search
Rapid7
Trends
- 1New BPFDoor variant hides as mail traffic on telecom edge devicesโA new BPFDoor backdoor variant and the AVERAT implant hide on telecom edge devices by posing as mail traffic. See how th
Security researchers at Rapid7 have detailed a new variant of the BPFDoor backdoor and a related implant called AVERAT that operate on Linux-based telecom network edge devices. The malware disguises its command traffic as ordinary email, making it hard to detect, and is linked to an operations-relay infrastructure. Researchers have published guidance on how organisations can hunt for infections.
- 2Moderate vulnerability disclosed in Rapid7's Velociraptorโ๐จ EUVD-2026-92536 ๐ Score: 5.5/10 (CVSS v3.1) ๐ฆ Product: Velociraptor ๐ข Vendor: Rapid7 ๐ Updated: 2026-10-05 ๐ Velocirap
A vulnerability tracked as EUVD-2026-92536 has been documented in Velociraptor, the endpoint monitoring and forensics tool owned by Rapid7. The flaw carries a CVSS v3.1 score of 5.5, a moderate severity rating. Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints, and these artifacts can be used to do essentially anything on a system, typically running with elevated privileges, which is why the disclosure is drawing attention from the security community.
- 3Critical Cisco SD-WAN Manager Vulnerability Under Active Exploitationโ(rapid7.com) Critical API Authentication Bypass in Cisco Catalyst SD-WAN Manager (CVE-2026-76504) Under Active Exploitat
Rapid7 reports a critical API authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-76504, that is being actively exploited in the wild. The flaw lets attackers bypass authentication on the network management platform, prompting security teams to review patching and mitigation guidance for affected deployments.