<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tod Beardsley &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/author/tod-beardsley/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Tue, 21 Mar 2023 18:54:03 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>CVE-2023-0391: MGT-COMMERCE CloudPanel Shared Certificate Vulnerability and Weak Installation Procedures</title>
		<link>https://noise.getoto.net/2023/03/21/cve-2023-0391-mgt-commerce-cloudpanel-shared-certificate-vulnerability-and-weak-installation-procedures/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 21 Mar 2023 18:54:03 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=c3c1ab512a644a42c81b84765be16853</guid>

					<description><![CDATA[Rapid7 has discovered three security concerns in CloudPanel from MGT-COMMERCE, a self-hosted web administration solution.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/03/GettyImages-1345443906.jpg" length="0" type="" />

			</item>
		<item>
		<title>Microsoft Defender for Cloud Management Port Exposure Confusion</title>
		<link>https://noise.getoto.net/2023/03/14/microsoft-defender-for-cloud-management-port-exposure-confusion/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 14 Mar 2023 19:20:00 +0000</pubDate>
				<category><![CDATA[cloud security]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=9acec6c2cc00fe63e91b9940f8188989</guid>

					<description><![CDATA[Microsoft Defender for Cloud, until recently, didn't distinguish "0.0.0.0/0" as a synonym for "any" when checking for management port exposures for Azure instances.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/03/GettyImages-1352385622-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>A Deep Dive into Reversing CODESYS</title>
		<link>https://noise.getoto.net/2023/02/14/a-deep-dive-into-reversing-codesys/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 14 Feb 2023 15:00:00 +0000</pubDate>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[Operational Technology]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=8ce0a3980573ab9d017dc9d926a8defd</guid>

					<description><![CDATA[This white paper offers a technical deep dive into PLC protocols and how to safely scan CODESYS-based ICS networking stacks.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/02/post-auth-exchange-etr.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Multiple DMS XSS (CVE-2022-47412 through CVE-20222-47419)</title>
		<link>https://noise.getoto.net/2023/02/07/multiple-dms-xss-cve-2022-47412-through-cve-20222-47419/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 07 Feb 2023 14:05:00 +0000</pubDate>
				<category><![CDATA[dms]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=68606b567c55f455433866291f02a498</guid>

					<description><![CDATA[Rapid7 has discovered, and is now disclosing, eight XSS issues affecting four on-premises document management systems. As of this disclosure, none have patches available.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/02/GettyImages-533557042.jpg" length="0" type="" />

			</item>
		<item>
		<title>Refreshing Rapid7&#8217;s Coordinated Vulnerability Disclosure Policy</title>
		<link>https://noise.getoto.net/2022/12/28/refreshing-rapid7s-coordinated-vulnerability-disclosure-policy/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Wed, 28 Dec 2022 17:02:50 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=de8013c8e406341e46fbd2c91dda4f49</guid>

					<description><![CDATA[Rapid7 has updated its coordinated vulnerability disclosure (CVD) policy and philosophy. In this article, you'll learn what prompted the changes.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/12/GettyImages-1411220647.jpg" length="0" type="" />

			</item>
		<item>
		<title>Never Mind the Ears, Here&#8217;s Security Nation</title>
		<link>https://noise.getoto.net/2022/12/21/never-mind-the-ears-heres-security-nation/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Wed, 21 Dec 2022 14:00:00 +0000</pubDate>
				<category><![CDATA[Security Nation]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=8855ec9330a28a4b511ccf8691bd7b83</guid>

					<description><![CDATA[It's another year down and another season down for Security Nation. With the close of our fifth season, we reflect on who we spoke with and what we talked about.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/12/security_nation_logo-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Cengage LTI Session Management Leakage</title>
		<link>https://noise.getoto.net/2022/12/20/cengage-lti-session-management-leakage/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 20 Dec 2022 14:05:00 +0000</pubDate>
				<category><![CDATA[cloud security]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=81f094f860b90eab5db8f311b5a59343</guid>

					<description><![CDATA[Cengage, an education technology provider in use in many higher education environments primarily in the United States, had two issues in the way it handled session management over its Learning Tools Integration (LTI) pipeline.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/12/business-2717066_1920.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-4261: Rapid7 Nexpose Update Validation Issue (FIXED)</title>
		<link>https://noise.getoto.net/2022/12/07/cve-2022-4261-rapid7-nexpose-update-validation-issue-fixed/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Wed, 07 Dec 2022 19:08:00 +0000</pubDate>
				<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=b79ca235b0f3b8f433160511c7f4c9ba</guid>

					<description><![CDATA[Nexpose version 6.6.172 fixes an issue with how Nexpose validates update packages, CVE-2022-4261.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/12/rapid7-nexpose-digital-lock.jpeg" length="0" type="" />

			</item>
		<item>
		<title>New Research: We’re Still Terrible at Passwords; Making it Easy for Attackers</title>
		<link>https://noise.getoto.net/2022/10/20/new-research-were-still-terrible-at-passwords-making-it-easy-for-attackers/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Thu, 20 Oct 2022 13:00:00 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=95804adebf157eab8ae013564bd4d645</guid>

					<description><![CDATA[We look at two of the most popular protocols used for remote administration, SSH and RDP, to get a sense of how attackers are taking advantage of weaker password management to gain access to systems.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/10/GettyImages-538571730.jpg" length="0" type="" />

			</item>
		<item>
		<title>25 Years of Nmap: Happy Scan-iversary!</title>
		<link>https://noise.getoto.net/2022/09/01/25-years-of-nmap-happy-scan-iversary/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Thu, 01 Sep 2022 14:30:46 +0000</pubDate>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=49fa8f55e4365ac70fc9ff2de105cc56</guid>

					<description><![CDATA[On September 1, 1997, the open-source security scanner Nmap was released. Our Director of Research Tod Beardsley reflects on the 25th anniversary.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/09/nmap-25th-anniversary.jpg" length="0" type="" />

			</item>
		<item>
		<title>Primary Arms PII Disclosure via IDOR</title>
		<link>https://noise.getoto.net/2022/08/02/primary-arms-pii-disclosure-via-idor/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 02 Aug 2022 15:00:00 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5574e888c66c249fc41779c0baf5eedb</guid>

					<description><![CDATA[Primary Arms, a popular e-commerce site dealing in firearms and related merchandise, suffers from an insecure direct object reference (IDOR) vulnerability.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/08/primary-arms-idor.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2021-3779: Ruby-MySQL Gem Client File Read (FIXED)</title>
		<link>https://noise.getoto.net/2022/06/28/cve-2021-3779-ruby-mysql-gem-client-file-read-fixed/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 28 Jun 2022 14:50:24 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=37459ffce975f45c28e2395f56367e33</guid>

					<description><![CDATA[The ruby-mysql Ruby gem prior to version 2.10.0 maintained by Tomita Masahiro is vulnerable to an instance of CWE-610.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/06/ruby-mysql.jpg" length="0" type="" />

			</item>
		<item>
		<title>The Hidden Harm of Silent Patches</title>
		<link>https://noise.getoto.net/2022/06/06/the-hidden-harm-of-silent-patches/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Mon, 06 Jun 2022 16:00:00 +0000</pubDate>
				<category><![CDATA[Rapid7 Perspective]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<category><![CDATA[Vulnerability Risk Management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=6fb93f99513738a3b5219817203b39b5</guid>

					<description><![CDATA[Silent patches limit who understands how to exploit a vulnerability, which sounds like a great plan — but there's a catch.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/06/silent-patches.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2022-1026: Kyocera Net View Address Book Exposure</title>
		<link>https://noise.getoto.net/2022/03/29/cve-2022-1026-kyocera-net-view-address-book-exposure/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 29 Mar 2022 13:29:15 +0000</pubDate>
				<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3889507e1f7928bbdf65d055da138c77</guid>

					<description><![CDATA[Rapid7 researcher Aaron Henderson has discovered that several models of Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/03/kyocera-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2021-3546[78]: Akkadian Console Server Vulnerabilities (FIXED)</title>
		<link>https://noise.getoto.net/2021/09/07/cve-2021-354678-akkadian-console-server-vulnerabilities-fixed/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 07 Sep 2021 13:00:00 +0000</pubDate>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=c0c0c3f5bf9a83cbed60e88cc7944da7</guid>

					<description><![CDATA[Rapid7 researchers discovered that the Akkadian Console version 4.7, a call manager solution, is affected by two vulnerabilities.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/09/akkadian-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2021-3927[67]: Fortress S03 WiFi Home Security System Vulnerabilities</title>
		<link>https://noise.getoto.net/2021/08/31/cve-2021-392767-fortress-s03-wifi-home-security-system-vulnerabilities/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 31 Aug 2021 13:00:00 +0000</pubDate>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=44bdd67de6da72b4173f27e81e125f2a</guid>

					<description><![CDATA[Rapid7 researcher Arvind Vishwakarma discovered multiple vulnerabilities in the Fortress S03 WiFi Home Security System.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/08/fortress-vuln.jpg" length="0" type="" />

			</item>
		<item>
		<title>Fortinet FortiWeb OS Command Injection</title>
		<link>https://noise.getoto.net/2021/08/17/fortinet-fortiweb-os-command-injection/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 17 Aug 2021 13:58:19 +0000</pubDate>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=9511625276530fb6a6d0d99d27559bab</guid>

					<description><![CDATA[An OS command injection vulnerability in FortiWeb's management interface can allow a remote, authenticated attacker to execute arbitrary commands on the system.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/08/cybersecurity-testing-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>Multiple Open Source Web App Vulnerabilities Fixed</title>
		<link>https://noise.getoto.net/2021/07/27/multiple-open-source-web-app-vulnerabilities-fixed/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Tue, 27 Jul 2021 14:30:24 +0000</pubDate>
				<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=fe8d5c8e90aab923746af63be2abaded</guid>

					<description><![CDATA[While it's never great to learn of new vulnerabilities in your own product, all three project maintainers accepted, validated, and provided fixes for these vulnerabilities within one day, which is amazing when it comes to vulnerability disclosure.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/07/Data-Vulnerability2.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2020-7387..7390: Multiple Sage X3 Vulnerabilities</title>
		<link>https://noise.getoto.net/2021/07/07/cve-2020-7387-7390-multiple-sage-x3-vulnerabilities/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Wed, 07 Jul 2021 13:05:00 +0000</pubDate>
				<guid isPermaLink="false">http://noise.getoto.net/?guid=7e8aecf6144050dea823eefc18d04c57</guid>

					<description><![CDATA[Four vulnerabilities involving Sage X3 were identified by Rapid7 researchers Jonathan Peterson, Aaron Herndon, Cale Black, Ryan Villarreal, and William Vu.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/07/erp.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2021-20025: SonicWall Email Security Appliance Backdoor Credential</title>
		<link>https://noise.getoto.net/2021/06/23/cve-2021-20025-sonicwall-email-security-appliance-backdoor-credential/</link>
		
		<dc:creator><![CDATA[Tod Beardsley]]></dc:creator>
		<pubDate>Wed, 23 Jun 2021 18:50:55 +0000</pubDate>
				<category><![CDATA[cloud security]]></category>
		<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=10e71fc54cb6724f1c75b5720cabdb2f</guid>

					<description><![CDATA[The virtual, on-premises version of the SonicWall Email Security Appliance ships with an undocumented, static credential, which can be used by an attacker to gain root privileges on the device.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/06/email-security.jpg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 31/257 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2026-02-09 11:45:04 by W3 Total Cache
-->