Metasploit Wrap-Up 04/03/2026
2026-04-03T19:23:45Z•80ea741dfbfc5eb1507ae3196c2cecb1dab974fb59d6efcadc825076d0257ca9
AI-powered MDRBPFBPFDoorCVE-2026-23767CVSSESC/POSIABICMP relayMetasploitNTLM relayRDPRDWebVPNasset visibilityhttpShellicmpShellidentity postureinitial access brokerskernel backdoorred teamingstateless C2telecom infrastructurevisibility gapvulnerability prioritization
What happened
Rapid7’s blogs (early Apr 2026) highlight multiple active threats and operational guidance: new stealthy BPFDoor kernel backdoor variants (httpShell, icmpShell) that use BPF and stateless/ICMP C2 to establish nearly undetectable persistence in telecom infrastructure; shifts in the Initial Access Broker market toward higher-value targets and premium pricing (RDP/VPN/RDWeb remain primary vectors); Metasploit updates including improved NTLM relaying and modules exploiting CVE-2026-23767 (unauthenticated ESC/POS command injection in networked Epson-compatible printers) and an Eclipse Che unauth R
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 80ea741dfbfc5eb1507ae3196c2cecb1dab974fb59d6efcadc825076d0257ca9
- Enrichment time
- 2026-04-03T19:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.