Elektrine lite

← Feed

Metasploit

metasploit@infosec.exchange

<p>The Metasploit Project (part of the Rapid7 family)</p><p>Learn/mentor/contribute: <a href="https://metasploit.com/slack" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="">metasploit.com/slack</span><span class="invisible"></span></a></p>

Posts

  • View post

    Check out Episode 3 of Hacktics and Telemetry! https://youtu.be/dPYH5OfHTfQ Inside you&amp;#39;ll find 🔍: 00:00 - Welcome to Hacktics and Telemetry &amp;amp; The WordPress Dongle April Fool&amp;#39;s Joke 02:56 - The Situation Room: LightLLM Hacks, Claude Source Code Leaks, &amp;amp; Chrome Zero-Days 23:10 - The War Room: Weaponizing Cellular IoT with Deral Heiland 41:59 - The Mitigation Minute: Supply Chain Defenses &amp;amp; Hardware Protections

  • View post

    This week&amp;#39;s release features a 2x faster msfvenom bootup time and new modules, including exploits for the Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20127) and osTicket Arbitrary File Read (CVE-2026-22200). https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-10-2026/

  • View post

    Happy Friday, Metasploit users! 🎉 The weekly wrapup is here with a massive update: 7 new modules, including 4 fresh RCE exploits (targeting AVideo, openDCIM, ChurchCRM, &amp;amp; Selenium Grid/Selenoid) and 3 new Windows persistence techniques. Get the details and happy hacking! https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-17-2026/

  • View post

    Episode 4 of Hacktics and Telemetry is Live! Bug Bounties, AI Superpowers, and Breach Impersonations https://youtube.com/watch?v=-xv0w61K5L0 The goodness contains: 02:13 - The Situation Room: Vercel breach, Shiny Hunter impersonators, and Anthropic’s Opus 4.7. 16:00 - The War Room: Bug bounty strategies and the Arson Framework with Harrison Richardson. 43:07 - The Mitigation Minute: Defending against supply chain attacks and identity compromise.

  • View post

    The latest Metasploit Weekly Wrapup is here! Highlights include a new RCE exploit for Langflow (CVE-2026-27966), improved check method visibility with detailed reasoning, and updates for legacy SMB targets. Plus 3 other new modules! Read more: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-25-2026/

  • View post

    This weeks wrap up is packed with new stuff including an MCP server, and new modules for relaying NTLM from HTTP to LDAP and a Copy Fail exploit with x64 and AARCH64 support https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-05-01-2026/

  • View post

    This weeks&amp;#39; release is themed &amp;quot;Spring Cleanup&amp;quot; and brings some improvements to Metasploit! Key updates include payload fixes for Copy Fail on x64 and new support for ARMLE Linux, enhancements to the shiro_rememberme_v124_deserialize module for broader targeting, and general fixes for FTP utility modules. Checkout the details at https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-05-08-2026/

  • View post

    The ultimate persistence mechanism is here: Vim plugin persistence! Seriously, who can close Vim anyway? Catch up on the latest Metasploit Wrap-up, also featuring Unauthenticated Marvell QConvergeConsole Path Traversal (CVE-2025-6793), Authenticated RCE in GestioIP 3.5.7 (CVE-2024-48760), and a classic PHP filter bypass in Dolibarr ERP/CRM (CVE-2023-30253). As always, check it out the blog: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-05-15-2026/

  • View post

    Episode 6 of Hacktics and Telemetry is Live! Cisco SD-WAN Zero-Days, Mythos AI Evaluations, and Pwn2Own Drama Get it here: https://www.youtube.com/watch?v=tg4TkzDIrKw

  • View post

    This week&amp;#39;s release has a whooping 5 new modules including LPE &amp;#39;sploits for dirty frag and a info leak scanner for Citrix NetScaler. Check it out at https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-05-29-2026/

  • View post

    Checkout the War Room segment on the latest Hacktics and Telemetry episode where Stephen and Johah discuss a Cisco Catalyst SD-WAN 0-day that @rapid7 discovered and added to Metasploit https://www.youtube.com/watch?v=GWSX1fI1zUM

  • View post

    In the latest Hacktics and Telemetry&amp;#39;s Mitigation Minute, @_CryptoCat dives into his recent zero-day Gogs exploit and Metasploit module as he discusses what to do when there is no patch https://www.youtube.com/watch?v=EPioibHRKPY&amp;amp;t=4136s

  • View post

    This week&amp;#39;s release adds new Kerberos/Certificate tracing options (GSoC project), a community feedback call on evasion module UX, a new ClickFix social-engineering exploit module, 9 enhancements, and more https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-13-06-2026/

  • View post

    This week&amp;#39;s release adds a full unauthenticated RCE chain for Paperclip AI, an NTLM relay-to-self local priv esc module, a VS Code extension persistence technique, MCP server integration for AI-assisted msfconsole operation, and more. https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-19-06-2026/

  • View post

    Metasploit 6.5 is out just in time for Hack Summer Camp. This release comes with Malleable C2 support for Meterpreter, more relaying improvements and an integrated MCP server. Check out all the details here: https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/

  • View post

    We&#39;ll be demoing Metasploit 6.5 at Black Hat Arsenal Station 4 tomorrow, August 5th at 4PM. Be sure to stop by if you&#39;re attending to see the latest features in action and chat with some of the maintainers.

  • View post

    Metasploit 6.5 shipped Malleable C2 support for all current Meterpreter payloads — same profile format you already know, now shaping Meterpreter&#39;s HTTP(S) traffic. See it in action: https://youtu.be/cu5UGE-VL2

  • View post

    Our latest Wrap-up is live. This update adds Fetch Multi payloads for automatic architecture identification, expands RISC-V support, and includes a new HTTP to SMB Relay module. Check it out at: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-an-http-to-smb-relay-plus-payload-improvements/

  • View post

    This week&#39;s Metasploit update includes new exploits for Flowise CSV Agent, Apache .htaccess persistence, and macOS PackageKit privilege escalation. Check out the full details here: https://www.rapid7.com/blog/post/pt-weekly-metasploit-update-exploits-for-flowiseai-csv-agent-and-macos-package-kit/

  • View post

    This week&#39;s Metasploit Framework update is live, featuring new modules for Audiobookshelf, LiteLLM, Next.js, and Dalfox. We have also added improvements to service and host reporting for brute-force modules. We also have a short survey about evasion modules. You can read the full update details here: https://www.rapid7.com/blog/post/pt-weekly-metasploit-update-modules-for-audiobookshelf-litellm-next-js-dalfox-and-more/

  • View post

    The annual wrap-up for Metasploit Framework is out now, and it includes the entirety of stats for 2025. This wrap-up and its contents would not be possible without the participation and dedication of our contributors and researchers, and all of our thanks goes to them! Metasploit Framework wouldn&amp;#39;t be the same without you, thank you. https://www.rapid7.com/blog/post/pt-metasploit-2025-annual-wrap-up/