Metasploit Wrap-Up 03/27/2026
2026-03-29T19:23:50Z•e93d0c021dc5cdbe916ab74f555d30ec112ed09b33399925b5487bc57d4fe720
AT commandsBPFdoorBSI C5 Type 2CVE-2026-23767CVE-2026-3055CitrixESC/POSEclipse CheIoTMetasploit modulesNTLM relayNetScalerRed MenshenRubySMBSMBVector Commandcellular modulesespionagemetasploitprinterstelecomunauthenticated RCEvulnerability managementwhitepaper
What happened
Collection of Rapid7 blog highlights (Mar 24–27, 2026). Key items: Metasploit update improves SMB NTLM relaying (RubySMB client change) and adds an ESC/POS printer command injector exploiting CVE-2026-23767; an Eclipse Che unauthenticated machine-exec RCE was added to Metasploit. Rapid7 Labs published a telecom threat report on BPFdoor sleeper cells attributed to a China-nexus actor (“Red Menshen”). A whitepaper and PoCs detail attacks against cellular-based IoT modules (hardware/AT-command based techniques, Metasploit proxy modules). Rapid7 also published posts on web-app testing (Vector Cmd)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- e93d0c021dc5cdbe916ab74f555d30ec112ed09b33399925b5487bc57d4fe720
- Enrichment time
- 2026-03-29T19:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.