Negotiating with the Board: Translating Active Risk into Financial Exposure

2026-03-20T19:23:45Z456aa077c14b337ba2100748d3c77e881775208048ee397bca624eda55104c23
CNAPPCVE-2026-31381CVE-2026-31382Exposure CommandGainsight AssistMDRMicrosoft Teams phishingQuick Assistboard communicationexploit timelineinformation disclosurepatchedreflected XSSsecurity reportingsocial engineeringthreat landscape 2026vulnerability management

What happened

A Rapid7 blog batch covering multiple security topics: Rapid7 Labs discovered a chained Information Disclosure (CVE-2026-31381) and reflected XSS (CVE-2026-31382) in the Gainsight Assist plugin and associated domain—both issues were patched in March 2026. Rapid7 also warns of accelerated exploitation timelines in the 2026 Global Threat Landscape Report and reports active Microsoft Teams phishing campaigns where attackers impersonate IT to get users to launch Quick Assist for remote access. Additional posts cover CNAPP/Exposure Command integration, MDR guidance, and partner program updates.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
456aa077c14b337ba2100748d3c77e881775208048ee397bca624eda55104c23
Enrichment time
2026-03-20T19:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Negotiating with the Board: Translating Active Risk into Financial Exposure · Baitaphish