Metasploit Wrap-Up 03/27/2026

2026-03-29T19:23:50Ze93d0c021dc5cdbe916ab74f555d30ec112ed09b33399925b5487bc57d4fe720
AT commandsBPFdoorBSI C5 Type 2CVE-2026-23767CVE-2026-3055CitrixESC/POSEclipse CheIoTMetasploit modulesNTLM relayNetScalerRed MenshenRubySMBSMBVector Commandcellular modulesespionagemetasploitprinterstelecomunauthenticated RCEvulnerability managementwhitepaper

What happened

Collection of Rapid7 blog highlights (Mar 24–27, 2026). Key items: Metasploit update improves SMB NTLM relaying (RubySMB client change) and adds an ESC/POS printer command injector exploiting CVE-2026-23767; an Eclipse Che unauthenticated machine-exec RCE was added to Metasploit. Rapid7 Labs published a telecom threat report on BPFdoor sleeper cells attributed to a China-nexus actor (“Red Menshen”). A whitepaper and PoCs detail attacks against cellular-based IoT modules (hardware/AT-command based techniques, Metasploit proxy modules). Rapid7 also published posts on web-app testing (Vector Cmd)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
e93d0c021dc5cdbe916ab74f555d30ec112ed09b33399925b5487bc57d4fe720
Enrichment time
2026-03-29T19:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metasploit Wrap-Up 03/27/2026 · Baitaphish