Rapid7 Launches Rapid7 Intelligence to Harness Threat Data Against Attackers
Rapid7 (RPD) launched Rapid7 Intelligence, a unified engine combining threat intelligence, vulnerability research and the work of Rapid7 Labs.
Sentiment and the balance of points
Rhea-AI Sentiment reads the wording of the document, how positive or negative its language is on a 1 to 5 scale. The balance of points shown with the takes weighs what the document actually discloses, so the two can disagree, for example when a trial that missed its main goal is described in upbeat language.
Rhea-AI Summary
Rapid7 (RPD) launched Rapid7 Intelligence, a unified engine combining threat intelligence, vulnerability research and the work of Rapid7 Labs. The company describes its purpose as moving enterprise defenses from reactive monitoring toward proactive prevention by translating attacker behavior into AI-powered action.
The engine feeds intelligence into Rapid7 products, managed detection and response services, and Exposure Management. Critical advisories, vulnerability research and exploitation insights remain openly available. Rapid7 researchers also identified a modular Linux malware ecosystem targeting telecom and network-edge devices.
Key Figures
- Critical vulnerabilities tracked
- 8,539 vulnerabilities
- Q2
Key Terms
smtp technical
dmz technical
managed detection and response technical
AI-generated analysis. How Rhea-AI works. Not financial advice.
As automated exploits dismantle traditional defense models in hours, Rapid7 unites threat intelligence, vulnerability research, and Rapid7 Labs to end reactive cybersecurity once and for all
BOSTON, Oct. 02, 2026 (GLOBE NEWSWIRE) -- Today, Rapid7, Inc. (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, announced the launch of Rapid7 Intelligence, a unified engine designed to transform enterprise threat defenses from reactive monitoring to proactive prevention. By combining threat intelligence, vulnerability research, and the legacy of Rapid7 Labs, Rapid7 Intelligence transforms insights on attacker behavior into AI-powered action to help organizations anticipate and disrupt attacks.
Indicators Expire. Behavior Doesn't: Defense for the Agentic Era.
Building on Rapid7 Labs’ 13-year legacy, Rapid7 Intelligence turns attacker behavior into scalable protection faster than traditional vendors reliant on static indicators. With AI compressing exploitation windows to minutes—and 8,539 critical vulnerabilities tracked in Q2 alone—attackers are leveraging automation to scale phishing, reconnaissance, and script development. Rapid7 Intelligence monitors these threats in real time to deliver actionable, expert-validated insights that keep defenders ahead.
"Static threat intelligence isn't completely dead—it's just sitting in standard dashboards doing what it's always done, giving organizations a false sense of security while autonomous threat agents burn down their perimeters," said Christiaan Beek, Vice President of Rapid7 Intelligence. "The real differentiator isn't hoarding more raw feeds; it's having curated, vetted intelligence focused relentlessly on true signals rather than waiting around for alerts to trigger after the damage is done. Rapid7 Intelligence isn't built to generate another 50-page PDF report for security teams to ignore; it aggressively converts real-time operational adversary insight into a proactive, preemptive shield."
Rapid7 Intelligence in Action: Behavioral Correlation Exposes a Hidden Linux Malware Ecosystem
A concrete illustration of Rapid7 Intelligence's power is a new finding from Rapid7 researchers, who uncovered a modular Linux malware ecosystem—spanning new BPFDoor variants, BPF Rekoobe, droppers, and AVERAT implants—actively targeting telecom and network-edge devices.
Researchers identified two campaigns linked by a common focus on the network edge. Rapid7 Intelligence analyzed their shared behaviors, uncovering an emerging pattern: using SMTP to blend into the victim’s DMZ, target mail security appliances, and maintain long-term access.
New BPFDoor variants indicate the malware family is evolving into an ecosystem where each sample is tailored to the telco plane (control, management, and data plane) it targets, and where threat actors know exactly what software is adopted at each layer.
Rapid7 Intelligence will continue tracking and disrupting tactics like this to keep defenders ahead of attackers.
Expert-Led, Actionable Intelligence
To continuously power research like this and help defenders stay ahead of emerging threats, Rapid7 Intelligence delivers:
- Immediate Protective Force: Frontline intelligence bypasses legacy research lags, flowing directly into Rapid7 products, MDR, and Exposure Management to neutralize adversary infrastructure before attacks execute.
- Unified Intelligence Engine: Threat intelligence, vulnerability analysis, and engineering inside the products customers already run, instead of a report they have to translate into action themselves.
- Uncompromised Community Arsenal: Building on the legendary foundation of Metasploit and Rapid7 Labs, critical advisories, vulnerability research and exploitation insights remain open, ensuring the industry stays capable of pushing back.
“In a world of infinite telemetry and automated attacks, playing defense with traditional tools is an exercise in futility,” said Mel Stone, Chief Global Services Officer at Rapid7. “Rapid7 Intelligence shifts the balance of power. By fusing machine-scale observation with frontline human expertise, we turn raw threat data into immediate, actionable intelligence—empowering security teams to disrupt adversaries before they establish a foothold.”
To learn more about Rapid7 Intelligence, visit here.
About Rapid7
Rapid7, Inc. (NASDAQ: RPD) is a global leader in AI-powered managed cybersecurity operations, trusted to advance organizations’ cyber resilience. Open and extensible, the Rapid7 Command Platform integrates security data, enriching it with AI, threat intelligence, and 25 years of expertise and innovation to reduce risk and disrupt attackers. As a recognized leader in preemptive managed detection and response (MDR), Rapid7 unifies exposure and detection to transform the cybersecurity operations of more than 11,500 customers worldwide. For more information, visit our website, check out our blog, or follow us on LinkedIn or X.
Media Contact
Christine Nurnberger
SVP Global Marketing and Growth
press@rapid7.com
Rapid7 Investor Contact
Christopher Keenan
Vice President, Deputy General Counsel
investors@rapid7.com