Rapid7 launched an intelligence engine combining threat intelligence, vulnerability research and the work of its Labs team. The company says the service turns observations of attacker behavior into action inside its cybersecurity products.
The October 02, 2026 announcement describes Rapid7 Intelligence as a move from reactive monitoring toward proactive prevention. Those performance claims come from the company, which announced the launch through a GlobeNewswire release.
Rapid7 Combines Research With Product Operations
The engine brings together threat intelligence, vulnerability analysis and engineering within products customers already run. The company says frontline findings flow into its products, managed detection and response services, and Exposure Management.

It presents that integration as an alternative to reports that security teams must translate into operational changes themselves. The announcement also says critical advisories, vulnerability research and exploitation insights will remain openly available.
The service builds on the Labs team’s 13-year legacy and the foundation of Metasploit. Rapid7 says its researchers monitor automated threats in real time and deliver expert-validated insights.
The release cites 8,539 critical vulnerabilities tracked in Q2 alone. It says attackers use automation to scale phishing, reconnaissance and script development as exploitation windows compress.

Researchers Describe Linux Malware Campaigns
As an example of the research, Rapid7 reported a modular Linux malware ecosystem targeting telecom and network-edge devices. The findings span new BPFDoor variants, BPF Rekoobe, droppers and AVERAT implants.
Researchers identified two campaigns with a shared focus on the network edge, according to the company. Analysis of their behavior indicated use of SMTP to blend into a victim’s DMZ.
The company says the campaigns targeted mail security appliances and sought to maintain long-term access. It describes the BPFDoor variants as tailored to the control, management and data planes of telecom systems.
Rapid7 says these variants indicate that threat actors understand which software is used at each layer. The company plans to continue tracking and disrupting the tactics described in the announcement.
Related reporting covers water plant cybersecurity challenges, the reported FBI breach and smart contract security expertise.
Executives Emphasize Curated Intelligence
Christiaan Beek, Vice President of Rapid7 Intelligence, argued that gathering more raw feeds is insufficient. Beek said the distinction lies in curated, vetted intelligence focused on meaningful signals.
“The real differentiator isn’t hoarding more raw feeds; it’s having curated, vetted intelligence focused relentlessly on true signals rather than waiting around for alerts to trigger after the damage is done.”
Chief Global Services Officer Mel Stone described the service as combining machine-scale observation with frontline human expertise. Stone said the aim is to help security teams disrupt adversaries before they establish a foothold.
The release says the company’s Command Platform integrates security data with AI and threat intelligence. It identifies more than 11,500 customers worldwide, while describing its product work across exposure and detection.
The launch retains an open research commitment alongside the commercial product integration. Rapid7 says critical advisories, vulnerability research and exploitation insights will continue to be available to the wider community.





