Metasploit Wrap-Up 04/25/2026

2026-04-25T07:23:44Z7fa05a82817f1210b84c72d337db30f6f1c038d06b02eac7106d5e306ff4b3e2
AI-driven vulnerability discoveryAVideoBulk ExportCamaleon CMSDirectory TraversalHyper-VKyber ransomwareMCP ServerMetasploitProject GlasswingRCERustSMBv1SQL injectionTor infrastructureVMware ESXiWindowscheck methodsdatastore encryptionincident responselegacy SMBopen-sourceopenDCIMransomwaresoftware supply chain

What happened

Rapid7 blog roundup covering Metasploit Framework updates (improved check-method visibility, fixes for legacy/non‑Windows SMB targets) and several new Metasploit modules, including a Camaleon CMS directory traversal (CVE-2024-46987) and recent SQLi/RCE modules (CVE-2026-28501, CVE-2026-28517). Also highlights a detailed analysis of Kyber ransomware that deploys coordinated Windows and VMware ESXi payloads (datastore encryption, VM termination, management defacement) with Tor-based infrastructure, plus coverage of AI-driven vulnerability discovery (Project Glasswing) and Rapid7’s open-source MC

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
7fa05a82817f1210b84c72d337db30f6f1c038d06b02eac7106d5e306ff4b3e2
Enrichment time
2026-04-25T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.