Archive for Rapid7

Rapid7’s Q2 2026 threat report is out… And it’s bad

Posted in Commentary with tags on August 18, 2026 by itnerd

Rapid7’s Q2 2026 threat report found that critical vulnerability disclosures doubled year-over-year, yet only 25 of the 40 exploited flaws needed zero credentials or user interaction to break in. The report’s takeaway: CVSS score matters less than actual exposure, and defenders can’t patch their way out of the gap.

Anders Askåsen, SVP of Strategy and Marketing, Radiant Logic

“25 of the 40 exploited vulnerabilities last quarter needed no credentials at all. So the break-in is cheap. What costs you is what the attacker inherits once inside: the service accounts on that host, the tokens it holds, the systems those entitlements reach. The truth is that exposure matters more than CVSS score. But exposure is not just where a flaw sits in the network. It is what the identities on that machine can do next. And with AI agents now getting credentials faster than most JML processes from your favorite IGA tool were built to handle, very few teams can answer that question.”

Justin Beals, CEO & Founder, Strike Graph 

“Rapid7’s numbers confirm what a lot of security leaders have felt but couldn’t prove. Disclosures of high and critical vulnerabilities doubled year over year, but exploited vulnerabilities only grew 8 percent. That gap is the real story. Discovery isn’t the bottleneck anymore, exposure is. For years we scored risk by CVSS and hoped patch windows would catch up. That math never worked, and now AI has widened the gap between disclosure and exploitation faster than a monthly cycle can track. The rise in what Rapid7 calls ‘Holy Grail’ vulnerabilities, the ones that need no credentials and no user interaction, is the part that should worry people most. Those are the flaws that turn a scanner hit into an active breach with nobody doing anything wrong. Teams that keep triaging by severity score alone are going to keep losing this race. The ones who survive will map exposure first, what’s actually reachable, what’s actually exploitable, and treat that as a picture that updates continuously instead of a report that lands once a quarter. A patch cycle built for a slower world isn’t built for this one.”

Expect disclosures and vulnerabilities to increase further as time goes on. That is my take away. That means that patching you way out of this at scale is not an option. Defenders will have to find other ways to deal with this situation. And fast.

New SharePoint auth bypass already being exploited hours after PoC went public

Posted in Commentary with tags on August 12, 2026 by itnerd

Rapid7 published a proof-of-concept exploit today for CVE-2026-55040, an authentication bypass in SharePoint’s JWT token validation that lets an attacker impersonate any user or admin without credentials. Threat intel firm Defused reported the exploit code was already hitting its honeypots the same day; it’s the second distinct on-prem SharePoint flaw to make news this week, after Monday’s ransomware-exploited deserialization bug.

More info here: CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

Roman Sannikov, Global Research Coordinator, iCOUNTER said this:

“Microsoft patched CVE-2026-55040 in July. Rapid7 published a full technical write-up and working exploit code today, and Defused was already seeing that exact code hit its honeypots the same day. Hours passed between a researcher publishing proof-of-concept code and someone using it against real targets. No group has been identified yet, which tracks, at this stage it’s likely opportunistic scanning off the public PoC rather than a targeted campaign. This is exactly the kind of flaw that matters more as companies move away from plain passwords. CVE-2026-55040 breaks the token validation that’s supposed to replace passwords in the first place, and we’re seeing threat actors go after tokens and other forms of MFA directly instead of trying to phish or guess a credential. The bigger pattern is worth focusing reporting on: this is the second separate on-prem SharePoint flaw in the news this week. The story now is how many separate ways into the same platform are surfacing at once.”

This is fixed and people should update all the things. That would mitigate this issue completely. Otherwise pwnage will be guaranteed.

Hundreds Of Brother Printer Models Along With Some From Other Vendors At Risk Of Pwnage

Posted in Commentary with tags on July 1, 2025 by itnerd

 Rapid7 has discovered eight vulnerabilities affecting 689 Brother printers. But 46 models from other brands are also at risk of being pwned including models from Fujifilm, Toshiba, Ricoh, and Konica Minolta. You can read the details here, but here’s the TL:DR:

Rapid7 conducted a zero-day research project into multifunction printers (MFP) from Brother Industries, Ltd. This research resulted in the discovery of 8 new vulnerabilities. Some or all of these vulnerabilities have been identified as affecting 689 models across Brother’s range of printer, scanner, and label maker devices. Additionally, 46 printer models from FUJIFILM Business Innovation, 5 printer models from Ricoh, 2 printer models from Toshiba Tec Corporation, and 6 models from Konica Minolta, Inc. are affected by some or all of these vulnerabilities. In total, 748 models across 5 vendors are affected

Here’s the worst vulnerability:

The most serious of the findings is the authentication bypass CVE-2024-51978. A remote unauthenticated attacker can leak the target device’s serial number through one of several means, and in turn generate the target device’s default administrator password. This is due to the discovery of the default password generation procedure used by Brother devices. This procedure transforms a serial number into a default password. Affected devices have their default password set, based on each device’s unique serial number, during the manufacturing process. Brother has indicated that this vulnerability cannot be fully remediated in firmware, and has required a change to the manufacturing process of all affected models.

So if you own a Brother printer, you should change your administrator password ASAP. Now newer Brother printers won’t have this vulnerability as the company will change how they generate the password. But that doesn’t help anyone who owns one of these printers right now. The other vulnerabilities will be fixed via firmware updates. You should check your vendor’s website to see what you should do in that regard: