Tech News
← Home  ·  All topics

Rapid7

3 GoKawiil briefs on this topic

Rapid7 links suspected North Korean hackers to breach of South Korean media, auto firms

Rapid7 reports that a stealthy espionage campaign has compromised South Korean automotive and media companies since early 2025, with medium-confidence attribution to North Korean APT37 based on overlapping command-and-control infrastructure. The attackers exploited the open-source HAProxy load balancer to install a custom Linux toolkit called TED, granting them visibility into and control over victims' network traffic.

SonicWall SMA 1000 Devices Hit by Two Actively Exploited Zero-Days

SonicWall disclosed two vulnerabilities in its SMA 1000 series appliances: a maximum-severity SSRF flaw (CVE-2026-83548) in the user-facing Work Place portal and an OS command injection bug (CVE-2026-83549) in the admin console. SonicWall's security team confirmed active exploitation in the wild and urged customers to patch immediately, while researchers at Rapid7 noted the two bugs can be chained together for unauthenticated remote code execution.

Attackers chain two Microsoft SharePoint flaws using public PoC exploits

Threat intelligence firm Defused reports that hackers are actively probing SharePoint servers by combining two vulnerabilities: an authentication bypass in JWT token validation (CVE-2026-55040) and a Business Connectivity Services flaw (CVE-2026-63520) that enables remote code execution. Proof-of-concept code for both bugs was published publicly in August by researchers at Rapid7 and VulnCheck, and Defused says it has already observed the bypass being exploited alongside admin enumeration on honeypots, though no successful code execution has been confirmed yet.