Exploiting an Internal Network, Loud and Proud

Rapid7 was recently tasked with testing a client’s internal network, an environment that included multiple subnets. Due to the size of the network, this was a paired internal – an engagement in which two consultants are assigned to the same network penetration test.  Starting softly We kicked off this one how we typically do: by…

Read More

Givaudan to acquire US fragrance house Belle Aire Creations

Published September 30, 2025 Givaudan, a global leader in fragrance and beauty, announced on Tuesday its plans to acquire Belle Aire Creations, a prominent U.S.-based fragrance house. Terms of the deal were not disclosed.  Givaudan to acquire US fragrance house Belle Aire Creations. – Givaudan With this acquisition, Givaudan aims to leverage Belle Aire Creations’…

Read More

Crush FTP Vulnerability Exploited in the Wild

On Friday, July 18, 2025, managed file transfer vendor CrushFTP released information to a private mailing list on a new critical vulnerability, tracked as CVE-2025-54309, affecting versions below 10.8.5 and 11.3.4_23 across all platforms. According to the public-facing vendor advisory, this vulnerability in the CrushFTP managed file transfer software web interface is being exploited in…

Read More