Metasploit Wrap-Up 04/03/2026

2026-04-06T19:23:48Zbd6d73ad3f394f66ea2404f9a5bebdf58419417498cef8fbb6c07cc9901acbda
BPFBPFDoorCVE-2026-23767ESC/POSEclipse CheEpson printersFreeScoutGrav CMSHKCU\Environment\UserInitMprLogonScriptIABICMP relayInitial Access BrokerMetasploitNTLM relayRCERDPSMBVPN','RDWeb'Windows persistencehttpShellicmpShellkernel backdooros_cmd_execstateless C2telecom infrastructure

What happened

Rapid7 published multiple posts covering new offensive tooling, emerging threats, and security guidance. Metasploit additions include new HTTP/HTTPS CMD payloads for x64/x86 Windows, exploits and modules enabling unauthenticated RCE against FreeScout and Grav CMS, a generic multi/http/os_cmd_exec for HTTP-based command execution, and a new persistence primitive abusing HKCU\Environment\UserInitMprLogonScript; SMB/NTLM relay functionality was also improved. Rapid7 Labs released a whitepaper identifying seven new stealthy BPFDoor kernel backdoor variants (including httpShell and icmpShell) that·

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
bd6d73ad3f394f66ea2404f9a5bebdf58419417498cef8fbb6c07cc9901acbda
Enrichment time
2026-04-06T19:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metasploit Wrap-Up 04/03/2026 · Baitaphish