Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Cybersecurity Classified by Officially
Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
This wrap-up comes from the beautiful country of Belgium, where the Metasploit team is team-building and team-eating while we cheer on our very own teammates giving talks - shout-out to @jburgess-r7 who gave a wonderful talk about some of his 0day research.
Team building is a wonderful corporate ritual in which security researchers — people whose job is to break stuff and find ways into places they shouldn't be — are released into hotels full of questionable tech, and then everyone acts surprised by what happens next. So far, the only leak has been the Manneken Pis.
Anyway, while we were busy learning that a country with three official languages still has zero words for "one waffle is enough," the internet continued to be on fire.
We’re gonna jump right into the deep end. GitLab. Unauthenticated. Arbitrary file read. Exploited in the wild. That’s it. If you're reading this and your self-hosted GitLab is running anything from 18.7 up to the fixed versions, please stop reading and go patch.
Next, for anyone who has ever wanted to become the DNS server for an entire Windows network without the hassle of asking permission, we now have native mitm6-style DHCPv6 and IPv6 RA DNS takeover modules. Remember that IPv6 stack you never configured, never use, and definitely never disabled? Windows remembers. Windows is very happy to accept a new DNS server from a stranger who asks nicely.
And finally, Langflow brings us authenticated RCE via custom components, continuing the proud AI-industry tradition of building a feature that lets users run arbitrary Python and then being shocked when users run arbitrary Python.
GitLab Unauthenticated Arbitrary File Read
Authors: guneykabel, jheysel-r7, and s3ntago
Pull request: #21910 contributed by jheysel-r7
Path: gather/gitlab_file_read_cve_2026_85706
This is an extract. The publication continues at the source.
Read the original at the source: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-belgian-waffles-chocolates-and-modules-frites
Officially imported this from Rapid7’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Rapid7 — imported from official source
- Official source
- https://blog.rapid7.com/rss/ RSS
- Imported
- September 25, 2026 16:00
- Versions
- 1 recorded
- Identity
blt0e07d4de87ef7cf7