Corey Thomas
Greater Boston
19K followers
500+ connections
View mutual connections with Corey
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Corey
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Builder and problem solver who loves working with others to create strong organizations.
Activity
19K followers
-
Corey Thomas reposted thisCorey Thomas reposted thisAppSec remediation and endpoint remediation are not the same problem. That distinction matters more now because much of the conversation about AI remediation has centered on code. Understand the dependency chain. Determine whether a vulnerable component is reachable. Identify whether the exploitable condition exists. Propose a workaround. Open a PR. Refactor the code. That is valuable work. It is not what we do at furl. We focus on autonomous endpoint remediation: changing the state of systems already running across an enterprise. Sometimes that means installing a vendor patch. Other times it means upgrading or uninstalling software, changing a configuration, applying a hardening control, or mitigating risk when no immediate fix exists. Then you have to verify that the change worked, confirm the exposure actually closed, and roll back safely if it didn't. Doing that autonomously absolutely requires context. You need to understand the endpoint, its software and configuration, dependencies, ownership, prior state, maintenance windows, approval requirements, and the boundaries within which the system is allowed to act. Building and maintaining that understanding is a prerequisite for safe autonomous remediation. But it isn't the remediation itself. Knowing that an endpoint is vulnerable is not fixing it. Understanding why it's vulnerable is not fixing it. Knowing how its components relate is not fixing it. Determining that it's exploitable is not fixing it. Eventually, something has to change on the system. That's the execution problem. And I think security has historically invested much more heavily in understanding, detecting, and prioritizing risk than in increasing our capacity to actually eliminate it. AppSec and endpoint remediation are parts of the same larger problem, but they operate at different layers. Code gets compiled, packaged, and deployed onto IT systems. Those systems accumulate vulnerable software, misconfigurations, legacy components, and hardening gaps that still have to be addressed. AI has enormous potential across that entire stack. No one company is going to solve every layer. We chose to go very deep on endpoints. Because knowing exactly what's wrong is necessary. Actually fixing it is a different problem.
-
Corey Thomas posted thisI’ve had the extreme privilege of leading Rapid7 for over 13 years, and today I am thrilled to welcome Wael Mohamed to the company as our new CEO, as I transition into my new role as Executive Chairman. Rapid7 is home to some of the most curious, brilliant, and compassionate people in cybersecurity. I am confident in Wael’s ability to continue driving our preemptive security strategy — effectively integrating MDR and exposure management into AI-led security operations to preempt attackers at machine speed. It has been an honor to lead Rapid7 through significant milestones: shaping cybersecurity research policy, leading the shift from traditional vulnerabilty management to threat aware exposure mangement, going from launching our MDR business to becoming one of the top MDR vendors in the world— to name just a few — and through it all, helping customers and business leaders navigate the constantly shifting technology landscape. As Executive Chairman, I look forward to focusing on our technology vision, the AI landscape and strategy, and continuing to drive momentum around policy that will help our customers stay secure. As it has been from the Metasploit days, I remain deeply passionate about community-focus and industry engagement as the two most important forces to drive meaningful change in cybersecurity. This marks an important moment for Rapid7 as we continue strengthening our position as a leader in the emerging AI-SOC market, and I couldn't be more excited for the chapter ahead. Please join me in giving Wael a warm welcome to the Rapid7 team!
-
Corey Thomas shared thisYou can't build trust in AI without transparency, and as AI gets embedded in security operations, leaders expect to understand how decisions are made. Thank you, Craig Adams for a great conversation - the future of MDR is bright.Corey Thomas shared this⏱️ AI is accelerating everything in cybersecurity. The question now is whether our defenders are accelerating with it. Rapid7's 'Experts on Experts' video series is back! To kick off Season 2, Chief Product Officer Craig Adams sat down with our CEO, Corey Thomas, to talk about what AI is changing inside security operations – and what it isn’t. 🧵 Set the stage with a quick companion blog: r-7.co/3PFVGbQ ▶️ Or jump right into the full conversation on YouTube: r-7.co/4v2Iiyw
-
Corey Thomas shared thisWhen I talk with security leaders, something I often hear is that they’re chasing measurable impact. At Rapid7, our mission is to simplify access to security outcomes from risk to response. We built the Command Platform to unify all your data, not just what we collect, so your organization gets the facts of your environment from the beginning. This week, we took another leap toward our mission with the launch of Incident Command, our upgraded next-gen SIEM. Incident Command delivers all the benefits of the Command Platform plus broadened access to our decades of SOC expertise, with agentic AI built into the workflows security teams use every day. We have seen the incredible value of these features at work in our own SOC, and now we’re bringing that same value to our customers directly within the tools they use. Proud of the Rapid7 team that brought this to life. Excited for what this means for security leaders everywhere: https://r-7.co/4o2cKp0Press Release: Rapid7 Launches Incident Command: AI-Native SIEM Empowers Analysts to Act with Speed and Precision from Risk to Response - Rapid7Press Release: Rapid7 Launches Incident Command: AI-Native SIEM Empowers Analysts to Act with Speed and Precision from Risk to Response - Rapid7
-
Corey Thomas reposted thisCorey Thomas reposted this🚨🚨 Introducing Intelligence Hub, Rapid7’s integrated threat intelligence solution available via our Command Platform. 🚨🚨 Intelligence Hub was designed to empower security teams with curated, actionable insights to help teams confidently answer two pressing questions from their Leadership Teams and CISO's: 1. What do we know about the threat group and the associated IOCs, CVEs, or TTPs? 2. Are we currently impacted or at risk, and what is our coverage status (including estimated time to detection or mitigation)? No more noise—just the intel you need to act fast and stay ahead. Check out Craig Adams & Raj Samani's blog or the Official Rapid7 Press Release below. Blog: https://lnkd.in/eiKZMrSF Press Release: https://lnkd.in/eaXWvzJf #ThreatIntelligence #CyberSecurity #InfoSec #SecurityOperations #CyberThreats #RSAC
-
Corey Thomas reposted thisCorey Thomas reposted thisIntroducing Rapid7 MDR for Enterprise, built specifically for large, complex organizations spanning the cloud, on-premises, legacy systems & proprietary applications. Expert-led, deeply customized, and fully aligned with your environment. Take command of your enterprise-scale risk: https://r-7.co/42ZgVJM. Innovation is on fire at Rapid7!
-
Corey Thomas reposted thisCorey Thomas reposted thisA statement from Rapid7 and CEO Corey Thomas: Much of the world awoke to the shocking news coming out of Israel this morning. We condemn this act of terrorism and our thoughts are with our Israeli employees and the people of Israel as we watch the events with a great deal of sadness. We are in contact with our team on the ground and working to provide support to them, their families, and those employees who’ve already been called into service. We will continue to watch the situation carefully so that we can best support our team’s safety and well-being.
-
Corey Thomas shared thisAmazing mission, company and founders.Corey Thomas shared thisGrowing up, my family was poor. I mean, poor, poor. Everyday was an exercise in survival, and, as a young person, that has a profound impact on how you view yourself and the world around you. For me that has meant knowing (1) that I am blessed to live the life I do today, and (2) that so many others do not have the same opportunities. One of the most devastating ways I see this disparity play out is in the space of health and wellness. Even as a “successful person” by most standards of the world, I have watched the destructive legacies of health inequity impact my own family. Which is why my dear friend Carmichael Roberts and I co-founded WellWithAll, a health and wellness company built on the premise that we all deserve healthy lives and the opportunity to thrive. Starting with our initial line of vitamins and supplements aimed at improving everyday health, we hope to empower folks with the tools they need to create healthier outcomes for themselves and their families. Beyond the products we make, we are committing 20% of our profits to the communities we serve, with a goal of investing $300 million over 10 years in Black, Brown, and low-income communities, where the brunt of health inequity is felt hardest. We look forward to having you on this journey with us! Visit WellWithAll.com to learn more about our story, and become part of our growing community on Instagram @wellwithall_.
-
Corey Thomas posted thisI’m deeply saddened by the loss of Philippe Courtot. He was not just a pioneer in the tech industry, but also a man I profoundly respected. I will always recall with fondness our dinners together spent in conversation on technology, business, and life.
-
Corey Thomas reacted on thisCorey Thomas reacted on thisI'm thrilled to share that I've joined Gradient AI as Chief Product Officer. I've spent my career building technology products that solve complex problems, and I can't think of a more exciting one to tackle next. Insurance is fundamentally a data and decision business. Every day, insurers make millions of decisions about which risks to take, how to price them, how to manage claims, and where to focus their resources. The quality of those decisions directly impacts both financial performance and the people they serve. AI is going to revolutionize how all of it gets done. What drew me to Gradient AI is the combination of deep insurance expertise, proprietary data, and AI purpose-built for the industry. The result is technology that goes beyond automating workflows - it improves the quality and economics of insurance decisions and, ultimately, patient lives. Gradient AI is already working with hundreds of insurance organizations across health, property & casualty, and workers' compensation. I'm excited to join Stan Smith and the entire Gradient AI team at this point in the company's journey. My focus will be on building on the strong foundation the team has created, accelerating product innovation, and helping our customers operate at speed — so consumers can get the care they need, affordably. The opportunity ahead is enormous, and we are just getting started. 🔗 https://www.gradientai.com #GradientAI #Insurance #AI #ProductLeadership #InsurTech #NewRoleAI-Powered Intelligence for Insurance | Gradient AIAI-Powered Intelligence for Insurance | Gradient AI
-
Corey Thomas liked thisCorey Thomas liked thisAppSec remediation and endpoint remediation are not the same problem. That distinction matters more now because much of the conversation about AI remediation has centered on code. Understand the dependency chain. Determine whether a vulnerable component is reachable. Identify whether the exploitable condition exists. Propose a workaround. Open a PR. Refactor the code. That is valuable work. It is not what we do at furl. We focus on autonomous endpoint remediation: changing the state of systems already running across an enterprise. Sometimes that means installing a vendor patch. Other times it means upgrading or uninstalling software, changing a configuration, applying a hardening control, or mitigating risk when no immediate fix exists. Then you have to verify that the change worked, confirm the exposure actually closed, and roll back safely if it didn't. Doing that autonomously absolutely requires context. You need to understand the endpoint, its software and configuration, dependencies, ownership, prior state, maintenance windows, approval requirements, and the boundaries within which the system is allowed to act. Building and maintaining that understanding is a prerequisite for safe autonomous remediation. But it isn't the remediation itself. Knowing that an endpoint is vulnerable is not fixing it. Understanding why it's vulnerable is not fixing it. Knowing how its components relate is not fixing it. Determining that it's exploitable is not fixing it. Eventually, something has to change on the system. That's the execution problem. And I think security has historically invested much more heavily in understanding, detecting, and prioritizing risk than in increasing our capacity to actually eliminate it. AppSec and endpoint remediation are parts of the same larger problem, but they operate at different layers. Code gets compiled, packaged, and deployed onto IT systems. Those systems accumulate vulnerable software, misconfigurations, legacy components, and hardening gaps that still have to be addressed. AI has enormous potential across that entire stack. No one company is going to solve every layer. We chose to go very deep on endpoints. Because knowing exactly what's wrong is necessary. Actually fixing it is a different problem.
-
Corey Thomas liked thisCorey Thomas liked thisAt our 2026 #AnnualMeeting, Chamber President & CEO Jim Rooney reminded us why Greater Boston has always been — and continues to be — a place where bold ideas, business leadership, and civic purpose come together. He began by congratulating our newest Distinguished Bostonians — Kevin Churchwell, Catherine D'Amato, and Paul Ayoub — whose leadership and impact exemplify the very best of our region and its business community. Jim also reflected on the importance of strong, values-driven leadership, thanking Chamber Board Chair Corey Thomas for two years of visionary, collaborative leadership that strengthened our advocacy, sharpened our focus on emerging issues, and deepened the Chamber’s impact across the region. He then welcomed incoming Board Chair Miceal Chamberlain, praising his longstanding commitment to community, economic growth, and inclusive prosperity and expressing confidence in his ability to lead the Chamber into its next chapter. Throughout his remarks, Jim brought the evening’s theme — Revolutionary Past. Visionary Future. — to life by reflecting on Boston’s central role in America’s founding. He drew a powerful connection between the entrepreneurs, thinkers, and businesses that helped spark a revolution 250 years ago and today’s business leaders who are shaping what comes next. Looking ahead, Jim struck a note of optimism and responsibility, acknowledging the very real challenges facing our region while reinforcing the Chamber’s role as a convener, connector, and champion of growth: “We know that what happens in Boston changes the world. We know that the next era of success for this region and this country can be built today, right here in Massachusetts.” With gratitude for our past, confidence in our leadership, and belief in the power of business to drive progress, his message was clear: Greater Boston’s best days are ahead — and we will shape that future together.
-
Corey Thomas liked thisCorey Thomas liked thisThe security industry has spent two decades getting brilliant at finding risk. More signals. A lot of dashboards. Multiple scanners. Almost nothing on the other half: fixing the risk. The time to remediate used to be measured in days and weeks. That window has collapsed, attackers move in hours. There needs to be a shift in remediation culture. We believe Furl is the catalyst for that change. One of the main reasons I partnered with Derek Abdine is his conviction on the Rubik's Cube of remediation. Not just patching an exploitable CVE, but hygiene, compliance, configuration management, and much more. The long tail of work that makes an environment safe instead of just observed. Remediation is the work no one wants to touch. It's messy. It crosses teams. It breaks things. So vendors stayed upstream, the commodity side of the problem. At Furl, we wanted to be the team that takes the hard half. Today, Furl is generally available. We've built something to deliver real value to our customers and we have the team to back it up. With incredible partners, investors, and customers furl is moving into the next chapter. cc: Christina Luconi Ten Eleven Ventures Open Opportunity Fund Mark H. Paul Judge Corey Thomas
-
Corey Thomas liked thisI am incredibly proud to share that Rapid7’s 2026 Global Threat Landscape Report: Decoding the Accelerated Cyber Attack Cycle is officially live! 🚀 Myself and my team poured a massive amount of effort into this research, and seeing it finally out in the wild is truly rewarding. A huge shoutout to everyone involved in bringing this together! 👏 H/T Stephen Fewer, Ryan Emmons, Jonah Burgess, Deral Heiland, Raj Samani Christiaan Beek Stacey Holleran Here are a few of the most critical findings we uncovered in the report: 📈 Exploitations have doubled: Exploited high and critical-severity vulnerabilities surged by 105% year-over-year (jumping from 71 in 2024 to 146 in 2025). ⏱️ Weaponization timelines are collapsing: The median time from vulnerability publication to CISA KEV inclusion dropped from 8.5 days to just 5.0 days. 🔓 Identity exposure remains the top intrusion path: Valid accounts with missing or lax MFA accounted for a massive 43.9% of all our incident response investigations. 🚨 Ransomware is highly industrialized: Total ransomware leak posts increased 46.4% YoY, and ransomware was involved in 42% of our MDR investigations. Check out the press release and get the full report! 👇Corey Thomas liked thisThe 2026 threat landscape is moving faster than most security programs can keep up with. New research from Rapid7 Labs shows: • Exploited high and critical vulnerabilities increased 105% year over year • 43.9% of incident response cases began with valid accounts without MFA • 42% of Rapid7 MDR investigations involved ransomware The window between vulnerability disclosure and exploitation is collapsing, turning exposure into compromise in days, not weeks. For organizations, this emphasizes the need to move from reactive to preemptive security operations. 📰 Read the press release: https://r-7.co/4sjIDvd 💼 Download the 2026 Global Threat Landscape Report: https://r-7.co/3PicnK6
-
Corey Thomas reacted on thisIndependence is for physicians, too. Proud of my sister-in-law Dr. Raina Gazurian for standing up to our challenged healthcare system and creating an alternative that delivers personalized and transparent care. The parallels between medicine and wealth management are fascinating to me… physicians are moving away from large systems just like breakaway advisors. And it’s working, because consumers are voting with their feet. 🙌🏽 This is the type of care I’m grateful to have in my family, and I’d love to share with yours. If you are in the Philly area please check out Lanai Health! 😃Corey Thomas reacted on thisI want to put the "primary" back in primary care. Primary care shouldn't be rushed, hard to get into, or episodic. It should be a longterm relationship with a physician who knows your story and is your first stop when you don't feel your best--and, more importantly, when you are well and want to stay that way. At Lanai Health--my direct primary care practice in Doylestown, PA--I provide primary care that is affordable, accessible, and personalized. www.lanai-health.com Danielle Taylor
Volunteer Experience
Patents
-
Methods and systems for testing and analyzing vulnerabilities of computing systems based on exploits of the vulnerabilities
Filed US US 20110191854 A1
A security tool can identify vulnerabilities in a computing system and determine a risk level of the vulnerabilities. The security tool can determine the risk level based on exploits associated with the vulnerabilities. The security tool can determine the risk level based on factors associated with the exploits such as whether an exploit exists, a rank of the exploit, a number of exploits that exist for the vulnerability, a difficulty to identify whether the exploit exists, and an effect of the…
A security tool can identify vulnerabilities in a computing system and determine a risk level of the vulnerabilities. The security tool can determine the risk level based on exploits associated with the vulnerabilities. The security tool can determine the risk level based on factors associated with the exploits such as whether an exploit exists, a rank of the exploit, a number of exploits that exist for the vulnerability, a difficulty to identify whether the exploit exists, and an effect of the exploit on the vulnerability. The security tool can a report identifying the vulnerabilities of the computing system, the exploits associated with the vulnerabilities, and the risk level of the vulnerabilities. The report can also include links to information about the exploits.
Other inventorsSee patent
Languages
-
Spanish
-
Recommendations received
4 people have recommended Corey
Join now to viewView Corey’s full profile
-
See who you know in common
-
Get introduced
-
Contact Corey directly
Other similar profiles
Explore more posts
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content