<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Stephen Fewer &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/stephen-fewer/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Wed, 14 May 2025 14:59:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>CVE-2025-32756 Exploited in the Wild, Affecting Multiple Fortinet Products</title>
		<link>https://noise.getoto.net/2025/05/14/cve-2025-32756-exploited-in-the-wild-affecting-multiple-fortinet-products/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Wed, 14 May 2025 14:59:20 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[InsightVM]]></category>
		<category><![CDATA[Nexpose]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=2faee9200943cae6b92ab50f068c465f</guid>

					<description><![CDATA[On May 13, 2025, Fortinet disclosed CVE-2025-32756, an unauthenticated stack-based buffer overflow affecting multiple FortiNet products; including FortiVoice, FortiRecorder, FortiNDR, FortiMail, and FortiCamera.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Multiple vulnerabilities in Ingress NGINX Controller for Kubernetes</title>
		<link>https://noise.getoto.net/2025/03/25/multiple-vulnerabilities-in-ingress-nginx-controller-for-kubernetes/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Tue, 25 Mar 2025 16:10:50 +0000</pubDate>
				<category><![CDATA[cloud security]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e2aad7ff9aa3232f879e893547406a34</guid>

					<description><![CDATA[On March 24, 2025, Kubernetes disclosed 5 new vulnerabilities affecting the Ingress NGINX Controller for Kubernetes. Successful exploitation could allow attackers access to all secrets stored across all namespaces in the Kubernetes cluster, which could result in cluster takeover.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/03/emergent-threat-banner-3.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Multiple zero-day vulnerabilities in Broadcom VMware ESXi and other products</title>
		<link>https://noise.getoto.net/2025/03/04/multiple-zero-day-vulnerabilities-in-broadcom-vmware-esxi-and-other-products/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Tue, 04 Mar 2025 17:00:13 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=172ef530764aad919e0f10cdce8bfbb9</guid>

					<description><![CDATA[On Tuesday, March 4, 2025, Broadcom published a critical security advisory (VMSA-2025-0004) on 3 new zero-day vulnerabilities affecting multiple VMware products, including ESXi, Workstation, and Fusion.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/03/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2025-1094: PostgreSQL psql SQL injection (FIXED)</title>
		<link>https://noise.getoto.net/2025/02/13/cve-2025-1094-postgresql-psql-sql-injection-fixed/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Thu, 13 Feb 2025 15:07:10 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=af696ea0bf3ccd1f6e260d613c779304</guid>

					<description><![CDATA[Rapid7 discovered and is disclosing CVE-2025-1094, a high-severity SQL injection vulnerability affecting the PostgreSQL interactive tool psql.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/02/vuln-disclosure-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Lorex 2K Indoor Wi-Fi Security Camera: Multiple Vulnerabilities (FIXED)</title>
		<link>https://noise.getoto.net/2024/12/03/lorex-2k-indoor-wi-fi-security-camera-multiple-vulnerabilities-fixed/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Tue, 03 Dec 2024 20:00:00 +0000</pubDate>
				<category><![CDATA[IOT]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e8728ec128b0776821852a8e806403cd</guid>

					<description><![CDATA[The Lorex 2K Indoor Wi-Fi Security Camera is a consumer security device that provides cloud-based video camera surveillance capabilities. This device was a target at the 2024 Pwn2Own IoT competition. As of December 3, 2024, we are disclosing these issues publicly in coordination with the vendor.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/12/GettyImages-2185437206.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2024-28995: Trivially Exploitable Information Disclosure Vulnerability in SolarWinds Serv-U</title>
		<link>https://noise.getoto.net/2024/06/11/cve-2024-28995-trivially-exploitable-information-disclosure-vulnerability-in-solarwinds-serv-u/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Tue, 11 Jun 2024 14:25:38 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=39be80c75a231c58c53aed824c8ff7b5</guid>

					<description><![CDATA[On June 5, 2024, SolarWinds disclosed CVE-2024-28995, a high-severity directory traversal vulnerability affecting the Serv-U file transfer server. Successful exploitation of the vulnerability allows unauthenticated attackers to read sensitive files on the host.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/06/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-47218: QNAP QTS and QuTS Hero Unauthenticated Command Injection (FIXED)</title>
		<link>https://noise.getoto.net/2024/02/13/cve-2023-47218-qnap-qts-and-quts-hero-unauthenticated-command-injection-fixed/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Tue, 13 Feb 2024 16:00:00 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=aeeb93164ec083eacf5d397df0159cb6</guid>

					<description><![CDATA[Rapid7 has identified an unauthenticated command injection vulnerability in the QNAP operating system known as QTS, a core part of the firmware for numerous QNAP entry- and mid-level Network Attached Storage (NAS) devices.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/02/emergent-threat-banner-1-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-49103 &#8211; Critical Information Disclosure in ownCloud Graph API</title>
		<link>https://noise.getoto.net/2023/12/01/cve-2023-49103-critical-information-disclosure-in-owncloud-graph-api/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Fri, 01 Dec 2023 17:19:25 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=fa43d5237cce5b33e2f0e687fd114934</guid>

					<description><![CDATA[On November 21, 2023, ownCloud disclosed CVE-2023-49103, an unauthenticated information disclosure vulnerability affecting ownCloud, when a vulnerable extension called “Graph API” (graphapi) is present.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/12/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-35082 &#8211; MobileIron Core Unauthenticated API Access Vulnerability</title>
		<link>https://noise.getoto.net/2023/08/02/cve-2023-35082-mobileiron-core-unauthenticated-api-access-vulnerability/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Wed, 02 Aug 2023 16:05:47 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=6627626deb31105fbf3bab7f61aa0610</guid>

					<description><![CDATA[Rapid7 discovered a new vulnerability that allows unauthenticated attackers to access the API in unsupported versions of MobileIron Core (11.2 and below).]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/08/GettyImages-1185282377-2-2-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-38205: Adobe ColdFusion Access Control Bypass [FIXED]</title>
		<link>https://noise.getoto.net/2023/07/19/cve-2023-38205-adobe-coldfusion-access-control-bypass-fixed/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Wed, 19 Jul 2023 17:25:06 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=299c5c38fa4b37fea494e775f2106602</guid>

					<description><![CDATA[Rapid7 discovered that the initial patch for CVE-2023-29298 (Adobe ColdFusion access control bypass vulnerability) did not successfully remediate the issue.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/07/GettyImages-1185282377-3.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2023-29298: Adobe ColdFusion Access Control Bypass</title>
		<link>https://noise.getoto.net/2023/07/11/cve-2023-29298-adobe-coldfusion-access-control-bypass/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Tue, 11 Jul 2023 15:30:00 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=af89e3740fb97329034e56ba6e181abb</guid>

					<description><![CDATA[Rapid7 discovered an access control bypass vulnerability affecting Adobe ColdFusion that allows an attacker to access the administration endpoints.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/07/GettyImages-1345443906.jpg" length="0" type="" />

			</item>
		<item>
		<title>Active Exploitation of ZK Framework CVE-2022-36537</title>
		<link>https://noise.getoto.net/2023/03/01/active-exploitation-of-zk-framework-cve-2022-36537/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Wed, 01 Mar 2023 17:46:28 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=81aeb2840db23d882e9b744107e014fc</guid>

					<description><![CDATA[Rapid7 is aware of active exploitation of CVE-2022-36537 in vulnerable versions of ConnectWise R1Soft Server Backup Manager software.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/03/GettyImages-1352385622.jpg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 95/101 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-02-07 03:28:00 by W3 Total Cache
-->