Rapid7 Cuts 314 Jobs; Boeing 737 Hack Demo; Fridge Flaws
Rapid7 will cut 314 jobs. Researchers showed a coin-sized device can access Boeing 737 systems. Claroty found RCE flaws in Copeland XWEB Pro and Danfoss AK-SM 800A controllers, now patched.
Rapid7 announced it will eliminate 314 positions, about 12% of its workforce, under a restructuring led by CEO Wael Mohamed. The company expects up to $11 million in severance and related costs and plans to refocus resources on product modernization and artificial intelligence features for its core security platform. Rapid7 outlined a goal of lifting its non-GAAP operating margin to 20% by the fourth quarter of 2026 and said operations will continue as the company implements the changes.
A team of academic security researchers demonstrated that a coin-sized hardware device attached to an external aircraft port can give an attacker access to certain systems on a Boeing 737. The device was shown to spoof sensor inputs such as outside air temperature and aircraft weight and could be used to alter a flight plan. The researchers noted that existing aircraft safety systems would likely prevent direct harm during normal operations. The test involved installing a small covert implant on an external port and observing how manipulated inputs affected onboard operational data.
Claroty’s Team82 reported 23 vulnerabilities in Copeland XWEB Pro refrigeration controllers, including flaws that can be chained to bypass controls and achieve root-level remote code execution. In a demonstration, a compromised controller was able to change the behavior of cooling fans and compressors while concealing resulting temperature increases, creating a risk of undetected food spoilage. Team82 also identified multiple vulnerabilities, including remote code execution, in Danfoss AK-SM 800A controllers. Copeland and Danfoss released patches after the issues were reported and provided mitigation guidance for customers.
The Rapid7 restructuring affects a range of roles across the company as leadership concentrates on consolidating the platform and adding AI capabilities. The aviation experiment involved physical access to an aircraft port and tested how a concealed implant could provide persistent connectivity and a foothold for further manipulation. For the refrigeration findings, vendors and researchers recommended applying available patches, segmenting control systems from enterprise networks, and restricting remote access to controllers.
Each disclosure was shared with the affected parties and followed by mitigations: Rapid7 published expected costs and timing for its restructuring, the aircraft researchers made their findings available to prompt security reviews of external ports and maintenance procedures, and refrigeration vendors issued fixes and guidance to customers.








