
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Think a routine dependency update is harmless? The recent npm malware attack—where phishers stole maintainer tokens to publish malicious versions of five popular packages—proves supply-chain trust can be shattered and why maintainers, consumers, and registries must act now to enforce 2FA, rotate tokens, and verify publish provenance.

LameHug is a new AI-augmented malware that adapts, hides, and strikes Windows systems—showing how attackers are using machine learning to make threats smarter and harder to stop. Stay informed and harden defenses now: patch systems, use behavioral detection, and share threat intel to stay a step ahead.

The discovery of AI-generated Lcryx ransomware hidden in a long-running cryptomining botnet shows attackers are marrying covert resource theft with adaptive extortion—pushing organizations and individuals to rethink defenses as malware becomes faster, smarter, and harder to stop.

AI-generated ransomware is reshaping cybercrime—combining adaptive, stealthy malware with cryptomining botnets to create faster, more profitable attacks. Learn why this shift matters and what practical steps organizations and users can take now to reduce risk.

Malware-as-a-Service is turning trusted platforms like GitHub into convenient delivery channels for threats like the Amadey botnet, letting even novice attackers rent powerful tools and hide payloads in seemingly legitimate repos. Learn how to spot risky repos, lock down CI and developer workflows, and keep collaboration safe without stifling innovation.

Malware-as-a-Service is now using GitHub to quietly deliver Amadey payloads, turning trusted code into attack paths—now’s the time for teams to harden supply-chain checks, vet dependencies, and lock down CI/CD pipelines.

A new ZuRu malware strain is quietly targeting macOS developer machines and toolchains, putting builds, secrets, and the entire software supply chain at risk. Harden workstations, isolate builds, and secure credentials now to prevent a single compromised device from triggering a widespread breach.

Ransomware attacks now fuel nearly half of all manufacturing cyber breaches in 2024, threatening not just production lines but national security and global supply chains. Discover why this surge puts the backbone of our economy on high alert—and what it means for the future of manufacturing.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
“How safe are our personal and corporate data in an age where digital extortion has become a pervasive threat?” This question gains urgency as British authorities announced the arrest of…

A new wave of cyberattacks using the sophisticated SquidLoader malware is putting Hong Kong’s financial sector on high alert, threatening to shake the very foundation of global finance with stealthy breaches and data theft.

Ransomware attacks on global retailers skyrocketed 58% in Q2 2025, spotlighting a growing cyber threat that’s shaking checkout lines and boardrooms alike—especially across the UK. Is your favorite store ready to fight back?

Think your apps are safe? Think again—Konfety’s new malware twist uses sneaky “evil twin” apps to outsmart detection and secretly steal your data while flying under the radar.

North Korean hackers have taken their game to a new level, sneaking a dangerous malware loader into the trusted npm registry—putting thousands of developers and organizations at risk without them even knowing it. Stay ahead of the threat that’s shaking the very foundation of software supply chains worldwide.

Think twice before downloading that interview prep package—North Korean hackers are stealthily slipping dangerous malware into popular npm tools, turning trusted resources into digital traps for developers worldwide.

North Korean hackers are stealthily spreading a new malware loader through popular npm packages, putting thousands of developers and organizations at risk in a chilling reminder that our digital supply chains are only as secure as their weakest link.

A cunning new malware called HazyBeacon is using AWS Lambda to slip past defenses and steal sensitive data from Southeast Asian governments, revealing a dangerous new frontier in cloud-based cyberattacks.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
When a powerful open-source tool like AsyncRAT falls into the wrong hands, it can quickly transform from a helpful remote admin app into a global malware menace—fueling a surge of cyberattacks that threaten industries worldwide.

What started as an open-source learning tool has turned into a global cyber threat, as AsyncRAT’s freely available code fuels a growing wave of malware attacks targeting everything from personal devices to critical infrastructure.

North Korean hackers have unleashed a new wave of malware on the npm registry, cleverly hiding malicious code in popular JavaScript packages and putting millions of developers at risk—can we still trust the tools that power our software?

A new PHP-based RAT is shaking up cybersecurity by sneaking into web servers through a clever FileFix delivery system—posing a serious challenge for industries used to defending against traditional Windows threats.

Interlock ransomware just leveled up—deploying a stealthy new Remote Access Trojan that lets attackers silently steal data and move through networks undetected. It’s a wake-up call for everyone to rethink cybersecurity before it’s too late.

With cyberattacks on the rise, stealthy info-stealer malware and savvy phishing kits are quietly stealing your digital identity—making strong, adaptive security more crucial than ever.

A Russian basketball player’s unexpected arrest in France for alleged ransomware negotiations blurs the lines between sports and cybercrime, raising intriguing questions about the hidden players in today’s digital battles.

With cybercriminals increasingly targeting MOVEit Transfer, it’s time to ask: how safe is the sensitive data you trust to these platforms? Discover why rising scans could signal a looming wave of cyber threats and what that means for your security.