See what we're thinking about, working on, & blogging about.

Explore the latest insights, ideas, & opinions from our talented team of experts & researchers.

Subscribe Now

Get our latest Rapid Responses, insights, and blogs delivered directly to your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

runZero Research
Security Surprises with SNMP v3
October 8, 2021
SNMP v3 has been the official version of the protocol since 2004, but still holds a few surprises when it comes to information exposure. Read our...
Rapid Response
How to find Apache HTTP Server instances
October 5, 2021
The Apache Software Foundation recently announced a path traversal vulnerability present in version 2.4.49 of the Apache HTTP Server software.
Product
Rumble 2.7 New dashboard, multi-subscription Azure, AWS ELBs, Splunk add-on improvements, and faster discovery for Rumble Professional
October 5, 2021
User experience improvement, get insights, trends, and visualizations from your dashboard, and more.
runZero Research
Fingerprinting Windows build numbers
September 30, 2021
Our goal at Rumble is to help customers identify everything on their networks, quickly, and without authentication. This process is driven by...
Rapid Response
How to find Hikvision IP cameras and recorders on your network
September 21, 2021
Newly published security research from Watchful IP reveals an unauthenticated code execution vulnerability (assigned CVE-2021-36260) present in...
Rapid Response
How to find assets running OMI services
September 17, 2021
Details on vulnerabilities present in some Azure Linux VMs, collectively referred to as “OMIGOD”, came to light this week via published research by...
Rapid Response
How to find Fortinet web application firewall devices
August 25, 2021
Recently published security research from Rapid7 provides details on an OS command injection vulnerability in Fortinet’s web application firewall...
runZero Research
BlackHat gems HP iLO 5 vulnerabilities
August 19, 2021
Each year, August arrives with promises of hot weather and cool security research talks. The DEF CON, Black Hat, and BSidesLV security conferences...
runZero Research
Fingerprinting Windows versions, AV, wireless cards over the network—all without authentication
August 11, 2021
Correctly identifying and categorizing network-connected systems without credentials is a tricky challenge and one of the fun parts of working at...
Product
Rumble 2.5 Identify endpoint protection agents, detect wireless & mobile Internet, and scan all your EC2 accounts
August 3, 2021
Identify endpoint protection agents via integrations and unauthenticated scans and much more.
Rapid Response
How to find SolarWinds Serv-U systems on your network
July 15, 2021
Microsoft recently notified SolarWinds that they had discovered a remote code execution vulnerability in Serv-U Managed File Transfer and Serv-U...