<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Erick Galinkin &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/erick-galinkin/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Thu, 09 Feb 2023 18:36:28 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Nearly 19,000 ESXi Servers Still Vulnerable to CVE-2021-21974</title>
		<link>https://noise.getoto.net/2023/02/09/nearly-19000-esxi-servers-still-vulnerable-to-cve-2021-21974/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Thu, 09 Feb 2023 18:36:28 +0000</pubDate>
				<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=68d29b7690846a3122a1f9fe36f4fdd5</guid>

					<description><![CDATA[Rapid7 research has found that nearly 19,000 ESXi servers likely remain vulnerable to CVE-2021-21974, which is being exploited in the ESXiArgs campaign.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/02/GettyImages-1331944718.jpg" length="0" type="" />

			</item>
		<item>
		<title>Leaked Android Platform Certificates Create Risks for Users</title>
		<link>https://noise.getoto.net/2022/12/02/leaked-android-platform-certificates-create-risks-for-users/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Fri, 02 Dec 2022 21:45:15 +0000</pubDate>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=2e360c6f21f3d47b3f84e41304e4b8f3</guid>

					<description><![CDATA[A new report contains 10 different platform certificates and malware sample SHA256 sums where the malware sample had been signed by a platform certificate.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/12/emergent-threats-series-hero-background.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-42889: Keep Calm and Stop Saying &#8220;4Shell&#8221;</title>
		<link>https://noise.getoto.net/2022/10/17/cve-2022-42889-keep-calm-and-stop-saying-4shell/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Mon, 17 Oct 2022 20:36:16 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=f7ba3352d40fae34a5ec64e58595ed85</guid>

					<description><![CDATA[<p>CVE-2022-42889, which some have begun calling “Text4Shell,” is a vulnerability in the popular Apache Commons Text library that can result in code execution when processing malicious input. The vulnerability was announced on October 13, 2022 on the <a href="https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om">Apache dev list</a>. CVE-2022-42889 arises from insecure implementation of Commons Text’s variable</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/10/hero-art-blog.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Architecting for Extortion: Acting on the IST’s Blueprint for Ransomware Defense</title>
		<link>https://noise.getoto.net/2022/09/02/architecting-for-extortion-acting-on-the-ists-blueprint-for-ransomware-defense/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Fri, 02 Sep 2022 13:15:00 +0000</pubDate>
				<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=0dd00d549fa9bc3bafbf86da74a4eb12</guid>

					<description><![CDATA[Last month, the Institute for Security and Technology’s  Ransomware Task Force launched the Blueprint for Ransomware Defense.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/09/ist-ransomware-blueprint.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-27511: Citrix ADM Remote Device Takeover</title>
		<link>https://noise.getoto.net/2022/06/16/cve-2022-27511-citrix-adm-remote-device-takeover/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Thu, 16 Jun 2022 20:03:55 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=c3fb7b0ba665ac291b6331292f32f47a</guid>

					<description><![CDATA[On Monday, June 14, 2022, Citrix published an advisory on CVE-2022-27511, a critical improper access control vulnerability affecting their ADM product.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/06/citrix-adm-etr.jpg" length="0" type="" />

			</item>
		<item>
		<title>8 Tips for Securing Networks When Time Is Scarce</title>
		<link>https://noise.getoto.net/2022/03/22/8-tips-for-securing-networks-when-time-is-scarce/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Tue, 22 Mar 2022 15:44:09 +0000</pubDate>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Russia-Ukraine Conflict]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e35b64e8da1151a3f291fb78488ebb29</guid>

					<description><![CDATA[In light of increased cyber risk surrounding the Russia-Ukraine conflict, we’ve put together 8 tips that defenders can take right now to prepare.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/03/8-tips.jpg" length="0" type="" />

			</item>
		<item>
		<title>2022 Planning: Metrics That Matter and Curtailing the Cobra Effect</title>
		<link>https://noise.getoto.net/2022/01/18/2022-planning-metrics-that-matter-and-curtailing-the-cobra-effect/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Tue, 18 Jan 2022 15:53:09 +0000</pubDate>
				<category><![CDATA[2022 Planning]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3571a6657384ffbf732b596df47a5a6f</guid>

					<description><![CDATA[Creating metrics in cybersecurity is hard enough, but creating metrics that matter is a harder challenge still.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/01/2022-planning-metrics.jpg" length="0" type="" />

			</item>
		<item>
		<title>Being Naughty to See Who Was Nice: Machine Learning Attacks on Santa’s List</title>
		<link>https://noise.getoto.net/2022/01/14/being-naughty-to-see-who-was-nice-machine-learning-attacks-on-santas-list/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Fri, 14 Jan 2022 14:46:41 +0000</pubDate>
				<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[Hacky Holidays 2021]]></category>
		<category><![CDATA[machine learning]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=f76ef7d6ab9eb07fc8b8bce442dc3a69</guid>

					<description><![CDATA[Like many organizations with big data problems, Santa has turned to machine learning to help him sort through his naughty and nice lists.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/01/naughty-nice-machine-learning.jpg" length="0" type="" />

			</item>
		<item>
		<title>The Ransomware Killchain: How It Works, and How to Protect Your Systems</title>
		<link>https://noise.getoto.net/2021/09/16/the-ransomware-killchain-how-it-works-and-how-to-protect-your-systems/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Thu, 16 Sep 2021 13:30:13 +0000</pubDate>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=d6bebf9a6cc79f65d45993d44d7bcfee</guid>

					<description><![CDATA[How does a machine go from one that's working perfectly fine to one that's inoperable due to ransomware? This post takes a close look.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/09/ransomware-killchain.jpg" length="0" type="" />

			</item>
		<item>
		<title>Slot Machines and Cybercrime: Why Ransomware Won&#8217;t Quit Pulling Our Lever</title>
		<link>https://noise.getoto.net/2021/08/06/slot-machines-and-cybercrime-why-ransomware-wont-quit-pulling-our-lever/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Fri, 06 Aug 2021 14:17:22 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5aa5975326c293fc6bf9c7c3267cd0bb</guid>

					<description><![CDATA[Ransomware remains a significant problem, partly because the incentives for everyone, including victims, are there to increase the number of ransomware attacks.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/08/slotmachineransomware.jpg" length="0" type="" />

			</item>
		<item>
		<title>Why the Robot Hackers Aren’t Here (Yet)</title>
		<link>https://noise.getoto.net/2021/07/14/why-the-robot-hackers-arent-here-yet/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Wed, 14 Jul 2021 17:55:41 +0000</pubDate>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Detection and Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ed214af25f7195f9938735fdfb01b11a</guid>

					<description><![CDATA[Over the years, we’ve seen security in general and vulnerability discovery in particular move from a risky, shady business to massive corporate-sponsored activities with open marketplaces for bug bounties.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/06/robot-hackers.jpg" length="0" type="" />

			</item>
		<item>
		<title>SolarWinds Serv-U FTP and Managed File Transfer CVE-2021-35211: What You Need to Know</title>
		<link>https://noise.getoto.net/2021/07/13/solarwinds-serv-u-ftp-and-managed-file-transfer-cve-2021-35211-what-you-need-to-know/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Mon, 12 Jul 2021 22:39:41 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Emerging Threats]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ba6a91f3a0b22c1bff0c8a73d90fb362</guid>

					<description><![CDATA[On July 12, 2021, SolarWinds confirmed an actively exploited zero-day vulnerability, CVE-2021-35211, in the Serv-U FTP and Managed File Transfer component of SolarWinds15.2.3 HF1 (released May 5, 2021) and all prior versions.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/07/rapid7-og-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2021-1675 (PrintNightmare) Patch Does Not Remediate Vulnerability</title>
		<link>https://noise.getoto.net/2021/06/30/cve-2021-1675-printnightmare-patch-does-not-remediate-vulnerability/</link>
		
		<dc:creator><![CDATA[Erick Galinkin]]></dc:creator>
		<pubDate>Wed, 30 Jun 2021 18:15:59 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=45a121567763ff457de6e50439c2605a</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><p><strong>Vulnerability note:</strong> Members of the community including <a href="https://www.kb.cert.org/vuls/id/383432">Will Dormann of CERT/CC</a> have noted that the publicly available exploits which purport to exploit CVE-2021-1675 may in fact target a new vulnerability in the same function as CVE-2021-1675. Thus, the advisory update published by Microsoft on June 21 does not address</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/06/evil-printer.jpeg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 33/187 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-03-13 12:44:46 by W3 Total Cache
-->