<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ron Bowes &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/ron-bowes/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Mon, 16 Oct 2023 15:00:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Multiple Vulnerabilities in South River Technologies Titan MFT and Titan SFTP [FIXED]</title>
		<link>https://noise.getoto.net/2023/10/16/multiple-vulnerabilities-in-south-river-technologies-titan-mft-and-titan-sftp-fixed/</link>
		
		<dc:creator><![CDATA[Ron Bowes]]></dc:creator>
		<pubDate>Mon, 16 Oct 2023 15:00:00 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=4f77c17949c3035ff869db150cb8ad9e</guid>

					<description><![CDATA[As part of our continuing research project into managed file transfer risk, including JSCAPE MFT and Fortra Globalscape EFT Server, Rapid7 discovered several vulnerabilities in South River Technologies’ Titan MFT and Titan SFTP servers.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/10/vuln-disclosure-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-4528: Java Deserialization Vulnerability in JSCAPE MFT (Fixed)</title>
		<link>https://noise.getoto.net/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/</link>
		
		<dc:creator><![CDATA[Ron Bowes]]></dc:creator>
		<pubDate>Thu, 07 Sep 2023 15:05:00 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3a9ab68d91ebd00bb3578197f859ddc2</guid>

					<description><![CDATA[In August 2023, Rapid7 discovered CVE-2023-4528, a Java deserialization vulnerability in Redwood Software’s JSCAPE MFT secure managed file transfer product. Successful exploitation can run arbitrary Java code as the `root` on Linux or the `SYSTEM` user on Windows.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/09/vuln-disclosure-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Exploitation of Juniper Networks SRX Series and EX Series Devices</title>
		<link>https://noise.getoto.net/2023/08/31/exploitation-of-juniper-networks-srx-series-and-ex-series-devices/</link>
		
		<dc:creator><![CDATA[Ron Bowes]]></dc:creator>
		<pubDate>Thu, 31 Aug 2023 20:23:59 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=866ca097f36bcf8e44a2b5c2ecba5eb6</guid>

					<description><![CDATA[On August 17, 2023, Juniper Networks published an out-of-band advisory on four different CVEs affecting Junos OS on SRX and EX Series devices. Successful exploitation would likely enable attackers to pivot to organizations’ internal networks.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/08/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Multiple Vulnerabilities in Fortra Globalscape EFT Administration Server [FIXED]</title>
		<link>https://noise.getoto.net/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/</link>
		
		<dc:creator><![CDATA[Ron Bowes]]></dc:creator>
		<pubDate>Thu, 22 Jun 2023 16:16:57 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=fe38dd3544c0d0e389bb384b52535ef6</guid>

					<description><![CDATA[Rapid7 has uncovered four issues in Fortra Globalscape EFT, the worst of which can lead to remote code execution.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/06/GettyImages-1345443906.jpg" length="0" type="" />

			</item>
		<item>
		<title>Multiple Vulnerabilities in Rocket Software UniRPC server (Fixed)</title>
		<link>https://noise.getoto.net/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/</link>
		
		<dc:creator><![CDATA[Ron Bowes]]></dc:creator>
		<pubDate>Wed, 29 Mar 2023 15:21:09 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=bc6a455207f45574237d56f2d5a8ca3b</guid>

					<description><![CDATA[In early 2023, Rapid7 discovered several vulnerabilities in Rocket Software UniData UniRPC. We worked with the company to fix issues and coordinate this disclosure.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/03/GettyImages-1352385622-2.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-22374: F5 BIG-IP Format String Vulnerability</title>
		<link>https://noise.getoto.net/2023/02/01/cve-2023-22374-f5-big-ip-format-string-vulnerability/</link>
		
		<dc:creator><![CDATA[Ron Bowes]]></dc:creator>
		<pubDate>Wed, 01 Feb 2023 15:57:57 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=88c0dafa91cd3f8c9f21b748e969aa2a</guid>

					<description><![CDATA[Rapid7 found an additional vulnerability in the appliance-mode REST interface. We reported it to F5 and are now disclosing it in accordance with our vulnerability disclosure policy.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/02/GettyImages-1352385622.jpg" length="0" type="" />

			</item>
		<item>
		<title>FLEXlm and Citrix ADM Denial of Service Vulnerability</title>
		<link>https://noise.getoto.net/2022/10/18/flexlm-and-citrix-adm-denial-of-service-vulnerability/</link>
		
		<dc:creator><![CDATA[Ron Bowes]]></dc:creator>
		<pubDate>Tue, 18 Oct 2022 13:30:00 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=b6316c65dcd455ad37755dd4c29c655a</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><p>On June 27, 2022, Citrix released <a href="https://support.citrix.com/article/CTX460016/citrix-application-delivery-management-security-bulletin-for-cve202227511-and-cve202227512">an advisory</a> for <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27511">CVE-2022-27511</a> and <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27512">CVE-2022-27512</a>, which affect Citrix ADM (Application Delivery Management).</p>
<p>Rapid7 <a href="https://www.rapid7.com/blog/post/2022/06/16/cve-2022-27511-citrix-adm-remote-device-takeover/">investigated these issues</a> to better understand their impact, and found that the patch is not sufficient to prevent exploitation. We also determined that the worst outcome of this vulnerability is</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Exploitation of Unpatched Zero-Day Remote Code Execution Vulnerability in Zimbra Collaboration Suite (CVE-2022-41352)</title>
		<link>https://noise.getoto.net/2022/10/06/exploitation-of-unpatched-zero-day-remote-code-execution-vulnerability-in-zimbra-collaboration-suite-cve-2022-41352/</link>
		
		<dc:creator><![CDATA[Ron Bowes]]></dc:creator>
		<pubDate>Thu, 06 Oct 2022 17:13:34 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=9191651e2ecce625aeb7bdcad1ea43f6</guid>

					<description><![CDATA[CVE-2022-41352 is an unpatched remote code execution vulnerability in Zimbra Collaboration Suite discovered in the wild due to active exploitation.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/10/zimbra-rce.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-36804: Easily Exploitable Vulnerability in Atlassian Bitbucket Server and Data Center</title>
		<link>https://noise.getoto.net/2022/09/20/cve-2022-36804-easily-exploitable-vulnerability-in-atlassian-bitbucket-server-and-data-center/</link>
		
		<dc:creator><![CDATA[Ron Bowes]]></dc:creator>
		<pubDate>Tue, 20 Sep 2022 15:14:26 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=bcf3916e38ec7840e9babbdd5431352b</guid>

					<description><![CDATA[On August 24, 2022, Atlassian published an advisory for Bitbucket Server and Data Center alerting users to CVE-2022-36804.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/09/atlassian-bitbucket-etr.jpg" length="0" type="" />

			</item>
		<item>
		<title>Active Exploitation of F5 BIG-IP iControl REST CVE-2022-1388</title>
		<link>https://noise.getoto.net/2022/05/09/active-exploitation-of-f5-big-ip-icontrol-rest-cve-2022-1388/</link>
		
		<dc:creator><![CDATA[Ron Bowes]]></dc:creator>
		<pubDate>Mon, 09 May 2022 17:57:00 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=07ca09b4e3b3835e096aa56546c43e8e</guid>

					<description><![CDATA[On May 4, 2022, F5 released an advisory on CVE-2022-1388, a critical authentication bypass that leads to remote code execution in iControl REST.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/05/f5-etr.jpg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 26/144 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-02-09 12:02:57 by W3 Total Cache
-->