Rapid7 has launched Rapid7 Intelligence, a platform that combines threat intelligence, vulnerability research and the work of Rapid7 Labs.
The launch is intended to address the shrinking gap between the disclosure of software flaws and their exploitation by attackers using AI and automation.
Rapid7 Intelligence brings several existing research and intelligence functions into one system. It focuses on identifying and correlating attacker behaviour rather than relying mainly on static indicators, with the aim of helping security teams act before attacks are fully underway.
The announcement comes as security vendors and corporate defenders face mounting pressure from a faster threat cycle. Rapid7 cited 8,539 critical vulnerabilities tracked in the second quarter alone, arguing that automated exploitation, phishing and reconnaissance are reducing the time available for defenders to respond.
Christiaan Beek, Vice President of Rapid7 Intelligence at Rapid7, said many organisations still depend on conventional threat intelligence feeds and dashboards that are not keeping pace with current attack methods.
"Static threat intelligence isn't completely dead - it's just sitting in standard dashboards doing what it's always done, giving organisations a false sense of security while autonomous threat agents burn down their perimeters," Beek said.
"The real differentiator isn't hoarding more raw feeds; it's having curated, vetted intelligence focused relentlessly on true signals rather than waiting around for alerts to trigger after the damage is done. Rapid7 Intelligence isn't built to generate another 50-page PDF report for security teams to ignore; it aggressively converts real-time operational adversary insight into a proactive, preemptive shield," he said.
Linux malware
As an example of the research the platform is intended to support, Rapid7 disclosed findings on a modular Linux malware ecosystem aimed at telecom and network-edge devices.
Researchers identified new BPFDoor variants, BPF Rekoobe, droppers and AVERAT implants in two campaigns linked by a shared focus on the network edge. Rapid7's analysis pointed to a broader pattern in which attackers used SMTP traffic to blend into a victim's demilitarised zone, target mail security appliances and maintain long-term access.
The new BPFDoor variants suggest the malware family is developing into a wider ecosystem. Rapid7 said individual samples appear tailored to different parts of a telecommunications environment, including control, management and data planes.
Integrated model
Rapid7 said the platform is designed to feed intelligence directly into its products, managed detection and response services, and exposure management tools. It will also continue to publish advisories, vulnerability research and exploitation insights through the community channels associated with Metasploit and Rapid7 Labs.
The broader shift reflects a change in how security suppliers are framing threat intelligence. Rather than presenting it as a separate stream of information for customers to interpret, vendors are increasingly trying to embed intelligence into protective tools and operational services so detection and mitigation can happen more quickly.
Mel Stone, Chief Global Services Officer at Rapid7, said the volume of telemetry and automated attacks has made older defensive methods less effective.
"In a world of infinite telemetry and automated attacks, playing defence with traditional tools is an exercise in futility," Stone said.
"Rapid7 Intelligence shifts the balance of power. By fusing machine-scale observation with frontline human expertise, we turn raw threat data into immediate, actionable intelligence - empowering security teams to disrupt adversaries before they establish a foothold," he said.