Get an instant alert the moment a critical CVE turns up
Every morning, WebRun opens Rapid7 InsightVM, checks for newly discovered critical severity vulnerabilities, logs each one to an Airtable register with the affected asset and a remediation owner, and posts an alert note to Notion when a new critical finding appears.
- No credit card
- Under $0.01 per run
- Cancel anytime
How do I find out immediately when Rapid7 InsightVM finds a new critical vulnerability?
WebRun checks Rapid7 InsightVM every morning for newly discovered critical severity vulnerabilities, logs each one to an Airtable register with the affected asset and a remediation owner, and posts an alert note to Notion the same day it's found. It never patches anything itself, only flags and assigns the finding for action.
- New critical findings get an owner the same day they're discovered
- Every critical vulnerability has a tracked record instead of a buried scan result
- Quiet days with no new critical findings produce no noise
Built for vulnerability management teams · security engineers · IT admins · DevSecOps teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.rapid7.comin a real browser with your saved login - no setup, no API keys. -
1
Rapid7 - check for new critical findings
WebRun opens Rapid7 to check for new critical findings. - Open Rapid7 InsightVM and check for vulnerabilities discovered since yesterday
- Filter to critical severity findings
- Note the affected asset and likely remediation owner for each
Done when Any new critical finding since yesterday is listed with asset and owner.
-
2
Airtable - log the finding with an owner
WebRun opens Airtable to log the finding with an owner. - Open the vulnerability register in Airtable
- Add a row for each new critical finding with asset, owner, and discovery date
- Leave the status open until remediation is confirmed
Done when Every new critical finding has a row in the Airtable register.
-
3
Notion - post the alert note
WebRun opens Notion to post the alert note. - Open the security runbook page in Notion
- Post an alert note naming the asset and owner for each new critical finding
- Skip posting on days with no new critical findings
Done when Notion has an alert note only on days a new critical finding appeared.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does WebRun patch the vulnerability itself?
No. WebRun only detects, logs, and assigns an owner. Patching or remediating the vulnerability is a manual step for your engineering team.
Does it scan for new vulnerabilities itself?
No. It only reads findings from scans Rapid7 InsightVM already ran. Running a new scan stays a manual action.
What if there's no new critical finding today?
Then nothing posts. The Notion alert only appears on days a new critical severity finding actually shows up.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.