
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Imagine a research preview that can teach itself to find and exploit the very flaws security teams scramble to patch - that's now a harsh reality, as an advanced language model has autonomously discovered and exploited zero-day vulnerabilities in every major operating system and browser. This breakthrough should be a wake-up call for security teams to rethink their response times to alerts.

The FBI has successfully dismantled a massive phishing operation built around the notorious W3LL phishing kit, which was linked to a staggering $20 million in fraud attempts. By taking down this operation, the bureau has disrupted a key tool used by cybercriminals to carry out their scams.

North Korean hackers APT37 have cleverly turned Facebook friend requests into a sneaky way to deliver RokRAT malware, exploiting our natural tendency to trust social connections. By accepting a friend request, victims unwittingly open the door to a remote access trojan that can compromise their device.

Kaspersky's Global Research and Analysis Team has uncovered a sophisticated malware campaign, dubbed JanelaRAT, that's specifically targeting users in Latin America with financial threats. This evolved malware has been detailed in a recent report, revealing its updated functionality and infection chain.

A single click can be costly: over 20,000 crypto users across three countries fell victim to a $12 million approval phishing scam, tricked into handing over full access to their wallets. Thankfully, authorities swooped in, seizing the lost funds in a major cross-border crackdown dubbed Operation Atlantic.

A critical vulnerability in Marimo is being actively exploited by attackers to steal sensitive credentials, and it requires no prior authentication to run code remotely. This flaw has severe consequences for organizations using Marimo, making it essential to take immediate action.

For one day in April, unsuspecting users who visited CPUID.com, a trusted site for hardware-monitoring tools, unknowingly downloaded trojanized software that deployed a malicious remote access trojan called STX RAT. The compromised software, including CPU-Z and HWMonitor, turned a trusted resource into a malware delivery vehicle.

In a chilling 2TB data heist, the Anubis ransomware gang has struck Signature Healthcare in Massachusetts, stealing sensitive patient information despite claiming they didn't encrypt the hospital's systems. As the healthcare system scrambles to cope, patients are feeling the impact, with ambulance patients being diverted and clinicians forced to go old-school with paper records.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Thousands of US industrial devices, including programmable logic controllers made by Rockwell Automation, have been targeted by Iranian-linked hackers, raising concerns about the vulnerability of critical infrastructure networks. This cyber campaign highlights the alarming risk to the networks we rely on every day.

For six hours, unsuspecting visitors to the CPUID website were put at risk of having their passwords stolen when malicious malware was served in place of the HWMonitor tool they were trying to download. This alarming security breach highlights the vulnerability even trusted sites can have, leaving users to wonder if their sensitive information is safe.
Alarming new data from cybersecurity firm Check Point reveals that just three ransomware gangs - Qilin, Akira, and Dragonforce - accounted for a staggering 40% of all ransomware incidents in March, with a whopping 269 attacks attributed to these groups alone. This concentration of power raises serious concerns about the growing threat of ransomware attacks.

Beware of payroll pirate attacks: a financially motivated threat actor has been hijacking Canadian employees' accounts to steal their salary payments, leaving them with a nasty surprise on payday. Microsoft is sounding the alarm on this emerging threat, dubbed Storm-2755.

A widely used WordPress plugin, Smart Slider 3 Pro, was compromised when hackers hijacked its update system to push a poisoned version containing a backdoor, putting over 800,000 active installations at risk. This alarming breach raises critical questions about trust and security in the mechanisms we rely on to protect our online presence.

As AI tools become more advanced, experts warn that they can also supercharge healthcare cyber threats, autonomously identifying and exploiting software flaws at unprecedented speeds. This could lead to a dramatic surge in attacks on hospitals, clinics, and patients, making the threat landscape more treacherous than ever.

In a major cyber crackdown, German police have unmasked the leader of the notorious REvil gang, dealing a significant blow to the ransomware group, but also highlighting the ever-shifting threat landscape. As one threat subsides, new ones emerge, leaving defenders to prioritize scarce resources against an array of evolving threats.

A sneaky new malware called LucidRook has set its sights on non-governmental organizations and universities in Taiwan, using spear-phishing to catch its victims off guard. This Lua-based threat is the latest cyber attacker to target these vulnerable sectors.

Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
A new phishing-as-a-service platform called VENOM is making it alarmingly easy for hackers to target senior executives, specifically seeking their Microsoft logins. This compact toolkit is putting the keys to the corner office within reach of any motivated adversary, leaving security teams scrambling to respond.

A security flaw in the EngageLab SDK has put a whopping 50 million Android users at risk, allowing apps on the same device to bypass Android's security sandbox and gain unauthorized access to sensitive information. This vulnerability, now patched, exposed cryptocurrency wallet users and others to potential data breaches.

A ransomware attack on Dutch healthcare IT firm ChipSoft has left patients and clinicians scrambling, as clinical portals and scheduling tools went dark, disrupting critical care management systems. The devastating cyber incident forced ChipSoft to take its website and digital services offline, leaving many wondering who's left holding the chart.

In a major breakthrough, law enforcement agencies in the US, UK, and Canada joined forces to disrupt a massive $45 million global cryptocurrency scam, freezing $12 million in stolen funds and identifying over 20,000 linked wallet addresses. This significant action not only recovered funds for victims but also shed light on the darker side of digital cash and the challenges of accountability in the crypto world.

The game has changed: a new AI model called Mythos can now uncover devastating zero-day flaws in software and chain them together to create powerful exploits, putting this potent capability in the hands of anyone with an internet connection. This development blurs the lines between nation-state hackers and amateur cyber attackers, raising urgent questions about the future of cybersecurity.

Beware of the person on the other end of the line - a new phishing gang is impersonating IT helpdesks to scam dozens of major corporations, leaving investigators racing to keep up. Google is sounding the alarm on this latest extortion tactic, which uses clever social engineering to catch victims off guard.

A mysterious threat cluster, UAT-10362, has launched a targeted spear-phishing attack on Taiwanese NGOs and universities, deploying a newly discovered malware called LucidRook. This sophisticated attack raises urgent concerns for Taiwanese civil-society groups, highlighting the need for heightened vigilance and robust defenses.
Meet STX RAT, a sneaky new remote access trojan that's got its sights set on the finance sector, using advanced stealth methods and command-and-control capabilities to evade detection. This latest threat is a wake-up call for defenders, testing their readiness to respond to increasingly sophisticated attacks.