PACT 2026: A Stronger, Simpler, More Profitable Path for Rapid7 Partners

2026-03-17T19:23:49Zf9bbf97ea793bda5da79c9f230abd90d91a63536a04f8878f5667d6118b3a7f6
cve-2025-71243detection coverageevasionexploitiran-linked activitylateral movementleakixmalwaremetasploitmetasploit promicrosoft teamsphishingquick assistrapid7 mdrremote accesssocial engineeringspipthreat intelligence

What happened

Rapid7 published multiple updates: (1) Rapid7 MDR is tracking an uptick in Microsoft Teams phishing where actors impersonate internal IT to trick users into launching Quick Assist, granting remote access for malware deployment, data exfiltration, or lateral movement; (2) Metasploit Framework added three modules: LeakIX search (discovery), a Linux x64 RC4 payload packer (evasion), and an unauthenticated RCE exploit for SPIP Saisies (CVE-2025-71243); Metasploit Pro 5.0.0 was released with UI and SSO enhancements; (3) Rapid7 detailed detection/enrichment coverage for Iran-linked activity; and (4)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
f9bbf97ea793bda5da79c9f230abd90d91a63536a04f8878f5667d6118b3a7f6
Enrichment time
2026-03-17T19:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.