As cited
Copy frozen at (site build).
vulnerabilities
Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
Rapid7 released five new Metasploit modules this week, including a full remote code execution chain for Paperclip AI using six API calls, an NTLM relay technique for privilege escalation to SYSTEM on Windows, VS Code extension persistence, and exploits for Xerte Online Toolkits and Linux kernel vulnerabilities. The update also includes an MCP server plugin enabling AI tool integration within msfconsole and improved module check codes with richer diagnostic detail.
Why it matters: Penetration testers and red team operators should review the Paperclip AI and NTLM relay modules immediately if they conduct assessments of these targets, as both enable unauthenticated or low-privilege compromise paths that attackers will likely weaponize quickly.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
Metasploit released five new exploit modules this week, including an unauthenticated remote code execution (RCE) chain for Paperclip AI (CVE-2026-41679), a Windows NTLM relay privilege escalation technique, and a VS Code extension persistence method. The framework also added an MCP server plugin to integrate artificial intelligence (AI) tools directly into msfconsole and enhanced module check codes with richer detail.
Why it matters: Penetration testers and red teamers gain immediate access to new post-exploitation techniques for Windows domain environments and emerging vulnerabilities in web applications and AI systems; organizations running Paperclip AI or Xerte Online Toolkits should prioritize patching CVE-2026-41679 and related CVEs before external reconnaissance can lead to compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
Metasploit released five new modules this week, including an unauthenticated remote code execution (RCE) exploit for Paperclip artificial intelligence (AI) and a VS Code extension persistence technique. A post-exploitation module enables NTLM relay attacks to escalate from low-privilege Windows sessions to SYSTEM access via Shadow Credentials and Kerberos service tickets. The framework also added an MCP server plugin to integrate AI tools directly into msfconsole and enhanced module check codes with richer diagnostic output.
Why it matters: Red teamers and penetration testers can now exploit Paperclip AI instances with default configurations (CVE-2026-41679), escalate Windows privileges via NTLM relay attacks, and maintain persistence through VS Code extensions; blue teams should patch Paperclip and monitor for NTLM relay and extension-based persistence tactics.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
Metasploit released five new modules this week, including an unauthenticated remote code execution (RCE) exploit for Paperclip artificial intelligence (AI) and a VS Code extension persistence technique. A post-exploitation module enables NTLM relay attacks to escalate from low-privilege Windows sessions to SYSTEM access via Shadow Credentials and Kerberos service tickets. The framework also added an MCP server plugin to integrate AI tools directly into msfconsole and enhanced module check codes with richer diagnostic output.
Why it matters: Red teamers and penetration testers can now exploit Paperclip AI instances with default configurations (CVE-2026-41679), escalate Windows privileges via NTLM relay attacks, and maintain persistence through VS Code extensions; blue teams should patch Paperclip and monitor for NTLM relay and extension-based persistence tactics.
- Source published
- First seen by Cybersecurity Tracker