<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ryan Emmons &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/ryan-emmons/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Tue, 09 Dec 2025 15:31:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>CVE-2025-10573: Ivanti EPM Unauthenticated Stored Cross-Site Scripting (Fixed)</title>
		<link>https://noise.getoto.net/2025/12/09/cve-2025-10573-ivanti-epm-unauthenticated-stored-cross-site-scripting-fixed/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Tue, 09 Dec 2025 15:31:59 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=970a4434c0a7db70ae8ef2038bde99c3</guid>

					<description><![CDATA[Ivanti Endpoint Manager (“EPM”) versions 2024 SU4 and below are vulnerable to stored cross-site scripting (“XSS”). The vulnerability, tracked as CVE-2025-10573 and assigned a CVSS score of 9.6, was patched on December 9, 2025 with the release of Ivanti...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" length="0" type="" />

			</item>
		<item>
		<title>CVE-2025-13315, CVE-2025-13316: Critical Twonky Server Authentication Bypass (NOT FIXED)</title>
		<link>https://noise.getoto.net/2025/11/19/cve-2025-13315-cve-2025-13316-critical-twonky-server-authentication-bypass-not-fixed/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Wed, 19 Nov 2025 17:30:41 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=4d2e29fd9db2cdc97524d0f7a864f6fc</guid>

					<description><![CDATA[OverviewTwonky Server version 8.5.2 is susceptible to two vulnerabilities that facilitate administrator authentication bypass on Linux and Windows. An unauthenticated attacker can improperly access a privileged web API endpoint to leak application logs...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1de2821d1eac3ffb/683ddc6570aa95f50bfe2f13/vuln-disclosure-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Ivanti Endpoint Manager Mobile exploit chain exploited in the wild</title>
		<link>https://noise.getoto.net/2025/05/16/ivanti-endpoint-manager-mobile-exploit-chain-exploited-in-the-wild/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Fri, 16 May 2025 11:00:20 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[InsightVM]]></category>
		<category><![CDATA[Nexpose]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3f5c8acb268ff78836ae527ef6989557</guid>

					<description><![CDATA[On May 13, 2025, Ivanti disclosed an exploited in the wild exploit chain, comprising of two new vulnerabilities affecting Ivanti Endpoint Manager Mobile: CVE-2025-4427 and CVE-2025-4428.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/emergent-threat-banner-1-2.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Multiple vulnerabilities in SonicWall SMA 100 series (FIXED)</title>
		<link>https://noise.getoto.net/2025/05/07/multiple-vulnerabilities-in-sonicwall-sma-100-series-fixed/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Wed, 07 May 2025 20:18:06 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=377230f024bbf3b223a0859d375c98a2</guid>

					<description><![CDATA[Rapid7 is disclosing three new vulnerabilities in SonicWall SMA 100 series appliances (CVE-2025-32819, CVE-2025-32820, and CVE-2025-32821). An attacker with access to an SMA SSLVPN user account can chain these vulnerabilities for root-level code execution.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/vuln-disclosure-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Ivanti Connect Secure CVE-2025-22457 exploited in the wild</title>
		<link>https://noise.getoto.net/2025/04/03/ivanti-connect-secure-cve-2025-22457-exploited-in-the-wild/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Thu, 03 Apr 2025 18:50:02 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ef69275a89bd044479527f9cd655f500</guid>

					<description><![CDATA[On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical a stack-based buffer overflow vulnerability that allows for remote code execution on affected devices.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/04/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Multiple Vulnerabilities in Wowza Streaming Engine (Fixed)</title>
		<link>https://noise.getoto.net/2024/11/20/multiple-vulnerabilities-in-wowza-streaming-engine-fixed/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Wed, 20 Nov 2024 16:42:05 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=d31867e3f9d146e14ef4620fe7876b67</guid>

					<description><![CDATA[Rapid7 is disclosing multiple vulnerabilities in Wowza Streaming Engine below v4.9.1. These vulnerabilities are tracked as CVE-2024-52052, CVE-2024-52053, CVE-2024-52054, CVE-2024-52055, and CVE-2024-52056. They are patched as of Wowza Streaming Engine v4.9.1.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/11/vuln-disclosure-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2024-45195: Apache OFBiz Unauthenticated Remote Code Execution (Fixed)</title>
		<link>https://noise.getoto.net/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Thu, 05 Sep 2024 14:54:31 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=c945e2cf50d0c5a2186995d52f2424c8</guid>

					<description><![CDATA[Apache OFBiz below 18.12.16 is vulnerable to unauthenticated remote code execution (CVE-2024-45195) on Linux and Windows. Exploitation is facilitated by bypassing previous patches.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/09/vuln-disclosure-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2024-6922: Automation Anywhere Automation 360 Server-Side Request Forgery</title>
		<link>https://noise.getoto.net/2024/07/26/cve-2024-6922-automation-anywhere-automation-360-server-side-request-forgery/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Fri, 26 Jul 2024 13:05:00 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=bc21cacd8e41b8e83b7e47bc26750b55</guid>

					<description><![CDATA[Automation 360 Robotic Process Automation suite v21-v32 is vulnerable to unauthenticated Server-Side Request Forgery (SSRF).]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/07/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Authentication Bypasses in MOVEit Transfer and MOVEit Gateway</title>
		<link>https://noise.getoto.net/2024/06/25/authentication-bypasses-in-moveit-transfer-and-moveit-gateway/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Tue, 25 Jun 2024 18:16:32 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=8f79cf94642331746e235fde66560ed2</guid>

					<description><![CDATA[On June 25, 2024, Progress Software published information on two new vulnerabilities in MOVEit Transfer and MOVEit Gateway: CVE-2024-5806 and CVE-2024-5805.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/06/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 33/131 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-02-06 16:31:45 by W3 Total Cache
-->