Metasploit Wrap-Up 04/25/2026
2026-04-25T07:23:44Z•7fa05a82817f1210b84c72d337db30f6f1c038d06b02eac7106d5e306ff4b3e2
AI-driven vulnerability discoveryAVideoBulk ExportCamaleon CMSDirectory TraversalHyper-VKyber ransomwareMCP ServerMetasploitProject GlasswingRCERustSMBv1SQL injectionTor infrastructureVMware ESXiWindowscheck methodsdatastore encryptionincident responselegacy SMBopen-sourceopenDCIMransomwaresoftware supply chain
What happened
Rapid7 blog roundup covering Metasploit Framework updates (improved check-method visibility, fixes for legacy/non‑Windows SMB targets) and several new Metasploit modules, including a Camaleon CMS directory traversal (CVE-2024-46987) and recent SQLi/RCE modules (CVE-2026-28501, CVE-2026-28517). Also highlights a detailed analysis of Kyber ransomware that deploys coordinated Windows and VMware ESXi payloads (datastore encryption, VM termination, management defacement) with Tor-based infrastructure, plus coverage of AI-driven vulnerability discovery (Project Glasswing) and Rapid7’s open-source MC
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 7fa05a82817f1210b84c72d337db30f6f1c038d06b02eac7106d5e306ff4b3e2
- Enrichment time
- 2026-04-25T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.