<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Caitlin Condon &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/caitlin-condon/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Mon, 28 Apr 2025 11:57:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Active exploitation of SAP NetWeaver Visual Composer CVE-2025-31324</title>
		<link>https://noise.getoto.net/2025/04/28/active-exploitation-of-sap-netweaver-visual-composer-cve-2025-31324/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Mon, 28 Apr 2025 11:57:12 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=585e735948850f5c4503d5a7910daa78</guid>

					<description><![CDATA[A critical SAP NetWeaver zero-day vulnerability (CVE-2025-31324) that allows for full SAP server compromise is being actively exploited in the wild.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/04/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Apache Tomcat CVE-2025-24813: What You Need to Know</title>
		<link>https://noise.getoto.net/2025/03/19/apache-tomcat-cve-2025-24813-what-you-need-to-know/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Wed, 19 Mar 2025 17:40:52 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=0b6bdde08532a2c03d0cd0f384936118</guid>

					<description><![CDATA[<p>Here at Rapid7, our usual bar for calling a vulnerability an emergent threat is either known exploitation at scale, or likelihood of exploitation at scale. Apache Tomcat <a href="https://attackerkb.com/topics/4GajxQH17l/cve-2025-24813">CVE-2025-24813</a> fulfills neither of these criteria, despite a variety of news headlines alleging broad exploitation in the wild. Tomcat is widely deployed and</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/03/etr-banner-2.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Fortinet firewalls hit with new zero-day attack, older data leak</title>
		<link>https://noise.getoto.net/2025/01/16/fortinet-firewalls-hit-with-new-zero-day-attack-older-data-leak/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Thu, 16 Jan 2025 15:57:23 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ab31e768b64e3083f4d837e3621f409a</guid>

					<description><![CDATA[Rapid7 is responding to two separate events affecting Fortinet firewall customers: Zero-day exploitation of CVE-2024-55591 in FortiOS, and a large-scale data leak of older FortiGate firewall IPs, passwords, and configs.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/01/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2025-0282: Ivanti Connect Secure zero-day exploited in the wild</title>
		<link>https://noise.getoto.net/2025/01/08/cve-2025-0282-ivanti-connect-secure-zero-day-exploited-in-the-wild/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Wed, 08 Jan 2025 18:13:13 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=01050d3f41f01c12c034a865ebd66d66</guid>

					<description><![CDATA[Two stack-based buffer overflow issues were disclosed in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA. CVE-2025-0282, the more severe of the two issues, has been exploited in the wild against Ivanti Connect Secure devices.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/01/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Zero-day exploitation targeting Palo Alto Networks firewall management interfaces</title>
		<link>https://noise.getoto.net/2024/11/15/zero-day-exploitation-targeting-palo-alto-networks-firewall-management-interfaces/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Fri, 15 Nov 2024 12:44:09 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e21b583a0596f6623214eed7c3ff4b03</guid>

					<description><![CDATA[Palo Alto Networks has indicated they are observing threat activity exploiting a zero-day unauthenticated remote command execution vulnerability in their firewall management interfaces.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/11/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Fortinet FortiManager CVE-2024-47575 Exploited in Zero-Day Attacks</title>
		<link>https://noise.getoto.net/2024/10/23/fortinet-fortimanager-cve-2024-47575-exploited-in-zero-day-attacks/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Wed, 23 Oct 2024 16:21:47 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=1401007d29ae885e7a8a27f39328be21</guid>

					<description><![CDATA[On Wednesday, October 23, 2024, security company Fortinet published an advisory on CVE-2024-47575, a critical zero-day vulnerability affecting their FortiManager network management solution.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/10/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Unauthenticated CrushFTP Zero-Day Enables Complete Server Compromise</title>
		<link>https://noise.getoto.net/2024/04/23/unauthenticated-crushftp-zero-day-enables-complete-server-compromise/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Tue, 23 Apr 2024 15:26:06 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e6563063f150e6def29127a1c2f7b927</guid>

					<description><![CDATA[CVE-2024-4040 is an unauthenticated zero-day vulnerability in managed file transfer software CrushFTP. Successful exploitation allows for arbitrary file read as root, authentication bypass for administrator account access, and remote code execution.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/04/emergent-threat-banner-1-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2024-3400: Critical Command Injection Vulnerability in Palo Alto Networks Firewalls</title>
		<link>https://noise.getoto.net/2024/04/12/cve-2024-3400-critical-command-injection-vulnerability-in-palo-alto-networks-firewalls/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Fri, 12 Apr 2024 12:59:48 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=26feb6d8b9cab5030636fb1d175ad84a</guid>

					<description><![CDATA[On Friday, April 12, Palo Alto Networks published an advisory on CVE-2024-3400, a CVSS 10 vulnerability in several versions of PAN-OS, the operating system that runs on the company’s firewalls. CVE-2024-3400 allows for arbitrary code execution as root.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/04/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2024-0204: Critical Authentication Bypass in Fortra GoAnywhere MFT</title>
		<link>https://noise.getoto.net/2024/01/23/cve-2024-0204-critical-authentication-bypass-in-fortra-goanywhere-mft/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Tue, 23 Jan 2024 18:42:31 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ea9e7b4804ccd335561e44ef90293c3f</guid>

					<description><![CDATA[On January 22, 2024, Fortra published a security advisory on CVE-2024-0204, a critical authentication bypass affecting its GoAnywhere MFT secure managed file transfer product prior to version 7.4.1.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/01/emergent-threat-banner-1-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Zero-Day Exploitation of Ivanti Connect Secure and Policy Secure Gateways</title>
		<link>https://noise.getoto.net/2024/01/11/zero-day-exploitation-of-ivanti-connect-secure-and-policy-secure-gateways/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Thu, 11 Jan 2024 13:00:40 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=a65cc7d51bf22d1f65417f2debf7c7b4</guid>

					<description><![CDATA[CVE-2023-46805 and CVE-2024-21887 are zero-day vulnerabilities affecting Ivanti Connect Secure and Ivanti Policy Secure gateways. They have been exploited in the wild to gain access to corporate networks and conduct a range of nefarious activities, including backdooring legitimate files.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/01/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-47246: SysAid Zero-Day Vulnerability Exploited By Lace Tempest</title>
		<link>https://noise.getoto.net/2023/11/09/cve-2023-47246-sysaid-zero-day-vulnerability-exploited-by-lace-tempest/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Thu, 09 Nov 2023 14:12:55 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=aeed4d36b077eccfca3b83af18a18165</guid>

					<description><![CDATA[A new zero-day vulnerability (CVE-2023-47246) in SysAid IT service management software is being exploited by the threat group responsible for the MOVEit Transfer attack in May 2023.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/11/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-20198: Active Exploitation of Cisco IOS XE Zero-Day Vulnerability</title>
		<link>https://noise.getoto.net/2023/10/17/cve-2023-20198-active-exploitation-of-cisco-ios-xe-zero-day-vulnerability/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Tue, 17 Oct 2023 19:50:03 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=03c5f815ef444693e9663c8d609a26d3</guid>

					<description><![CDATA[On Monday, October 16, Cisco’s Talos group published a blog on an active threat campaign exploiting CVE-2023-20198, a “previously unknown” zero-day vulnerability in the web UI component of Cisco IOS XE software.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/10/emergent-threat-banner-2.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-22515: Zero-Day Privilege Escalation in Confluence Server and Data Center</title>
		<link>https://noise.getoto.net/2023/10/04/cve-2023-22515-zero-day-privilege-escalation-in-confluence-server-and-data-center/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Wed, 04 Oct 2023 15:28:53 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=0020b058392816674afc320d3aea550f</guid>

					<description><![CDATA[On October 4, 2023, Atlassian published a security advisory on CVE-2023-22515, a critical privilege escalation vulnerability affecting on-premises instances of Confluence Server and Confluence Data Center.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/10/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Critical Vulnerabilities in WS_FTP Server</title>
		<link>https://noise.getoto.net/2023/09/29/critical-vulnerabilities-in-ws_ftp-server/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Fri, 29 Sep 2023 13:33:05 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=7c95eeb2803d4c084da21e4086821121</guid>

					<description><![CDATA[<p>On September 27, 2023, Progress Software published a security advisory on multiple vulnerabilities affecting <a href="https://www.ipswitch.com/ftp-server">WS_FTP Server</a>, a secure file transfer solution. There are a number of vulnerabilities in the advisory, two of which are critical (CVE-2023-40044 and CVE-2023-42657). </p><p>Rapid7 is not aware of any exploitation in the wild as</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/09/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-42793: Critical Authentication Bypass in JetBrains TeamCity CI/CD Servers</title>
		<link>https://noise.getoto.net/2023/09/25/cve-2023-42793-critical-authentication-bypass-in-jetbrains-teamcity-ci-cd-servers/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Mon, 25 Sep 2023 17:32:48 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ae4534b1167aaa21fcdc6efabc8c56a3</guid>

					<description><![CDATA[On September 20, 2023, JetBrains disclosed CVE-2023-42793, a critical authentication bypass vulnerability in on-premises instances of their TeamCity CI/CD server. Successful exploitation could make the vulnerability a potential supply chain attack vector.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/09/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Critical Zero-Day Vulnerability in Citrix NetScaler ADC and NetScaler Gateway</title>
		<link>https://noise.getoto.net/2023/07/18/critical-zero-day-vulnerability-in-citrix-netscaler-adc-and-netscaler-gateway/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Tue, 18 Jul 2023 15:28:45 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3ecbd851d3460355d2abf3f8318d0e2c</guid>

					<description><![CDATA[Citrix has published a security bulletin warning users of three new vulnerabilities affecting NetScaler ADC and NetScaler Gateway.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/07/GettyImages-1185282377-2.jpg" length="0" type="" />

			</item>
		<item>
		<title>Active Exploitation of Multiple Adobe ColdFusion Vulnerabilities</title>
		<link>https://noise.getoto.net/2023/07/17/active-exploitation-of-multiple-adobe-coldfusion-vulnerabilities/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Mon, 17 Jul 2023 19:48:51 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=376f0b49aba7671b059c700076d0c5c6</guid>

					<description><![CDATA[Rapid7 managed services teams have observed exploitation of Adobe ColdFusion in multiple customer environments.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/07/GettyImages-1185282377-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>SonicWall Recommends Urgent Patching for GMS and Analytics CVEs</title>
		<link>https://noise.getoto.net/2023/07/13/sonicwall-recommends-urgent-patching-for-gms-and-analytics-cves/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Thu, 13 Jul 2023 14:56:13 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=f8e947b78d57cb73762e22b0e79a628c</guid>

					<description><![CDATA[SonicWall published an urgent security advisory on July 12, 2023 warning customers of new vulnerabilities affecting their GMS and Analytics products.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/07/GettyImages-1185282377.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-2868: Total Compromise of Physical Barracuda ESG Appliances</title>
		<link>https://noise.getoto.net/2023/06/08/cve-2023-2868-total-compromise-of-physical-barracuda-esg-appliances/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Thu, 08 Jun 2023 16:52:32 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=410e46ab5b6d5008c00e28838ff3a70a</guid>

					<description><![CDATA[Rapid7 incident response teams are investigating exploitation of physical Barracuda Networks Email Security Gateway (ESG) appliances.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/06/GettyImages-1185282377-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>Rapid7 Observed Exploitation of Critical MOVEit Transfer Vulnerability</title>
		<link>https://noise.getoto.net/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Thu, 01 Jun 2023 15:23:53 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=658fe67d6530b2c9405d7154ab2eb73f</guid>

					<description><![CDATA[Rapid7 managed services teams are observing exploitation of a critical vulnerability in Progress Software’s MOVEit Transfer solution across multiple customer environments.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/06/GettyImages-1185282377.jpg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 25/245 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-02-07 03:17:22 by W3 Total Cache
-->