RPD Rapid7 Inc.

Rapid7 Q3 Threat Report Reveals Ransomware Alliances, AI Weaponization, and the Obsolescence of “Time to Patch”

Rapid7 Q3 Threat Report Reveals Ransomware Alliances, AI Weaponization, and the Obsolescence of “Time to Patch”

BOSTON, Nov. 12, 2025 (GLOBE NEWSWIRE) -- , a leader in threat detection and exposure management, today released its , revealing how threat actors are accelerating the race between vulnerability disclosure and exploitation, consolidating ransomware power structures, and increasingly weaponizing artificial intelligence to evade detection. The report draws from Rapid7’s Intelligence Hub, AttackerKB, incident response, and managed detection and response (MDR) telemetry, offering data-driven insight into how adversaries are evolving and how defenders can adapt.

“Ransomware has evolved significantly beyond its early days to become a calculated strategy that destabilizes industries,” said Raj Samani, Chief Scientist at Rapid7. “In addition, the groups themselves are operating like shadow corporations. They merge infrastructure, tactics, and PR strategies to project dominance and erode trust faster than ever.”

Critical vulnerability exploitation speeds up as old weaknesses persist

Rapid7’s quarterly analysis shows that the total number of newly exploited vulnerabilities trended downward, dropping 21% from Q2 to Q3. However, adversaries doubled down on older, unpatched weaknesses, including CVEs more than a decade old, indicating that historic exposures remain potent attack vectors.

The mass exploitation of critical vulnerabilities in Microsoft SharePoint (CVE-2025-53770) and Cisco ASA/FTD products underscores the narrowing window between patch disclosure and in-the-wild attacks.

“The moment a vulnerability is disclosed, it becomes a bullet in the attacker’s arsenal,” said Christiaan Beek, senior director of threat intelligence and analytics at Rapid7. “Attackers are no longer waiting. Instead, they’re weaponizing vulnerabilities in real time and turning every disclosure into an opportunity for exploitation. Organizations must now assume that exploitation begins the moment a vulnerability is made public and act accordingly.”

Ransomware activity spikes with new alliances and innovative tactics

The quarter also saw 88 active ransomware groups, up from 65 in Q2 and 76 in Q1, signaling an increase in activity as well as underscoring these groups’ fluidity. Groups like Qilin, SafePay, and WorldLeaks led a wave of alliances targeting industries like business services, manufacturing, and healthcare, and experimenting with fileless operations, single-extortion data leaks, and affiliate service offerings such as ransom negotiation assistance, where a more senior member of the group partners with a less experienced player to extort the victim.

Generative AI lowers barriers as nation-state campaigns redefine cyber warfare

The report details how generative AI is lowering the barrier for creating convincing phishing campaigns and enabling adaptive malware, such as LAMEHUG, which can dynamically generate new commands.

Meanwhile, nation-state operators from Russia, China, and Iran refine their tactics, blurring the line between espionage and disruption by targeting supply chains and identity systems with an emphasis on stealth and persistence.

To read a full copy of the report, visit .

About the Rapid7 Threat Landscape Report

The Rapid7 Threat Landscape Report is a quarterly analysis of global adversary behavior drawn from the company’s managed detection and response operations, vulnerability intelligence platforms, and threat research telemetry. The Q3 2025 edition provides one of the most comprehensive views of the global threat ecosystem: from ransomware and zero days to state-sponsored operations and AI-driven attacks.

About Rapid7

Rapid7, Inc. (NASDAQ: RPD) is on a mission to create a safer digital world by making cybersecurity simpler and more accessible. We empower security professionals to manage a modern attack surface through our best-in-class technology, leading-edge research, and broad, strategic expertise. Rapid7’s comprehensive security solutions help more than 11,000 global customers unite cloud risk management with threat detection and response to reduce attack surfaces and eliminate threats with speed and precision. For more information, visit our , check out our , or follow us on or .

Rapid7 Media Relations

Alice Randall

Director, Global Communications



(857) 216-7804

Rapid7 Investor Contact

Ryan Gardella / Ryan Flanagan

ICR, Inc



(617) 865-4277



EN
12/11/2025

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Rapid7 Inc.

 PRESS RELEASE

Rapid7 Reports Inducement Grants under Nasdaq Listing Rule 5635(c)(4)

Rapid7 Reports Inducement Grants under Nasdaq Listing Rule 5635(c)(4) BOSTON, March 26, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, announced that the company granted inducement awards, effective as of March 26, 2026, to employees and contractors of Kenzo Security, Inc. (“Kenzo”) in connection with Rapid7’s acquisition of Kenzo on March 26, 2026, as a material inducement for the Kenzo employees and contractors to commence employment with Rapid7 and its subsidiaries following Rapid7’s acquisition of Kenzo. Rapid7 granted inducem...

 PRESS RELEASE

Rapid7 Acquires Kenzo Security to Accelerate Preemptive, AI-Powered Se...

Rapid7 Acquires Kenzo Security to Accelerate Preemptive, AI-Powered Security Operations Acquisition expands Rapid7’s Command Platform to deliver scalable, machine-speed detection and response that disrupts attackers BOSTON, March 26, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, announced it has acquired Kenzo Security, an agentic AI security platform built to scale autonomous security investigations. The acquisition further enhances the Rapid7 Command Platform, accelerating managed detection and response (MDR) services from AI...

 PRESS RELEASE

Rapid7 Labs Identifies State-Sponsored Sleeper Cells Embedded in Globa...

Rapid7 Labs Identifies State-Sponsored Sleeper Cells Embedded in Global Telecommunications Networks Research reveals long-term espionage access inside telecommunications infrastructure with implications for government communications and critical systems BOSTON, March 26, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, released findings from a months-long research investigation from Rapid7 Labs, “,” detailing a sustained espionage campaign conducted by a China-nexus threat actor, Red Menshen, with covert access inside global teleco...

 PRESS RELEASE

Rapid7 2026 Global Threat Landscape Report Shows Exploited High and Cr...

Rapid7 2026 Global Threat Landscape Report Shows Exploited High and Critical-Severity Vulnerabilities Surged 105% as Attack Timelines Collapsed New research reveals exploitation now occurs within days of disclosure, reinforcing the need for preemptive security operations BOSTON, March 18, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, today released . The report finds that the window between vulnerability disclosure and confirmed exploitation continues to collapse, leaving organizations with dramatically less time to assess risk,...

 PRESS RELEASE

Rapid7 Advances 2026 PACT Partner Program to Strengthen Partner Led Go...

Rapid7 Advances 2026 PACT Partner Program to Strengthen Partner Led Go-to-Market and Profitability New tiers and simplified deal motions support scalable, partner-led MDR growth BOSTON, March 17, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: RPD), a global leader in AI-powered managed cybersecurity operations, announced 2026 updates to its designed to strengthen alignment between Rapid7 and its partner ecosystem and accelerate scalable growth through the channel. Rapid7 has long believed that tight Go-to-Market (GTM) alignment with partners is essential to delivering customer outcomes. The 2026 p...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch