<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Glenn Thorpe &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/glenn-thorpe/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Tue, 07 Feb 2023 17:27:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>CVE-2022-21587: Rapid7 Observed Exploitation of Oracle E-Business Suite Vulnerability</title>
		<link>https://noise.getoto.net/2023/02/07/cve-2022-21587-rapid7-observed-exploitation-of-oracle-e-business-suite-vulnerability/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Tue, 07 Feb 2023 17:27:49 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=179f96eaf2ed026dbb975adfc87471c0</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><p><em>Emergent threats evolve quickly, and as we learn more about this vulnerability, this blog post will evolve, too.</em></p>
<p>Rapid7 is responding to various compromises arising from the exploitation of <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21587">CVE-2022-21587</a>, a critical arbitrary file upload vulnerability (rated 9.8 on the CVSS v3 risk metric) impacting Oracle E-Business Suite (EBS)</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/02/GettyImages-1352385622-1-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-47966: Rapid7 Observed Exploitation of Critical ManageEngine Vulnerability</title>
		<link>https://noise.getoto.net/2023/01/19/cve-2022-47966-rapid7-observed-exploitation-of-critical-manageengine-vulnerability/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Thu, 19 Jan 2023 17:46:15 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3801c6c4728415bdc9a56a2258bd827b</guid>

					<description><![CDATA[Rapid7 is responding to various compromises arising from the exploitation of CVE-2022-47966, a vulnerability impacting at least 24 ManageEngine products.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/01/GettyImages-1352385622.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-41080, CVE-2022-41082: Rapid7 Observed Exploitation of `OWASSRF` in Exchange for RCE</title>
		<link>https://noise.getoto.net/2022/12/21/cve-2022-41080-cve-2022-41082-rapid7-observed-exploitation-of-owassrf-in-exchange-for-rce/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Wed, 21 Dec 2022 17:35:17 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=4f13870ace30dedd995c2dde4e4ff4d0</guid>

					<description><![CDATA[Beginning December 20, 2022, Rapid7 has responded to an increase in the number of Microsoft Exchange server compromises. Further investigation aligned these attacks to what CrowdStrike is reporting as “OWASSRF”.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/12/GettyImages-1352385622-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-27518: Critical Fix Released for Exploited Citrix ADC, Gateway Vulnerability</title>
		<link>https://noise.getoto.net/2022/12/14/cve-2022-27518-critical-fix-released-for-exploited-citrix-adc-gateway-vulnerability/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Tue, 13 Dec 2022 23:19:21 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=82937f96e2fa75f17c73d0c54d27fa1b</guid>

					<description><![CDATA[On Tuesday, December 13, 2022, Citrix published Citrix ADC and Citrix Gateway Security Bulletin for CVE-2022-27518 announcing fixes for a critical unauthenticated remote code execution (RCE) vulnerability.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/12/emergent-threats-series-hero-background-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-42475: Unauthenticated Remote Code Execution Vulnerability in FortiOS; Exploitation Reported</title>
		<link>https://noise.getoto.net/2022/12/12/cve-2022-42475-unauthenticated-remote-code-execution-vulnerability-in-fortios-exploitation-reported/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Mon, 12 Dec 2022 18:48:08 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=d1061bec8f38c05c82730335576c86af</guid>

					<description><![CDATA[Today FortiGuard Labs published advisory FG-IR-22-398 regarding a “heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN. FortiGuard Labs has confirmed at least one instance of the vulnerability being exploited in the wild.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/12/GettyImages-1352385622.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-40684: Remote Authentication Bypass Vulnerability in Fortinet Firewalls, Web Proxies</title>
		<link>https://noise.getoto.net/2022/10/07/cve-2022-40684-remote-authentication-bypass-vulnerability-in-fortinet-firewalls-web-proxies/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Fri, 07 Oct 2022 16:24:42 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=4e867f9e4f1818a4f797c0c8a1e26598</guid>

					<description><![CDATA[On October 3, 2022, Fortinet released an update that indicates then-current versions of FortiOS  and FortiProxy are vulnerable to CVE-2022-40684.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/10/bloghero.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Active Exploitation of Atlassian’s Questions for Confluence App CVE-2022-26138</title>
		<link>https://noise.getoto.net/2022/07/27/active-exploitation-of-atlassians-questions-for-confluence-app-cve-2022-26138/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Wed, 27 Jul 2022 19:26:38 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=c45deea0736048ff17ff9a53e337c92d</guid>

					<description><![CDATA[Exploitation is underway CVE-2022-26138, one of a trio of critical Atlassian vulnerabilities affecting the company's on-premises products.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/07/GettyImages-1059877984.jpg" length="0" type="" />

			</item>
		<item>
		<title>Active Exploitation of VMware Horizon Servers</title>
		<link>https://noise.getoto.net/2022/01/18/active-exploitation-of-vmware-horizon-servers/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Tue, 18 Jan 2022 20:00:15 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[log4j]]></category>
		<category><![CDATA[log4shell]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=6eadcd983283e3d546ef2907978e95f1</guid>

					<description><![CDATA[Attackers are actively targeting VMware Horizon servers vulnerable to Apache Log4j CVE-2021-44228 (Log4Shell) and related vulnerabilities.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/01/vmware-server-exploitation.jpg" length="0" type="" />

			</item>
		<item>
		<title>Patch Now: Sonicwall Fixes Multiple Vulnerabilities in SMA 100 Devices</title>
		<link>https://noise.getoto.net/2021/12/08/patch-now-sonicwall-fixes-multiple-vulnerabilities-in-sma-100-devices/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Wed, 08 Dec 2021 18:57:52 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=000305bc832103845a712987c0e849e4</guid>

					<description><![CDATA[On December 7, 2021, Sonicwall released a security advisory that includes patching guidance for five vulnerabilities that were discovered by Rapid7.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/12/sonicwall-fixes.jpg" length="0" type="" />

			</item>
		<item>
		<title>Oh No, Zoho: Active Exploitation of CVE-2021-44077 Allowing Unauthenticated Remote Code Execution</title>
		<link>https://noise.getoto.net/2021/12/07/oh-no-zoho-active-exploitation-of-cve-2021-44077-allowing-unauthenticated-remote-code-execution/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Tue, 07 Dec 2021 21:41:01 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=45c740b931e148e6075fd00036a389cb</guid>

					<description><![CDATA[Zoho customers have had a huge incentive lately to keep their software up to date, as recent Zoho critical vulnerabilities have been weaponized shortly after release by advanced attackers.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/12/zoho-rce.jpg" length="0" type="" />

			</item>
		<item>
		<title>Ongoing Exploitation of Windows Installer CVE-2021-41379</title>
		<link>https://noise.getoto.net/2021/11/30/ongoing-exploitation-of-windows-installer-cve-2021-41379/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Tue, 30 Nov 2021 19:03:28 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e5721e7c94293776737fd29ee61c94e2</guid>

					<description><![CDATA[On November 22, 2021, security researcher Abdelhamid Naceri found that Microsoft's initial patch for CVE-2021-41379 did not remediate the vulnerability.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/11/windowsinstaller-exploit.jpg" length="0" type="" />

			</item>
		<item>
		<title>NPM Library (ua-parser-js) Hijacked: What You Need to Know</title>
		<link>https://noise.getoto.net/2021/10/25/npm-library-ua-parser-js-hijacked-what-you-need-to-know/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Mon, 25 Oct 2021 19:16:58 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=4fd3efb0ae8ee8f9e55dafbbe2912d77</guid>

					<description><![CDATA[For approximately 4 hours on Friday, October 22, 2021, the widely used NPM package ua-parser-js was embedded with a malicious script.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/10/GettyImages-1093539466.jpg" length="0" type="" />

			</item>
		<item>
		<title>Critical vCenter Server File Upload Vulnerability (CVE-2021-22005)</title>
		<link>https://noise.getoto.net/2021/09/21/critical-vcenter-server-file-upload-vulnerability-cve-2021-22005/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Tue, 21 Sep 2021 19:55:35 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=076dbd838fd2726d9f20bceafc2d960d</guid>

					<description><![CDATA[On Tuesday, September 21, 2021, VMware published details on a critical file upload vulnerability in vCenter Server.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/09/vcenter-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>Popular Attack Surfaces, August 2021: What You Need to Know</title>
		<link>https://noise.getoto.net/2021/08/12/popular-attack-surfaces-august-2021-what-you-need-to-know/</link>
		
		<dc:creator><![CDATA[Glenn Thorpe]]></dc:creator>
		<pubDate>Thu, 12 Aug 2021 17:13:25 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5cdf95fb2ac31414fd390e0e0a47e057</guid>

					<description><![CDATA[Here’s the specific attack surface area and a few of the exploit chains we’re keeping our eye on right now.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/08/August-vulns.jpg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 30/182 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-02-27 08:14:22 by W3 Total Cache
-->