catc0n Profile Banner
Caitlin Condon Profile
Caitlin Condon

@catc0n

Followers
3K
Following
22K
Statuses
16K

Adventurer. Takes a lot of photos, calls many places home. Vulnerability research director at @Rapid7. Opinions mine, etc. She/her.

Boston, MA
Joined October 2010
Don't wanna be here? Send us removal request.
@catc0n
Caitlin Condon
2 years
Same username, probably same “hey I’m hiring” and “here are words about vulnerabilities” posts over at
1
3
17
@catc0n
Caitlin Condon
5 days
RT @Horse_ebooks: Everything happens so much
0
93K
0
@catc0n
Caitlin Condon
13 days
RT @stephenfewer: Great analysis from @the_emmons on the recent SonicWall VPN auth bypass. Hijacking an active client SSL VPN connection is…
0
7
0
@catc0n
Caitlin Condon
14 days
"Nobody is going to patch the printers anyway." —@Percent_X saying the quiet part out loud on a call 😭
2
5
24
@catc0n
Caitlin Condon
14 days
RT @the_emmons: The Rapid7 ETR team just published an analysis of CVE-2024-53704, a SonicWall VPN authentication bypass that was announced…
0
23
0
@catc0n
Caitlin Condon
21 days
RT @ShyBucketGetter: I’d never want the Chinese to get my data. They’d use it to exploit me. That’s why I trust it only with the least expl…
0
4K
0
@catc0n
Caitlin Condon
26 days
RT @mubix: Job opening on my team for a Lead Red Team role:
0
39
0
@catc0n
Caitlin Condon
26 days
Rapid7 MDR has observed CVE-2024-55591 threat activity from known TA IPs, but so far this has been consistent with reconnaissance, not exploitation. We have not linked a CVE to the data dump, but Kevin Beaumont notes possible link to CVE-2022-40684
0
2
3
@catc0n
Caitlin Condon
1 month
RT @catc0n: Rapid7's vulnerability research team is hiring a manager in Dublin, IE to run external CVD, shepherd new 0day research, and lea…
0
4
0
@catc0n
Caitlin Condon
1 month
Nice Google blog with threat intel — note the anti-forensics actions taken by the adversaries
@catc0n
Caitlin Condon
1 month
New Ivanti Connect Secure 0day — I'm sure we'll see Mandiant and MSTIC write-ups on whatever campaign/actor was using CVE-2025-0282 shortly.
0
3
14
@catc0n
Caitlin Condon
1 month
New Ivanti Connect Secure 0day — I'm sure we'll see Mandiant and MSTIC write-ups on whatever campaign/actor was using CVE-2025-0282 shortly.
2
36
124
@catc0n
Caitlin Condon
1 month
Naturally the link is now different 😂 Correct one:
@catc0n
Caitlin Condon
1 month
Rapid7's vulnerability research team is hiring a manager in Dublin, IE to run external CVD, shepherd new 0day research, and lead a small team of exceptionally skilled folks who are uncovering new forms of risk:
0
1
1
@catc0n
Caitlin Condon
1 month
RT @stephenfewer: We now have a @metasploit RCE exploit module in the pull queue for CVE-2024-55956 - an unauthenticated file write vulnera…
0
61
0
@catc0n
Caitlin Condon
1 month
RT @stephenfewer: Fantastic opportunity to join the @rapid7 vuln research team in a manager role🚀
0
1
0
@catc0n
Caitlin Condon
1 month
Rapid7's vulnerability research team is hiring a manager in Dublin, IE to run external CVD, shepherd new 0day research, and lead a small team of exceptionally skilled folks who are uncovering new forms of risk:
0
4
17
@catc0n
Caitlin Condon
1 month
No, Apache Struts CVE-2024-53677 isn't being "actively exploited" to actually compromise production systems. Stop it. You know better. And if you don't, stop saying words on the internet. There are real threats to prioritize.
0
3
15
@catc0n
Caitlin Condon
1 month
TL;DR = evangelizing or even installing security tech for loved ones isn't enough. You've gotta show them how to use those technologies, prove they can work for even non-tech-savvy folks, and help them practice to build confidence and trust.
@rapid7
Rapid7
1 month
🌲 Home for the holidays? In a new piece, @TechCrunch features Rapid7's @catc0n for some timely advice around MFA, password managers and more – perfect for sharing with friends and family. Here's to a secure 2025! Read on ⤵️
0
0
2
@catc0n
Caitlin Condon
2 months
It's been a week, so this is a bit belated, but @rapid7 released a round-up of threat statistics for 2024, with data on most active ransomware groups, most common malware our SOC observed, and notable CVEs.
Tweet media one
0
22
61
@catc0n
Caitlin Condon
2 months
@Sujeet @rapid7 @AttackerKb Thanks for the boost! We're hoping orgs can start looking at / interpreting guidance correctly ASAP. Totally get the confusion on this one based on incorrect public info.
0
0
0
@catc0n
Caitlin Condon
2 months
RT @rapid7: In 2024, our teams responded to 100s of major incidents, vulnerabilities, & ransomware threats — all bolstered by visibility in…
0
2
0