3 Reasons to Attend our Global Cybersecurity Summit if you’re Focused on AI, Threats, and CTEM
2026-04-24T19:23:52Z•c9543ef9729e372b2cc5601f075618aba6f7bd97850b230cc5497d011aff2a8b
ai-securitybulk-exportcve-2026-33032exposure-managementhyper-vkybermetasploitnginx-uiopen-source-mcpproject-glasswingransomwarercesoftware-supply-chainsql-injectionvmware-esxivulnerability-discoverywindows
What happened
Collection of Rapid7 posts (Apr 2026) covering multiple security topics: analysis of the Kyber ransomware campaign which deploys dual-platform payloads targeting VMware ESXi (datastore encryption, optional VM termination, management defacement) and Windows (Rust-based, experimental Hyper-V targeting) using Tor-based infrastructure; a critical missing-authentication vulnerability in Nginx UI (CVE-2026-33032, CVSS 9.8) that was patched in March 2026; new Metasploit modules including exploits for AVideo (CVE-2026-28501, unauthenticated SQLi) and openDCIM (CVE-2026-28517, chained SQLi→RCE); and讨论s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- c9543ef9729e372b2cc5601f075618aba6f7bd97850b230cc5497d011aff2a8b
- Enrichment time
- 2026-04-24T19:23:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.