypass CVE-2025-59718 Exploited in Active Attacks
Rapid7 IR confirms active exploitation of CVE-2025-59718 — a 9.8-CVSS FortiGate SSO bypass — enabling attackers to gain persistent admin access on unpatched appliances.
HIGHKyber Ransomware Deploys Dual Payloads for Windows and VMware ESXi
Kyber ransomware deploys two distinct payloads to encrypt both Windows systems and VMware ESXi servers, using a custom tool to wipe ESXi snapshots and hinder recovery. The attack chain begins with compromised RDP credentials.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.