Palo Alto VPN Bug Sees Active Exploitation

Security experts at Rapid7 have confirmed that hackers are actively exploiting a critical authentication bypass flaw in Palo Alto Networks' VPN, putting PAN-OS users at risk of targeted attacks. This urgent development means users must patch their systems ASAP to prevent exploitation.

https://osintsights.com/palo-alto-vpn-bug-sees-active-exploitation?utm_source=mastodon&utm_medium=social

#PaloAlto #Vpn #AuthenticationBypass #Panos #Rapid7

Palo Alto VPN Bug Sees Active Exploitation

Palo Alto VPN bug under active exploitation, learn how to protect your network now with emergency patching for PAN-OS users and prevent authentication bypass attacks today.

OSINTSights
Patch Tuesday, May 2026 Edition – Krebs on Security

#Rapid7 published some analysis of #malware likely dropped through the Notepad++ issue.
One of the loaders used by the malware is built with #Microsoft Warbird, a kernel-level code protection framework used by Windows. @cirosec blogged about how this framework could be abused a while back and also published a PoC on GitHub.
I'm one of the authors of that research. We included some thoughts on detection in the article but if there's any further questions about the technique or anything, ask away :)

#notepad #chrysalis #ioc #apt #warbird

The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit

Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom.

Rapid7
Patch Tuesday, January 2026 Edition – Krebs on Security

CVE Alert: CVE-2025-6264 - Rapid7 - Velociraptor - RedPacket Security

Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated

RedPacket Security

🚨 Crimson Collective hackers exploit AWS IAM keys to steal data, modify RDS passwords, and exfiltrate S3 snapshots.

The same group claims the Red Hat breach (570GB data theft) — partnering with Scattered Lapsus$ Hunters to raise extortion stakes.

🧩 Tool used: TruffleHog
🧠 TTPs: Long-term IAM compromise → privilege escalation → API-based exfiltration
💬 What detection logic would you apply to flag these IAM anomalies?

Follow @technadu for continuous threat intelligence and AWS security insights.

#AWS #InfoSec #CyberSecurity #CrimsonCollective #CloudSecurity #ThreatIntel #RedHat #Rapid7 #DataBreach #CyberThreats #TechNadu #AWSBreach

«Швейцарский нож» хакера: как появился и устарел (?) Metasploit Framework

В прошлой статье мы рассказывали о HD Moore — хакере, который подарил миру фреймворк, навсегда изменивший практику пентестов. Теперь на очереди сам Metasploit: в прошлом — настоящий «швейцарский нож» пентестера, ныне — скорее вспомогательный инструмент с отдельными рабочими лезвиями. Чем был Metasploit для индустрии в нулевые, что представляет из себя сейчас, и почему пентестеры продолжают использовать его даже спустя двадцать лет? Разбираем историю эволюции легендарного фреймворка, которому в этом июле исполняется 22 года.

https://habr.com/ru/companies/bastion/articles/930906/

#metasploit_framework #история_Metasploit #инструменты_пентестера #пентест #redteam #rapid7 #hd_moore #джеймс_мур #история_ибиндустрии #как_появился_Metasploit

«Швейцарский нож» хакера: как появился и устарел (?) Metasploit Framework

В прошлой статье мы рассказывали о HD Moore — хакере, который подарил миру фреймворк, навсегда изменивший практику пентестов. Теперь на очереди сам Metasploit: в прошлом — настоящий «швейцарский...

Хабр
Microsoft Fix Targets Attacks on SharePoint Zero-Day - On Sunday, July 20, Microsoft Corp. issued an emergency security update for a vuln... https://krebsonsecurity.com/2025/07/microsoft-fix-targets-attacks-on-sharepoint-zero-day/ #cybersecurity&infrastructuresecurityagency #sharepointserver #latestwarnings #thecomingstorm #cve-2025-49704 #cve-2025-49706 #cve-2025-53770 #cve-2025-53771 #microsoftcorp. #timetopatch #eyesecurity #rapid7 #cisa
Microsoft Fix Targets Attacks on SharePoint Zero-Day – Krebs on Security

Patch Tuesday, June 2025 Edition – Krebs on Security

Patch Tuesday, June 2025 Edition – Krebs on Security