<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Detection and Response &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/detection-and-response/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Mon, 28 Apr 2025 11:57:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Active exploitation of SAP NetWeaver Visual Composer CVE-2025-31324</title>
		<link>https://noise.getoto.net/2025/04/28/active-exploitation-of-sap-netweaver-visual-composer-cve-2025-31324/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Mon, 28 Apr 2025 11:57:12 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=585e735948850f5c4503d5a7910daa78</guid>

					<description><![CDATA[A critical SAP NetWeaver zero-day vulnerability (CVE-2025-31324) that allows for full SAP server compromise is being actively exploited in the wild.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/04/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Password Spray Attacks Taking Advantage of Lax MFA</title>
		<link>https://noise.getoto.net/2025/04/10/password-spray-attacks-taking-advantage-of-lax-mfa/</link>
		
		<dc:creator><![CDATA[Chris Boyd]]></dc:creator>
		<pubDate>Thu, 10 Apr 2025 13:00:00 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=f79717e575d4605909fca748644318d7</guid>

					<description><![CDATA[In the first quarter of 2025, Rapid7’s Managed Threat Hunting team observed a significant volume of brute-force password attempts leveraging FastHTTP, a high-performance HTTP server and client library for Go, to automate unauthorized logins via HTTP requests.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/04/GettyImages-2084264422.jpg" length="0" type="" />

			</item>
		<item>
		<title>Fortinet firewalls hit with new zero-day attack, older data leak</title>
		<link>https://noise.getoto.net/2025/01/16/fortinet-firewalls-hit-with-new-zero-day-attack-older-data-leak/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Thu, 16 Jan 2025 15:57:23 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ab31e768b64e3083f4d837e3621f409a</guid>

					<description><![CDATA[Rapid7 is responding to two separate events affecting Fortinet firewall customers: Zero-day exploitation of CVE-2024-55591 in FortiOS, and a large-scale data leak of older FortiGate firewall IPs, passwords, and configs.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/01/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Modular Java Backdoor Dropped in Cleo Exploitation Campaign</title>
		<link>https://noise.getoto.net/2024/12/11/modular-java-backdoor-dropped-in-cleo-exploitation-campaign/</link>
		
		<dc:creator><![CDATA[Christiaan Beek]]></dc:creator>
		<pubDate>Wed, 11 Dec 2024 18:44:06 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Malware]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=cad0b0e53565b5b6d234ccb3033fff66</guid>

					<description><![CDATA[While investigating incidents related to Cleo software exploitation, Rapid7 Labs and MDR team discovered a novel, multi-stage attack that deploys an encoded Java Archive (JAR) payload.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/12/Cleo_FLow_Attack_v1-1.png" length="0" type="" />

			</item>
		<item>
		<title>Widespread exploitation of Cleo file transfer software (CVE-2024-50623)</title>
		<link>https://noise.getoto.net/2024/12/10/widespread-exploitation-of-cleo-file-transfer-software-cve-2024-50623/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Tue, 10 Dec 2024 14:04:17 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=73b95367e4899c4a1125c872429bc843</guid>

					<description><![CDATA[<p>On Monday, December 9, multiple security firms began privately circulating reports of in-the-wild exploitation targeting Cleo file transfer software. Late the evening of December 9, security firm Huntress published a blog on active exploitation of three different Cleo products (<a href="https://cleo-infoeng.s3.us-east-2.amazonaws.com/PDF/Harmony/5.8/Harmony_58_UserGuide_053123.pdf">docs</a>):</p><ul><li>Cleo VLTrader, a server-side solution for “mid-enterprise organizations”</li><li>Cleo Harmony,</li></ul>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/12/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware</title>
		<link>https://noise.getoto.net/2024/12/04/black-basta-ransomware-campaign-drops-zbot-darkgate-and-custom-malware/</link>
		
		<dc:creator><![CDATA[Tyler McGraw]]></dc:creator>
		<pubDate>Wed, 04 Dec 2024 15:45:04 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=2c9775b70e57a2ce095a7c96e4b1f71e</guid>

					<description><![CDATA[Beginning in early October, Rapid7 has observed a resurgence of activity related to the ongoing social engineering campaign being conducted by Black Basta ransomware operators.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/12/GettyImages-2180078018.jpg" length="0" type="" />

			</item>
		<item>
		<title>Investigating a SharePoint Compromise: IR Tales from the Field</title>
		<link>https://noise.getoto.net/2024/10/30/investigating-a-sharepoint-compromise-ir-tales-from-the-field/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Wed, 30 Oct 2024 20:19:14 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=afde110ab71146f8f6bf1be76ee329ed</guid>

					<description><![CDATA[Our investigation uncovered an attacker who accessed a server without authorization and moved laterally across the network, compromising the entire domain.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/10/GettyImages-1422990988.jpg" length="0" type="" />

			</item>
		<item>
		<title>Three Recommendations for Creating a Risk-Based Detection and Response Program</title>
		<link>https://noise.getoto.net/2024/09/24/three-recommendations-for-creating-a-risk-based-detection-and-response-program/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Tue, 24 Sep 2024 13:00:00 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Gartner]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=d95574e7dbc70cd279207bf9f4a8d250</guid>

					<description><![CDATA[In a report released earlier this summer, Gartner analysts offer three recommendations for fostering an environment of risk-based threat detection, investigation, and response that includes a deeper understanding of your organization’s risk profile by more than just the security team.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/09/GettyImages-1475344810.jpg" length="0" type="" />

			</item>
		<item>
		<title>VMware ESXi CVE-2024-37085 Targeted in Ransomware Campaigns</title>
		<link>https://noise.getoto.net/2024/07/30/vmware-esxi-cve-2024-37085-targeted-in-ransomware-campaigns/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Tue, 30 Jul 2024 00:28:10 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=a713a4334973d03daa00ec30f241c0c8</guid>

					<description><![CDATA[On July 29, Microsoft published threat intelligence on observed exploitation of CVE-2024-37085, an authentication bypass vulnerability in Broadcom VMware ESXi hypervisors that has been used in multiple ransomware campaigns.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/07/emergent-threat-banner-1-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Supply Chain Compromise Leads to Trojanized Installers for Notezilla, RecentX, Copywhiz</title>
		<link>https://noise.getoto.net/2024/06/27/supply-chain-compromise-leads-to-trojanized-installers-for-notezilla-recentx-copywhiz/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Thu, 27 Jun 2024 18:01:02 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=57a2f50d3de0361f25ef9c3caed3a05e</guid>

					<description><![CDATA[<p>The following Rapid7 analysts contributed to this research: Leo Gutierrez, Tyler McGraw, Sarah Lee, and Thomas Elkins.</p><!--kg-card-begin: markdown--><h2>Executive Summary</h2>
<p>On Tuesday, June 18th, 2024, Rapid7 initiated an investigation into suspicious activity in a customer environment. Our investigation identified that the suspicious behavior was emanating from the installation of Notezilla, a</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/06/GettyImages-1128503636.jpg" length="0" type="" />

			</item>
		<item>
		<title>Malvertising Campaign Leads to Execution of Oyster Backdoor</title>
		<link>https://noise.getoto.net/2024/06/17/malvertising-campaign-leads-to-execution-of-oyster-backdoor/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Mon, 17 Jun 2024 20:28:23 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3e3cdb628acb9d36e96fee76a43274ec</guid>

					<description><![CDATA[Rapid7 has observed a recent malvertising campaign that lures users into downloading malicious installers for popular software such as Google Chrome and Microsoft Teams.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/06/Managed.jpg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2024-4978: Backdoored Justice AV Solutions Viewer Software Used in Apparent Supply Chain Attack</title>
		<link>https://noise.getoto.net/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Thu, 23 May 2024 13:00:00 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=827f2bd7cfaab2a2b4dfdab7fa176157</guid>

					<description><![CDATA[Justice AV Solutions (JAVS) is a U.S.-based company specializing in digital audio-visual recording solutions for courtroom environments. 

Rapid7 has determined that users with JAVS Viewer v8.3.7 installed are at high risk and should take immediate action.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/05/emergent-threat-banner-1-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Rapid7 Recognized in the 2024 Gartner® Magic Quadrant™ for SIEM</title>
		<link>https://noise.getoto.net/2024/05/13/rapid7-recognized-in-the-2024-gartner-magic-quadrant-for-siem/</link>
		
		<dc:creator><![CDATA[Meaghan Buchanan]]></dc:creator>
		<pubDate>Mon, 13 May 2024 15:06:25 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[siem]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=a4528fa3af8838c5c3d952115baf1dfc</guid>

					<description><![CDATA[Rapid7 is excited to share that we are named a Challenger for InsightIDR in the 2024 Gartner Magic Quadrant for SIEM.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/05/GettyImages-1350595566.jpg" length="0" type="" />

			</item>
		<item>
		<title>Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators</title>
		<link>https://noise.getoto.net/2024/05/10/ongoing-social-engineering-campaign-linked-to-black-basta-ransomware-operators/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Fri, 10 May 2024 17:31:59 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=681b197783c83554cc064ff84933474d</guid>

					<description><![CDATA[Rapid7 observes ongoing social engineering campaign consistent with Black Basta]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/05/GettyImages-1518854805.jpg" length="0" type="" />

			</item>
		<item>
		<title>RCE to Sliver: IR Tales from the Field</title>
		<link>https://noise.getoto.net/2024/02/15/rce-to-sliver-ir-tales-from-the-field/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Thu, 15 Feb 2024 19:38:59 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=8d62a23d94ff4ae9e3b4f55522f0569c</guid>

					<description><![CDATA[Rapid7 Incident Response was engaged to investigate an incident involving unauthorized access to two publicly-facing Confluence servers that were the source of multiple malware executions.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/02/GettyImages-1488115481.jpg" length="0" type="" />

			</item>
		<item>
		<title>Velociraptor 0.7.1 Release: Sigma Support, ETW Multiplexing, Local Encrypted Storage and New VQL Capabilities Highlight the Last Release of 2023</title>
		<link>https://noise.getoto.net/2023/12/29/velociraptor-0-7-1-release-sigma-support-etw-multiplexing-local-encrypted-storage-and-new-vql-capabilities-highlight-the-last-release-of-2023/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Fri, 29 Dec 2023 15:52:00 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Velociraptor]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=4379c7d7b9fa2fb739ee05cde644de41</guid>

					<description><![CDATA[Rapid7 is excited to announce that version 0.7.1 of Velociraptor is live and available for download.  There are several new features and capabilities that add to the power and efficiency of this open-source digital forensic and incident response (DFIR) platform.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/12/Screenshot-2023-12-27-at-11.40.29-AM.png" length="0" type="" />

			</item>
		<item>
		<title>Mastering Industrial Cybersecurity: The Significance of Combining Vulnerability Management with Detection and Response</title>
		<link>https://noise.getoto.net/2023/12/28/mastering-industrial-cybersecurity-the-significance-of-combining-vulnerability-management-with-detection-and-response/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Thu, 28 Dec 2023 16:00:00 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=8176608eb8e1150fc208248569126409</guid>

					<description><![CDATA[The convergence of operational technology (OT) and information technology (IT) has ushered in new efficiencies but has also exposed vulnerabilities. This article explores the pivotal role of Vulnerability Management and Detection and Response (VM/DR) in the realm of Industrial Cybersecurity.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/12/GettyImages-653379076.jpg" length="0" type="" />

			</item>
		<item>
		<title>What’s New in Rapid7 Detection &#038; Response: Q3 2023 in Review</title>
		<link>https://noise.getoto.net/2023/10/05/whats-new-in-rapid7-detection-response-q3-2023-in-review/</link>
		
		<dc:creator><![CDATA[Margaret Wei]]></dc:creator>
		<pubDate>Thu, 05 Oct 2023 15:49:48 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[DFIR]]></category>
		<category><![CDATA[InsightIDR]]></category>
		<category><![CDATA[Velociraptor]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=74cc37d4a37a598082ea50313dd3588c</guid>

					<description><![CDATA[Rapid7 has updated its Detection and Response offerings with advanced DFIR capabilities, custom detection rules, log search features, and more.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/10/GettyImages-1128503636.jpg" length="0" type="" />

			</item>
		<item>
		<title>Fake Update Utilizes New IDAT Loader To Execute StealC and Lumma Infostealers</title>
		<link>https://noise.getoto.net/2023/09/01/fake-update-utilizes-new-idat-loader-to-execute-stealc-and-lumma-infostealers/</link>
		
		<dc:creator><![CDATA[Natalie Zargarov]]></dc:creator>
		<pubDate>Thu, 31 Aug 2023 21:44:27 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=84b870d23e9df5e3bafb47c579afa533</guid>

					<description><![CDATA[Rapid7 has observed the Fake Browser Update lure utilizing a sophisticated new loader to execute infostealers.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/08/GettyImages-1128503636-1.jpg" length="0" type="" />

			</item>
		<item>
		<title>Under Siege: Rapid7-Observed Exploitation of Cisco ASA SSL VPNs</title>
		<link>https://noise.getoto.net/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Tue, 29 Aug 2023 14:00:00 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=258367784d61375ff64987b255c4083a</guid>

					<description><![CDATA[Rapid7’s managed detection and response (MDR) teams have observed increased threat activity targeting Cisco ASA SSL VPN appliances (physical and virtual) dating back to at least March 2023, including several incidents that ended in ransomware deployment.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2023/08/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 29/309 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-08 08:36:02 by W3 Total Cache
-->