CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 370

As cited

Copy frozen at (site build).

vulnerabilities

Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

Rapid7 released five new Metasploit modules this week, including a full remote code execution chain for Paperclip AI using six API calls, an NTLM relay technique for privilege escalation to SYSTEM on Windows, VS Code extension persistence, and exploits for Xerte Online Toolkits and Linux kernel vulnerabilities. The update also includes an MCP server plugin enabling AI tool integration within msfconsole and improved module check codes with richer diagnostic detail.

Why it matters: Penetration testers and red team operators should review the Paperclip AI and NTLM relay modules immediately if they conduct assessments of these targets, as both enable unauthenticated or low-privilege compromise paths that attackers will likely weaponize quickly.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

Metasploit released five new exploit modules this week, including an unauthenticated remote code execution (RCE) chain for Paperclip AI (CVE-2026-41679), a Windows NTLM relay privilege escalation technique, and a VS Code extension persistence method. The framework also added an MCP server plugin to integrate artificial intelligence (AI) tools directly into msfconsole and enhanced module check codes with richer detail.

Why it matters: Penetration testers and red teamers gain immediate access to new post-exploitation techniques for Windows domain environments and emerging vulnerabilities in web applications and AI systems; organizations running Paperclip AI or Xerte Online Toolkits should prioritize patching CVE-2026-41679 and related CVEs before external reconnaissance can lead to compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

Metasploit released five new modules this week, including an unauthenticated remote code execution (RCE) exploit for Paperclip artificial intelligence (AI) and a VS Code extension persistence technique. A post-exploitation module enables NTLM relay attacks to escalate from low-privilege Windows sessions to SYSTEM access via Shadow Credentials and Kerberos service tickets. The framework also added an MCP server plugin to integrate AI tools directly into msfconsole and enhanced module check codes with richer diagnostic output.

Why it matters: Red teamers and penetration testers can now exploit Paperclip AI instances with default configurations (CVE-2026-41679), escalate Windows privileges via NTLM relay attacks, and maintain persistence through VS Code extensions; blue teams should patch Paperclip and monitor for NTLM relay and extension-based persistence tactics.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

Metasploit released five new modules this week, including an unauthenticated remote code execution (RCE) exploit for Paperclip artificial intelligence (AI) and a VS Code extension persistence technique. A post-exploitation module enables NTLM relay attacks to escalate from low-privilege Windows sessions to SYSTEM access via Shadow Credentials and Kerberos service tickets. The framework also added an MCP server plugin to integrate AI tools directly into msfconsole and enhanced module check codes with richer diagnostic output.

Why it matters: Red teamers and penetration testers can now exploit Paperclip AI instances with default configurations (CVE-2026-41679), escalate Windows privileges via NTLM relay attacks, and maintain persistence through VS Code extensions; blue teams should patch Paperclip and monitor for NTLM relay and extension-based persistence tactics.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary