<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jake Baines &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/jake-baines/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Thu, 11 Aug 2022 17:20:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Rapid7 Discovered Vulnerabilities in Cisco ASA, ASDM, and FirePOWER Services Software</title>
		<link>https://noise.getoto.net/2022/08/11/rapid7-discovered-vulnerabilities-in-cisco-asa-asdm-and-firepower-services-software/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Thu, 11 Aug 2022 17:20:00 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=afd98a515cdca59ad97627970e2d2372</guid>

					<description><![CDATA[Rapid7 discovered vulnerabilities and non-security issues affecting Cisco ASA, ASDM, and FirePOWER Services Software for ASA.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/08/cisco-asa-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>QNAP Poisoned XML Command Injection (Silently Patched)</title>
		<link>https://noise.getoto.net/2022/08/04/qnap-poisoned-xml-command-injection-silently-patched/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Thu, 04 Aug 2022 14:43:45 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=651f7b992add894f63962c1bb45887a6</guid>

					<description><![CDATA[In researching the mystery surrounding alleged exploitation in the wild of CVE-2020-2509, we found what make be an entirely new vulnerability.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/08/qnap-poisoned-xml.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-30526 (Fixed): Zyxel Firewall Local Privilege Escalation</title>
		<link>https://noise.getoto.net/2022/07/19/cve-2022-30526-fixed-zyxel-firewall-local-privilege-escalation/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Tue, 19 Jul 2022 12:56:06 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=475391ab7e3e6516beb09cd86bc5de85</guid>

					<description><![CDATA[Rapid7 discovered a local privilege escalation vulnerability affecting Zyxel firewalls. The vulnerability allows a low privileged user, such as `nobody`, to escalate to `root` on affected firewalls.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/07/zyxel-firewall-vuln-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-31749: WatchGuard Authenticated Arbitrary File Read/Write (Fixed)</title>
		<link>https://noise.getoto.net/2022/06/24/cve-2022-31749-watchguard-authenticated-arbitrary-file-read-write-fixed/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Thu, 23 Jun 2022 22:39:24 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ef228aa6f05479714fa13ff42e4cc1c0</guid>

					<description><![CDATA[A remote and low-privileged WatchGuard Firebox or XTM user can red arbitrary system files due to an argument injection vulnerability.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/06/watchguard-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-22977: VMware Guest Authentication Service LPE (FIXED)</title>
		<link>https://noise.getoto.net/2022/05/24/cve-2022-22977-vmware-guest-authentication-service-lpe-fixed/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Tue, 24 May 2022 18:00:00 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=906a9e6ea4f0c790b0063ab06b04cfe0</guid>

					<description><![CDATA[A low-privileged local attacker can prevent the VMware Guest Authentication service from running in a guest Windows environment and can crash this service.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/05/vmware-guest-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-22972: Critical Authentication Bypass in VMware Workspace ONE Access, Identity Manager, and vRealize Automation</title>
		<link>https://noise.getoto.net/2022/05/19/cve-2022-22972-critical-authentication-bypass-in-vmware-workspace-one-access-identity-manager-and-vrealize-automation/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Thu, 19 May 2022 13:54:07 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=a84dc7a15fd5a2a6bf1c8389827a8b0d</guid>

					<description><![CDATA[On May 18, 2022, VMware published an advisory on CVE-2022-22972, a critical authentication bypass affecting multiple solutions.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/05/cve-2022-22972.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection</title>
		<link>https://noise.getoto.net/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Thu, 12 May 2022 13:30:29 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=02790ced26c6c155a03d093db7bff96f</guid>

					<description><![CDATA[Rapid7 discovered and reported a vulnerability that affects Zyxel firewalls supporting Zero Touch Provisioning (ZTP), identified as CVE-2022-30525.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/05/zyxel-firewall-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>Opportunistic Exploitation of WSO2 CVE-2022-29464</title>
		<link>https://noise.getoto.net/2022/04/23/opportunistic-exploitation-of-wso2-cve-2022-29464/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Fri, 22 Apr 2022 21:03:27 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3bf22f681b87e57ee0f937e2b84a45cc</guid>

					<description><![CDATA[On April 18, 2022, MITRE published CVE-2022-29464, an unrestricted file upload vulnerability affecting various WSO2 products.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/04/wso2-etr.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-28810: ManageEngine ADSelfService Plus Authenticated Command Execution (Fixed)</title>
		<link>https://noise.getoto.net/2022/04/14/cve-2022-28810-manageengine-adselfservice-plus-authenticated-command-execution-fixed/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Thu, 14 Apr 2022 15:48:37 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=54be79b36876fbcec89838b064a4b509</guid>

					<description><![CDATA[On April 9, ManageEngine fixed CVE-2022-28810 with the release of ADSelfService Plus Build 6122.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/04/managengine-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-24527: Microsoft Connected Cache Local Privilege Escalation (Fixed)</title>
		<link>https://noise.getoto.net/2022/04/12/cve-2022-24527-microsoft-connected-cache-local-privilege-escalation-fixed/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Tue, 12 Apr 2022 17:15:25 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=33d4097cdee31272c934831da3040995</guid>

					<description><![CDATA[On April 12, 2022, Microsoft published CVE-2022-24527, a local privilege escalation vulnerability in Microsoft Connected Cache.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/04/ms-connected-cache-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>Spring4Shell: Zero-Day Vulnerability in Spring Framework</title>
		<link>https://noise.getoto.net/2022/03/31/spring4shell-zero-day-vulnerability-in-spring-framework/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Wed, 30 Mar 2022 22:33:54 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=f14526c6852230a4e4cf44ade151df49</guid>

					<description><![CDATA[Rapid7 confirms the existence of an unpatched, unauthenticated remote code execution vulnerability in Spring Framework. We will update this blog continually as new information arises on this zero-day vulnerability.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/03/dark_background.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2021-4191: GitLab GraphQL API User Enumeration (FIXED)</title>
		<link>https://noise.getoto.net/2022/03/03/cve-2021-4191-gitlab-graphql-api-user-enumeration-fixed/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Thu, 03 Mar 2022 17:01:48 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5cc9edee77031820aceb3a11d748bee7</guid>

					<description><![CDATA[On February 25, 2022, GitLab published a fix for CVE-2021-4191, a now-patched vulnerability resulting from a missing authentication check.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/03/gitlab-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>Dropping Files on a Domain Controller Using CVE-2021-43893</title>
		<link>https://noise.getoto.net/2022/02/14/dropping-files-on-a-domain-controller-using-cve-2021-43893/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Mon, 14 Feb 2022 15:30:52 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=f14e17e573386db3ddd27a8e829e49a1</guid>

					<description><![CDATA[On December 14, 2021, during the Log4Shell chaos, Microsoft published CVE-2021-43893, a remote privelege escalation vulnerability affecting Windows EFS.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/02/dropping-files.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2021-20038..42: SonicWall SMA 100 Multiple Vulnerabilities (FIXED)</title>
		<link>https://noise.getoto.net/2022/01/11/cve-2021-20038-42-sonicwall-sma-100-multiple-vulnerabilities-fixed/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Tue, 11 Jan 2022 14:00:00 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=896942d0cdf4701faf0531a15c44da19</guid>

					<description><![CDATA[Over the course of routine security research, Rapid7 researcher Jake Baines discovered and reported five vulnerabilities involving the SonicWall Secure Mobile Access (SMA) 100 series of devices.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/01/sonicwall-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>Driver-Based Attacks: Past and Present</title>
		<link>https://noise.getoto.net/2021/12/13/driver-based-attacks-past-and-present/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Mon, 13 Dec 2021 14:00:00 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=a5cde39bfe09ad378ab425b9cb947fc8</guid>

					<description><![CDATA[In our analysis of CVE-2021-21551, a write-what-where vulnerability in a Dell driver, we found that Dell’s update didn’t fix the write-what-where condition but only limited access to administrative users.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/12/dell-drivers.jpg" length="0" type="" />

			</item>
		<item>
		<title>GitLab Unauthenticated Remote Code Execution CVE-2021-22205 Exploited in the Wild</title>
		<link>https://noise.getoto.net/2021/11/01/gitlab-unauthenticated-remote-code-execution-cve-2021-22205-exploited-in-the-wild/</link>
		
		<dc:creator><![CDATA[Jake Baines]]></dc:creator>
		<pubDate>Mon, 01 Nov 2021 13:33:43 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=42058f70e3a275d52c950440a003ea6d</guid>

					<description><![CDATA[Patches have been available for GitLab CVE-2021-22205 since April 2021, but analysis suggests a large number of instances are still vulnerable.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/11/GettyImages-1127457566.jpg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 36/194 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-02-10 11:04:39 by W3 Total Cache
-->