Metasploit 6.5 is out just in time for Hack Summer Camp. This release comes with Malleable C2 support for Meterpreter, more relaying improvements and an integrated MCP server. Check out all the details here: rapid7.com/blog/post/pt-meta…
Our latest wrap-up is live. Metasploit drops 16 new modules in total, with 10 exploit modules covering Cisco, SonicWall, Jetbrains, PaperCut, Langflow, and more ⤵️ r-7.co/3SZ9Wyc
Hacktics & Telemetry, Episode 13 is live!
Courtroom Prompt Injections and WhatsApp's Blind Spots (ft. Max Günther)! Get it here: piped.video/watch?v=7sQyReuw…
Latest Hacktics and Telemetry is out now!
Hacktics & Telemetry, E12: Pwn2Own, AI in Exploit Chains & Brother Printer Hacks (ft. Stephen Fewer)
Watch here: piped.video/watch?v=Dnx9yDwX…
We'll be demoing Metasploit 6.5 at Black Hat Arsenal Station 4 tomorrow, August 5th at 4PM. Be sure to stop by if you're attending to see the latest features in action and chat with some of the maintainers.
Metasploit 6.5 shipped Malleable C2 support for all current Meterpreter payloads — same profile format you already know, now shaping Meterpreter's HTTP(S) traffic. See it in action:
piped.video/cu5UGE-VL2o
Our latest Wrap-up is live. This update adds Fetch Multi payloads for automatic architecture identification, expands RISC-V support, and includes a new HTTP to SMB Relay module. Check it out at: rapid7.com/blog/post/pt-meta…
This week's Metasploit update includes new exploits for Flowise CSV Agent, Apache .htaccess persistence, and macOS PackageKit privilege escalation. Check out the full details here: rapid7.com/blog/post/pt-week…
This week's Metasploit Framework update is live, featuring new modules for Audiobookshelf, LiteLLM, Next.js, and Dalfox. We have also added improvements to service and host reporting for brute-force modules. We also have a short survey about evasion modules. You can read the full update details here: rapid7.com/blog/post/pt-week…
This week's release adds a full unauthenticated RCE chain for Paperclip AI, an NTLM relay-to-self local priv esc module, a VS Code extension persistence technique, MCP server integration for AI-assisted msfconsole operation, and more. rapid7.com/blog/post/pt-meta…
Listen to Hacktics & Telemetry, E8: How Brutecat Made $500K in Bug Bounties Hacking Google (ft. Arvin Shivram)!
Contents include: what it says on the tin :) piped.video/watch?v=wJKJpzFY…
In the latest Hacktics and Telemetry's Mitigation Minute, @_CryptoCat dives into his recent zero-day Gogs exploit and Metasploit module as he discusses what to do when there is no patch piped.video/watch?v=EPioibHR…
This week's release has a whooping 5 new modules including LPE 'sploits for dirty frag and a info leak scanner for Citrix NetScaler. Check it out at rapid7.com/blog/post/pt-meta…
Found an unpatched RCE in Gogs 👀 Any authenticated user can get code execution on the server through argument injection into git rebase. Full @rapid7 writeup + @metasploit module available now!
🔗rapid7.com/blog/post/ve-auth…
Episode 6 of Hacktics and Telemetry is Live!
Cisco SD-WAN Zero-Days, Mythos AI Evaluations, and Pwn2Own Drama
Get it here:
piped.video/watch?v=tg4TkzDI…