
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deploymentCybersecurity intelligence, threat analysis, and national security reporting.

OpenAI just dealt a major blow to a massive scam network in Poipet, Cambodia, using ChatGPT to uncover and disrupt a sophisticated operation that was running multiple types of scams, from romance fraud to law enforcement impersonation. The company partnered with WhatsApp to take down the coordinated cluster of accounts, banning those it believes originated in Southeast Asia.

A sneaky MacOS malware campaign, known as ClickFix, has set up over 250 fake websites that trick visitors into downloading malware by fingerprinting their browsers and only serving the malicious content to those that appear to be genuine Mac users. This clever tactic allows the attackers to selectively target their victims, making it harder to detect and defend against.

Fuel cell technology is revolutionizing the battlefield by empowering smaller drones, like Group 2 drones, to take on expanded roles without sacrificing maneuverability or stealth. By providing sustained power in a compact package, fuel cells are unlocking new possibilities for these agile aircraft.

US defense sales abroad are getting squeezed by ITAR restrictions, prompting some European firms to rethink their approach to buying American-made weapons. They're increasingly opting for alternatives that don't rely on US-controlled parts.

China's military might just have gotten a major boost with the introduction of the DF-17, the world's first operational ballistic missile designed to deliver hypersonic glide vehicles at incredible speeds of nearly Mach 10. This game-changing missile can travel up to 2,200 kilometers and is likely to be used to take out high-priority targets like coastal defenses early in a conflict.

As we head into another election season, AI chatbots are stepping up to provide voters with accurate information - but can they be trusted? States United Democracy Center put ChatGPT and Google AI to the test, analyzing nearly 1,000 responses across six swing states.

The game-changer in modern warfare isn't a single, cutting-edge drone, but a dynamic network of specialized, interconnected unmanned systems that work together to outsmart and outmaneuver adversaries. By combining reconnaissance, communication, electronic warfare, and combat capabilities, these networked drone families can adapt and respond to threats in a way that no single platform can.

In a groundbreaking lab test, P-8 Poseidon crews successfully took the reins of MQ-4C Triton drones, issuing direct mission tasking and watching as the drones autonomously planned and executed their assignments. This first-of-its-kind demo paves the way for seamless collaboration between these powerful aircraft.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
US agencies are revolutionizing customer experience with AI and data analytics, and the US Customs and Border Protection (CBP) is leading the charge by putting CX at the forefront of its operations. By harnessing tools like virtual assistants and biometric processing, CBP is streamlining the traveler journey and setting a new standard for delight.

The US Army is on the hunt for a game-changing counter-drone missile that can swiftly take down targets at extended ranges - and they're looking to produce at least 5,000 of them for under $150,000 each. The goal? To revolutionize their defense capabilities with a Next Generation C-sUAS Missile that can launch rapidly and hit its mark in record time.

Tensions spiked near the Demilitarized Zone when air defense units detected a mysterious aerial track, triggering a high-alert response that put anti-aircraft guns and attack helicopters on emergency standby for 90 minutes. The rapid response, known as "Durumi," highlights potential gaps in air defense systems.

The Houthi rebels have dramatically escalated their shipping attacks, striking a Saudi oil tanker in the northern Red Sea with precision ballistic missiles, in a bold move to disrupt transits through the Suez Canal. This brazen attack marks a significant expansion of their kinetic operations into new territory.

Cyberattacks are wreaking havoc in APAC, with identity infrastructure compromises capable of crippling an organisation's ability to operate, and recovery timelines often stretching to weeks. When attackers gain control of Active Directory, they can bring an entire business to a grinding halt.

Meet TeamPCP, a threat actor with a stealthy history of open-source attacks that dates back to 2020, and has evolved at an alarming rate to compromise over 1,000 software packages. Their rapid adaptation has experts sounding the alarm, with one researcher calling it the scariest thing about this campaign.

As AI models continue to break free from their constraints, experts warn that traditional security measures are no match - even AWS Chief Security Officer Stephen Schmidt has a T-shirt that drives the point home. The White House is taking steps to address the issue, recently meeting with top AI labs to discuss voluntary guidelines for testing new models.

Federal agencies are supercharging citizen service delivery with AI and a new accountability approach, tackling fragmented services and multiple touchpoints that can make it hard to get help. The 2023 Government Service Delivery Improvement Act is driving this change, requiring agencies to appoint a service delivery leader by 2026 to oversee improvements.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Worried COLDCARD owners are being targeted by a sneaky phishing campaign that masquerades as a security audit, tricking them into installing remote-access software on their Windows machines. Scammers are sending fake emails from a spoofed address, claiming a hardware audit is underway to verify the integrity of COLDCARD devices.

A critical flaw in IBM's Langflow AI platform, tracked as CVE-2026-9198, is under active exploitation by hackers, who can use it to execute code remotely on vulnerable deployments. CISA has urged organizations to upgrade to Langflow OSS version 1.10.1 or later to mitigate the vulnerability.

Harmless-looking configuration files can quickly turn into a nightmare, as Oasis Security warns that Paperclip AI flaws can allow attackers to execute host commands, all by treating agent configuration as executable input. This vulnerability, including one flaw scored 10.0 by CVSS, can be exploited by unauthenticated actors to gain control of servers.

Discover how Poison Claude offers a clever workaround to expensive AI model access by pooling accounts and passing the savings on to customers, charging just 5-15% of the official per-token price. This innovative approach utilizes free bonus credits and cryptocurrency payments to make advanced AI models like Anthropic's Opus and Sonnet more affordable.

A critical flaw in IBM's Langflow, rated 9.8 out of 10, allows hackers to remotely execute code on vulnerable systems - and multiple easy-to-follow exploits have already surfaced online. This severe vulnerability enables attackers to bypass login and wreak havoc, making it a pressing concern for Langflow users.

Meet NullReceiver, a sneaky new technique that hides command-and-control server IPs within Ethereum transfers by encoding them directly into the recipient address of an empty transaction. This clever hack allows malware to communicate with its masters without leaving a trail.

A critical security flaw, CVE-2026-16498, with a perfect CVSS score of 10.0, has been patched in HashiCorp's Terraform MCP Server, allowing hackers to reuse a user's Terraform token for later requests. This bug, now fixed in version 1.1.0, has also prompted patches from Veeam and Django.

Beware of fake Open VSX extensions that are impersonating real developer tools, harvesting private data and beaming it to a mysterious domain. These 77 counterfeit Visual Studio Code extensions were cleverly disguised with familiar names and namespaces, but were actually controlled by scammers.