<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emergent Threat Response &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/emergent-threat-response/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Thu, 04 Dec 2025 16:05:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>React2Shell (CVE-2025-55182) &#8211; Critical unauthenticated RCE affecting React Server Components</title>
		<link>https://noise.getoto.net/2025/12/04/react2shell-cve-2025-55182-critical-unauthenticated-rce-affecting-react-server-components/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Thu, 04 Dec 2025 16:05:50 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=86736633abea6180c3bf488088d4ad2d</guid>

					<description><![CDATA[OverviewOn December 3, 2025, Meta disclosed a new vulnerability, CVE-2025-55182, which has since been dubbed React2Shell. A second CVE identifier, CVE-2025-66478, was assigned and published to track the vulnerability in the context of Next.js. However ...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" length="0" type="" />

			</item>
		<item>
		<title>CVE-2025-64446: Critical Vulnerability in Fortinet FortiWeb Exploited in the Wild</title>
		<link>https://noise.getoto.net/2025/11/13/cve-2025-64446-critical-vulnerability-in-fortinet-fortiweb-exploited-in-the-wild/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Thu, 13 Nov 2025 21:36:27 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=da86d6cb666c73f3501f25e943f73bf6</guid>

					<description><![CDATA[OverviewOn October 6, 2025, the cyber deception company Defused published a proof-of-concept exploit on social media that was captured by one of their Fortinet FortiWeb Manager honeypots. FortiWeb is a Web Application Firewall (WAF) product that is des...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" length="0" type="" />

			</item>
		<item>
		<title>Ivanti Endpoint Manager Mobile exploit chain exploited in the wild</title>
		<link>https://noise.getoto.net/2025/05/16/ivanti-endpoint-manager-mobile-exploit-chain-exploited-in-the-wild/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Fri, 16 May 2025 11:00:20 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[InsightVM]]></category>
		<category><![CDATA[Nexpose]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3f5c8acb268ff78836ae527ef6989557</guid>

					<description><![CDATA[On May 13, 2025, Ivanti disclosed an exploited in the wild exploit chain, comprising of two new vulnerabilities affecting Ivanti Endpoint Manager Mobile: CVE-2025-4427 and CVE-2025-4428.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/emergent-threat-banner-1-2.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2025-32756 Exploited in the Wild, Affecting Multiple Fortinet Products</title>
		<link>https://noise.getoto.net/2025/05/14/cve-2025-32756-exploited-in-the-wild-affecting-multiple-fortinet-products/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Wed, 14 May 2025 14:59:20 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[InsightVM]]></category>
		<category><![CDATA[Nexpose]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=2faee9200943cae6b92ab50f068c465f</guid>

					<description><![CDATA[On May 13, 2025, Fortinet disclosed CVE-2025-32756, an unauthenticated stack-based buffer overflow affecting multiple FortiNet products; including FortiVoice, FortiRecorder, FortiNDR, FortiMail, and FortiCamera.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Active exploitation of SAP NetWeaver Visual Composer CVE-2025-31324</title>
		<link>https://noise.getoto.net/2025/04/28/active-exploitation-of-sap-netweaver-visual-composer-cve-2025-31324/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Mon, 28 Apr 2025 11:57:12 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=585e735948850f5c4503d5a7910daa78</guid>

					<description><![CDATA[A critical SAP NetWeaver zero-day vulnerability (CVE-2025-31324) that allows for full SAP server compromise is being actively exploited in the wild.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/04/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Ivanti Connect Secure CVE-2025-22457 exploited in the wild</title>
		<link>https://noise.getoto.net/2025/04/03/ivanti-connect-secure-cve-2025-22457-exploited-in-the-wild/</link>
		
		<dc:creator><![CDATA[Ryan Emmons]]></dc:creator>
		<pubDate>Thu, 03 Apr 2025 18:50:02 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ef69275a89bd044479527f9cd655f500</guid>

					<description><![CDATA[On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical a stack-based buffer overflow vulnerability that allows for remote code execution on affected devices.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/04/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Multiple vulnerabilities in Ingress NGINX Controller for Kubernetes</title>
		<link>https://noise.getoto.net/2025/03/25/multiple-vulnerabilities-in-ingress-nginx-controller-for-kubernetes/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Tue, 25 Mar 2025 16:10:50 +0000</pubDate>
				<category><![CDATA[cloud security]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e2aad7ff9aa3232f879e893547406a34</guid>

					<description><![CDATA[On March 24, 2025, Kubernetes disclosed 5 new vulnerabilities affecting the Ingress NGINX Controller for Kubernetes. Successful exploitation could allow attackers access to all secrets stored across all namespaces in the Kubernetes cluster, which could result in cluster takeover.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/03/emergent-threat-banner-3.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Notable vulnerabilities in Next.js (CVE-2025-29927) and CrushFTP</title>
		<link>https://noise.getoto.net/2025/03/25/notable-vulnerabilities-in-next-js-cve-2025-29927-and-crushftp/</link>
		
		<dc:creator><![CDATA[Calum Hutton]]></dc:creator>
		<pubDate>Tue, 25 Mar 2025 15:12:56 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=9924806a17d576a205aa3c898c619052</guid>

					<description><![CDATA[Rapid7 is warning customers of two notable vulnerabilities affecting Next.js (CVE-2025-29927) and file transfer software CrushFTP (no CVE).]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/03/emergent-threat-banner-2.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Critical Veeam Backup &#038; Replication CVE-2025-23120</title>
		<link>https://noise.getoto.net/2025/03/19/critical-veeam-backup-replication-cve-2025-23120/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Wed, 19 Mar 2025 19:51:26 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=b083fb176c10f7073952ef5438d79569</guid>

					<description><![CDATA[<p>On Wednesday, March 19, 2025, backup and recovery software provider Veeam published a <a href="https://www.veeam.com/kb4724">security advisory</a> for a critical remote code execution vulnerability tracked as <a href="https://attackerkb.com/topics/dHwvvN9gfv/cve-2025-23120">CVE-2025-23120</a>. The vulnerability affects Backup &#38; Replication systems that are domain joined. Veeam explicitly mentions that domain-joined backup servers are against security and compliance best practices,</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/03/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Apache Tomcat CVE-2025-24813: What You Need to Know</title>
		<link>https://noise.getoto.net/2025/03/19/apache-tomcat-cve-2025-24813-what-you-need-to-know/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Wed, 19 Mar 2025 17:40:52 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=0b6bdde08532a2c03d0cd0f384936118</guid>

					<description><![CDATA[<p>Here at Rapid7, our usual bar for calling a vulnerability an emergent threat is either known exploitation at scale, or likelihood of exploitation at scale. Apache Tomcat <a href="https://attackerkb.com/topics/4GajxQH17l/cve-2025-24813">CVE-2025-24813</a> fulfills neither of these criteria, despite a variety of news headlines alleging broad exploitation in the wild. Tomcat is widely deployed and</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/03/etr-banner-2.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Multiple zero-day vulnerabilities in Broadcom VMware ESXi and other products</title>
		<link>https://noise.getoto.net/2025/03/04/multiple-zero-day-vulnerabilities-in-broadcom-vmware-esxi-and-other-products/</link>
		
		<dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
		<pubDate>Tue, 04 Mar 2025 17:00:13 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=172ef530764aad919e0f10cdce8bfbb9</guid>

					<description><![CDATA[On Tuesday, March 4, 2025, Broadcom published a critical security advisory (VMSA-2025-0004) on 3 new zero-day vulnerabilities affecting multiple VMware products, including ESXi, Workstation, and Fusion.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/03/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Fortinet firewalls hit with new zero-day attack, older data leak</title>
		<link>https://noise.getoto.net/2025/01/16/fortinet-firewalls-hit-with-new-zero-day-attack-older-data-leak/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Thu, 16 Jan 2025 15:57:23 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ab31e768b64e3083f4d837e3621f409a</guid>

					<description><![CDATA[Rapid7 is responding to two separate events affecting Fortinet firewall customers: Zero-day exploitation of CVE-2024-55591 in FortiOS, and a large-scale data leak of older FortiGate firewall IPs, passwords, and configs.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/01/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2025-0282: Ivanti Connect Secure zero-day exploited in the wild</title>
		<link>https://noise.getoto.net/2025/01/08/cve-2025-0282-ivanti-connect-secure-zero-day-exploited-in-the-wild/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Wed, 08 Jan 2025 18:13:13 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=01050d3f41f01c12c034a865ebd66d66</guid>

					<description><![CDATA[Two stack-based buffer overflow issues were disclosed in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA. CVE-2025-0282, the more severe of the two issues, has been exploited in the wild against Ivanti Connect Secure devices.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/01/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Modular Java Backdoor Dropped in Cleo Exploitation Campaign</title>
		<link>https://noise.getoto.net/2024/12/11/modular-java-backdoor-dropped-in-cleo-exploitation-campaign/</link>
		
		<dc:creator><![CDATA[Christiaan Beek]]></dc:creator>
		<pubDate>Wed, 11 Dec 2024 18:44:06 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Malware]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=cad0b0e53565b5b6d234ccb3033fff66</guid>

					<description><![CDATA[While investigating incidents related to Cleo software exploitation, Rapid7 Labs and MDR team discovered a novel, multi-stage attack that deploys an encoded Java Archive (JAR) payload.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/12/Cleo_FLow_Attack_v1-1.png" length="0" type="" />

			</item>
		<item>
		<title>Widespread exploitation of Cleo file transfer software (CVE-2024-50623)</title>
		<link>https://noise.getoto.net/2024/12/10/widespread-exploitation-of-cleo-file-transfer-software-cve-2024-50623/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Tue, 10 Dec 2024 14:04:17 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=73b95367e4899c4a1125c872429bc843</guid>

					<description><![CDATA[<p>On Monday, December 9, multiple security firms began privately circulating reports of in-the-wild exploitation targeting Cleo file transfer software. Late the evening of December 9, security firm Huntress published a blog on active exploitation of three different Cleo products (<a href="https://cleo-infoeng.s3.us-east-2.amazonaws.com/PDF/Harmony/5.8/Harmony_58_UserGuide_053123.pdf">docs</a>):</p><ul><li>Cleo VLTrader, a server-side solution for “mid-enterprise organizations”</li><li>Cleo Harmony,</li></ul>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/12/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Zero-day exploitation targeting Palo Alto Networks firewall management interfaces</title>
		<link>https://noise.getoto.net/2024/11/15/zero-day-exploitation-targeting-palo-alto-networks-firewall-management-interfaces/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Fri, 15 Nov 2024 12:44:09 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e21b583a0596f6623214eed7c3ff4b03</guid>

					<description><![CDATA[Palo Alto Networks has indicated they are observing threat activity exploiting a zero-day unauthenticated remote command execution vulnerability in their firewall management interfaces.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/11/emergent-threat-banner.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Fortinet FortiManager CVE-2024-47575 Exploited in Zero-Day Attacks</title>
		<link>https://noise.getoto.net/2024/10/23/fortinet-fortimanager-cve-2024-47575-exploited-in-zero-day-attacks/</link>
		
		<dc:creator><![CDATA[Caitlin Condon]]></dc:creator>
		<pubDate>Wed, 23 Oct 2024 16:21:47 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=1401007d29ae885e7a8a27f39328be21</guid>

					<description><![CDATA[On Wednesday, October 23, 2024, security company Fortinet published an advisory on CVE-2024-47575, a critical zero-day vulnerability affecting their FortiManager network management solution.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/10/emergent-threat-banner-1.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Multiple Vulnerabilities in Common Unix Printing System (CUPS)</title>
		<link>https://noise.getoto.net/2024/09/27/multiple-vulnerabilities-in-common-unix-printing-system-cups/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Thu, 26 Sep 2024 22:48:34 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=1c3a91f96caac5f6709c3ad1d595cd91</guid>

					<description><![CDATA[Multiple unpatched vulnerabilities were publicly disclosed in the Common Unix Printing System (CUPS), a popular IPP-based open-source printing system.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/09/emergent-threat-banner-1-3.jpeg" length="0" type="" />

			</item>
		<item>
		<title>High-risk vulnerabilities in common enterprise technologies</title>
		<link>https://noise.getoto.net/2024/09/19/high-risk-vulnerabilities-in-common-enterprise-technologies/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Thu, 19 Sep 2024 20:45:57 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=00ec3d70f1ec613322b2afbc71b29ec8</guid>

					<description><![CDATA[Rapid7 is warning customers about high-risk vulnerabilities in Adobe ColdFusion, Broadcom VMware vCenter Server, and Ivanti Endpoint Manager (EPM). These CVEs are likely attack targets for APT and/or financially motivated adversaries.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/09/emergent-threat-banner-1-2.jpeg" length="0" type="" />

			</item>
		<item>
		<title>CVE-2024-40766: Critical Improper Access Control Vulnerability Affecting SonicWall Devices</title>
		<link>https://noise.getoto.net/2024/09/09/cve-2024-40766-critical-improper-access-control-vulnerability-affecting-sonicwall-devices/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Mon, 09 Sep 2024 18:38:23 +0000</pubDate>
				<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e4b4efda867a3eab4558e6ad3e9d0a9d</guid>

					<description><![CDATA[CVE-2024-40766 is a critical improper access control vulnerability affecting SonicOS, the operating system that runs on the company’s physical and virtual firewalls. As of September 9, 2024, Rapid7 is aware of several recent incidents in which SonicWall SSLVPN accounts were targeted or compromised.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/09/emergent-threat-banner-1-1.jpeg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 24/288 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-11 12:18:04 by W3 Total Cache
-->