<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spencer McIntyre &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/spencer-mcintyre/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Fri, 30 Jan 2026 21:11:27 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Metasploit Wrap-Up 01/30/2026</title>
		<link>https://noise.getoto.net/2026/01/30/metasploit-wrap-up-01-30-2026/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 30 Jan 2026 21:11:27 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=b4606ea3f7b0a769d9828caad7e65223</guid>

					<description><![CDATA[FreeBPX Content GaloreThis week brings 3 new pieces of module content for targeting FreePBX. All three chain multiple vulnerabilities together, starting with CVE-2025-66039. This initial vulnerability allows unauthenticated users to bypass the authenti...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0475760a2990dfd7/6849ab41a770d7563190a3ea/metasploit-fence.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up 01/09/2026</title>
		<link>https://noise.getoto.net/2026/01/10/metasploit-wrap-up-01-09-2026/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 09 Jan 2026 23:07:48 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=bf821051d7dafc85f9b7d756c8f5fc00</guid>

					<description><![CDATA[RISC-V PayloadsThis week brings more RISC-V payloads from community member bcoles. One provides a new adapter which allows RISC-V payloads to be converted to commands and delivered as a Metasploit fetch-payload. The second is a classic bind shell, offe...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0475760a2990dfd7/6849ab41a770d7563190a3ea/metasploit-fence.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit 2025 Annual Wrap-Up</title>
		<link>https://noise.getoto.net/2026/01/05/metasploit-2025-annual-wrap-up/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Mon, 05 Jan 2026 20:31:31 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=89ec9df8ce36f91cdc1599a7c981c149</guid>

					<description><![CDATA[Hard to believe it's that time again, and that Metasploit Framework will see the dawn of another Annual Wrap-Up (and a New Year). All of the metrics and modules you see here would in large part not be possible without the dedicated community members wh...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0475760a2990dfd7/6849ab41a770d7563190a3ea/metasploit-fence.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up 12/19/2025</title>
		<link>https://noise.getoto.net/2025/12/19/metasploit-wrap-up-12-19-2025/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 19 Dec 2025 21:02:00 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ff04125dca2883f3b4fab0bfb169a76a</guid>

					<description><![CDATA[React2Shell Payload ImprovementsLast week Metasploit released an exploit for the React2Shell vulnerability, and this week we have made a couple of improvements to the payloads that it uses. The first improvement affects all Metasploit modules. When an ...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0d50271a40a5f14f/6849ab419621d9f3824d5017/metasploit-sky.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up 12/12/2025</title>
		<link>https://noise.getoto.net/2025/12/12/metasploit-wrap-up-12-12-2025/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 12 Dec 2025 20:38:50 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=c4e376c93d7dd81ca2ee106bf21d4ebc</guid>

					<description><![CDATA[React2shell ModuleAs you may have heard, on December 3, 2025, the React team announced a critical Remote Code Execution (RCE) vulnerability in servers using the React Server Components (RSC) Flight protocol. The vulnerability, tracked as CVE-2025-55182...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7464fe659cab8a01/6852c358419e54d8e21c3458/blog-metasploit-wrap-up-.webp" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up 05/30/2025</title>
		<link>https://noise.getoto.net/2025/05/30/metasploit-wrap-up-05-30-2025/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 30 May 2025 18:08:30 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=6b4466d4b72a13dde13cba9b2d8e798b</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>The internet is a series of Tube [SOCKS]</h2>
<p>Metasploit has supported SOCKS proxies for years now, being able to both act as both a client (by setting the <code>Proxies</code> datastore option) and a server (by running the <code>auxiliary/server/socks_proxy</code> module). While Metasploit has supported both SOCKS versions 4a</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/metasploit-ascii-1-2-2.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up 05/16/2025</title>
		<link>https://noise.getoto.net/2025/05/16/metasploit-wrap-up-05-16-2025/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 16 May 2025 16:38:30 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e560106385e62f1ef4ac0782213e7ba2</guid>

					<description><![CDATA[This week's release includes 5 new modules including RCEs for Car Rental System, and three Wordpress plugins. The execute-assembly post module was also updated with 32-bit support.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/metasploit-ascii-1-2-1-2.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up 05/02/2025</title>
		<link>https://noise.getoto.net/2025/05/02/metasploit-wrap-up-05-02-2025/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 02 May 2025 19:38:42 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3f3b34a275a31ae29b536e45fc85f6ee</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Meterpreter Extended API Clipboard Monitoring</h2>
<p>Security is hard, and Open Source Security is a collaborative effort. This week, Metasploit released a fix for a vulnerability that was privately disclosed to us by long-time community member <a href="https://github.com/bcoles">bcoles</a>. The vulnerability in question impacted Metasploit users who were using the clipboard monitoring functionality</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/metasploit-sky.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up 04/04/2025</title>
		<link>https://noise.getoto.net/2025/04/04/metasploit-wrap-up-04-04-2025/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 04 Apr 2025 20:19:20 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=12cacb48e84407210a476d568920c23e</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>New RCEs</h2>
<p>Metasploit added four new modules this week, including three that leverage vulnerabilities to obtain remote code execution (RCE). Among these three, two leverage deserialization, showing that the exploit primitive is still going strong. The Tomcat vulnerability in particular <a href="https://attackerkb.com/search?q=CVE-2025-24813&#38;referrer=blog">CVE-2025-24813</a> garnered a lot of attention when it was disclosed;</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/04/metasploit-sky.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 01/31/25</title>
		<link>https://noise.getoto.net/2025/01/31/metasploit-weekly-wrap-up-01-31-25/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 31 Jan 2025 21:34:28 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=bd82d7b8d80e28b1c1f1fe724dd57097</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>ESC4 Detection</h2>
<p>This week, Metasploit’s <a href="https://github.com/jheysel-r7">jheysel-r7</a> updated the existing <code>ldap_esc_vulnerable_cert_finder</code> module to include detecting template objects that can be written to by the authenticated user. This means the module can now identify instances of ESC4 from the perspective of the account that the Metasploit operator</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/01/metasploit-ascii-1-2-1.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit 2024 Annual Wrap-Up</title>
		<link>https://noise.getoto.net/2025/01/03/metasploit-2024-annual-wrap-up/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 03 Jan 2025 16:52:00 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=661d479886379c168bd6e0fdf0978b57</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><p>Another year has come and gone, and the Metasploit team has taken some time to review the year’s notable additions. This year saw some great new features added, <a href="https://www.rapid7.com/blog/post/2024/03/25/metasploit-framework-6-4-released/">Metasploit 6.4 released</a> and a slew of new modules. We’re grateful to the community members new and old that</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/12/metasploit-sky.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 12/13/2024</title>
		<link>https://noise.getoto.net/2024/12/13/metasploit-weekly-wrap-up-12-13-2024/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 13 Dec 2024 19:36:49 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=93a6741eccabc2957ce4083067e79088</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>It’s raining RCEs!</h2>
<p>It's the second week of December and the weather forecast announced another storm of RCEs in Metasploit-Framework land. This weekly release includes RCEs for Moodle e-Learning platform, Primefaces, WordPress Really Simple SSL and CyberPanel along with two modules to change password through LDAP and SMB protocol.</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/12/metasploit-fence-1.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 11/22/2024</title>
		<link>https://noise.getoto.net/2024/11/22/metasploit-weekly-wrap-up-11-22-2024/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 22 Nov 2024 20:28:22 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5161374b0b0736fcb24143eed8f516d9</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>JetBrains TeamCity Login Scanner</h2>
<p>Metasploit added a login scanner for the TeamCity application to enable users to check for weak credentials. TeamCity has been the subject of multiple <a href="https://www.rapid7.com/blog/post/2024/03/04/etr-cve-2024-27198-and-cve-2024-27199-jetbrains-teamcity-multiple-authentication-bypass-vulnerabilities-fixed/">ETR vulnerabilities</a> and is a valuable target for attackers.</p>
<h2>Targeted DCSync added to Windows Secrets Dump</h2>
<p>This week, Metasploit community member <a href="https://github.com/smashery">smashery</a></p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/11/metasploit-sky.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 10/18/2024</title>
		<link>https://noise.getoto.net/2024/10/18/metasploit-weekly-wrap-up-10-18-2024/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 18 Oct 2024 18:14:07 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=eefd801bce3481511c8a20d65390ea13</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>ESC15: EKUwu</h2>
<p>AD CS continues to be a popular target for penetration testers and security practitioners. The latest escalation technique (hence the the ESC in ESC15) was <a href="https://trustedsec.com/blog/ekuwu-not-just-another-ad-cs-esc">discovered</a> by <a href="https://x.com/bandrel">Justin Bollinger</a> with details being released just last week. This latest configuration flaw has common issuance requirements to other ESC flaws</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/10/metasploit-ascii-1-2.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 09/13/2024</title>
		<link>https://noise.getoto.net/2024/09/13/metasploit-weekly-wrap-up-09-13-2024/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 13 Sep 2024 18:29:33 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=a3d1dd6e02fc3fd8e53eadde259b9996</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>SPIP Modules</h2>
<p>This week brings more modules targeting the SPIP publishing platform. SPIP has gained some attention from Metasploit community contributors recently and has inspired some PHP payload and encoder improvements.</p>
<h2>New module content (2)</h2>
<h3>SPIP BigUp Plugin Unauthenticated RCE</h3>
<p>Authors: Julien Voisin, Laluka, Valentin Lobstein, and Vozec<br>
Type: Exploit<br></p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/09/metasploit-fence.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up 05/17/2024</title>
		<link>https://noise.getoto.net/2024/05/17/metasploit-wrap-up-05-17-2024/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 17 May 2024 20:11:54 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=c71b55ce9f20897f32f35861d5c60b5c</guid>

					<description><![CDATA[Metasploit adds improved LDAP capabilities along with two new modules.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/05/metasploit-ascii-1-2.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 04/26/24</title>
		<link>https://noise.getoto.net/2024/04/26/metasploit-weekly-wrap-up-04-26-24/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 26 Apr 2024 19:49:58 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=35e5ade322d3eff8cbc6f8a451c03947</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Rancher Modules</h2>
<p>This week, Metasploit community member <a href="https://github.com/h00die">h00die</a> added the second of two modules targeting Rancher instances. These modules each leak sensitive information from vulnerable instances of the application which is intended to manage Kubernetes clusters. These are a great addition to Metasploit’s coverage for testing <a href="https://docs.metasploit.com/docs/pentesting/metasploit-guide-kubernetes.html">Kubernetes environments</a>.</p>
<h2>PAN-OS</h2>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/04/metasploit-sky-1.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Framework 6.4 Released</title>
		<link>https://noise.getoto.net/2024/03/25/metasploit-framework-6-4-released/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Mon, 25 Mar 2024 13:33:28 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=dace20fe376479a7810621bdb2e3b117</guid>

					<description><![CDATA[Metasploit 6.4 has been released with Kerberos improvements, new session types, indirect syscalls in the Windows Meterpreter and DNS configuration support.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/03/metasploit-ascii-1-2-1.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 02/23/2024</title>
		<link>https://noise.getoto.net/2024/02/23/metasploit-weekly-wrap-up-02-23-2024/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 23 Feb 2024 17:50:39 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e42d36b0b71e3a14464e3b3fbad58aa0</guid>

					<description><![CDATA[Metasploit adds a new LDAP capture module as well as the Ivanti Connect Secure unauthenticated RCE.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/02/metasploit-fence-1.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 02/16/2024</title>
		<link>https://noise.getoto.net/2024/02/16/metasploit-weekly-wrap-up-02-16-2024/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 16 Feb 2024 20:34:54 +0000</pubDate>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=1ca1cb5dd9aca2e0d72e576e58c53846</guid>

					<description><![CDATA[Metasploit adds an SMB fetch payload and new Base64 command encoder.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/02/metasploit-sky.png" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 22/240 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-02-10 18:19:18 by W3 Total Cache
-->