<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>exploits &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Tue, 14 Oct 2025 16:06:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Apple’s Bug Bounty Program</title>
		<link>https://noise.getoto.net/2025/10/15/apples-bug-bounty-program/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 15 Oct 2025 11:02:18 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70981</guid>

					<description><![CDATA[<p>Apple is now offering a <a href="https://arstechnica.com/security/2025/10/apple-ups-the-reward-for-finding-major-exploits-to-2-million/">$2M</a> <a href="https://www.csoonline.com/article/4071044/apple-bumps-rce-bug-bounties-to-2m-to-counter-commercial-spyware-vendors.html">bounty</a> for a zero-click exploit. According to <a href="https://security.apple.com/blog/apple-security-bounty-evolved/">the Apple website</a>:</p>
<blockquote><p>Today we’re announcing the next major chapter for Apple Security Bounty, featuring the industry’s highest rewards, expanded research categories, and a flag system for researchers to objectively demonstrate vulnerabilities and obtain accelerated awards.</p>
<ol>
<li>We’re doubling our top award to $2 million for exploit chains that can achieve similar goals as sophisticated mercenary spyware attacks. This is an unprecedented amount in the industry and the largest payout offered by any bounty program we’re aware of ­ and our bonus system, providing additional rewards for Lockdown Mode bypasses and vulnerabilities discovered in beta software, can more than double this reward, with a maximum payout in excess of $5 million. We’re also doubling or significantly increasing rewards in many other categories to encourage more intensive research. This includes $100,000 for a complete Gatekeeper bypass, and $1 million for broad unauthorized iCloud access, as no successful exploit has been demonstrated to date in either category.
...</li></ol></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Zero-Day Exploit in WinRAR File</title>
		<link>https://noise.getoto.net/2025/08/19/zero-day-exploit-in-winrar-file/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 19 Aug 2025 11:07:28 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[russia]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[zero day]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70599</guid>

					<description><![CDATA[<p>A zero-day vulnerability in WinRAR is <a href="https://arstechnica.com/security/2025/08/high-severity-winrar-0-day-exploited-for-weeks-by-2-groups/">being exploited</a> by at least two Russian criminal groups:</p>
<blockquote><p>The vulnerability seemed to have super Windows powers. It abused <a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fscc/c54dec26-1551-4d3a-a0ea-4fa40f848eb3">alternate data streams</a>, a Windows feature that allows different ways of representing the same file path. The exploit abused that feature to trigger a previously unknown path traversal flaw that caused WinRAR to plant malicious executables in attacker-chosen file paths %TEMP% and %LOCALAPPDATA%, which Windows normally makes off-limits because of their ability to execute code.</p></blockquote>
<p>More details in the article...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Microsoft SharePoint Zero-Day</title>
		<link>https://noise.getoto.net/2025/07/28/microsoft-sharepoint-zero-day/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 28 Jul 2025 11:09:22 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[zero day]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70517</guid>

					<description><![CDATA[<p>Chinese hackers are exploiting a high-severity vulnerability in Microsoft SharePoint to <a href="https://arstechnica.com/security/2025/07/sharepoint-vulnerability-with-9-8-severity-rating-is-under-exploit-across-the-globe/">steal data</a> worldwide:</p>
<blockquote><p>The vulnerability, tracked as CVE-2025-53770, carries a severity rating of 9.8 out of a possible 10. It gives unauthenticated remote access to SharePoint Servers exposed to the Internet. Starting Friday, researchers began warning of active exploitation of the vulnerability, which affects SharePoint Servers that infrastructure customers run in-house. Microsoft’s cloud-hosted SharePoint Online and Microsoft 365 are not affected.</p></blockquote>
<p><a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/">Here’s...</a></p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Court Rules Against NSO Group</title>
		<link>https://noise.getoto.net/2025/05/13/court-rules-against-nso-group/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 13 May 2025 11:07:54 +0000</pubDate>
				<category><![CDATA[courts]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[israel]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70255</guid>

					<description><![CDATA[The case is over:
A jury has awarded WhatsApp $167 million in punitive damages in a case the company brought against Israel-based NSO Group for exploiting a software vulnerability that hijacked the phones of thousands of users.
I&#8217;m sure it&#8217;...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up 7/19/2024</title>
		<link>https://noise.getoto.net/2024/07/19/metasploit-weekly-wrap-up-7-19-2024/</link>
		
		<dc:creator><![CDATA[Christophe De La Fuente]]></dc:creator>
		<pubDate>Fri, 19 Jul 2024 16:46:06 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=66905a5ebe9896150f65284658ae9a48</guid>

					<description><![CDATA[A new unauthenticated RCE exploit for GeoServer, plus library and Meterpreter updates and enhancements.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/07/metasploit-sky.png" length="0" type="" />

			</item>
		<item>
		<title>New iPhone Exploit Uses Four Zero-Days</title>
		<link>https://noise.getoto.net/2024/01/04/new-iphone-exploit-uses-four-zero-days/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 04 Jan 2024 12:11:49 +0000</pubDate>
				<category><![CDATA[backdoors]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[kaspersky]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[zero day]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=68259</guid>

					<description><![CDATA[<p>Kaspersky researchers <a href="https://arstechnica.com/security/2023/12/exploit-used-in-mass-iphone-infection-campaign-targeted-secret-hardware-feature/#p3">are detailing</a> “an attack that over four years backdoored dozens if not thousands of iPhones, many of which belonged to employees of Moscow-based security firm Kaspersky.” It’s a zero-click exploit that makes use of four iPhone zero-days.</p>
<blockquote><p>The most intriguing new detail is the targeting of the heretofore-unknown hardware feature, which proved to be pivotal to the Operation Triangulation campaign. A zero-day in the feature allowed the attackers to bypass advanced <a href="https://support.apple.com/guide/security/operating-system-integrity-sec8b776536b/web">hardware-based memory protections</a> designed to safeguard device system integrity even after an attacker gained the ability to tamper with memory of the underlying kernel. On most other platforms, once attackers successfully exploit a kernel vulnerability they have full control of the compromised system...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>New Windows/Linux Firmware Attack</title>
		<link>https://noise.getoto.net/2023/12/12/new-windows-linux-firmware-attack/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 12 Dec 2023 12:01:18 +0000</pubDate>
				<category><![CDATA[BIOS]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[firmware]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=68191</guid>

					<description><![CDATA[<p>Interesting attack based on malicious pre-OS <a href="https://arstechnica.com/security/2023/12/just-about-every-windows-and-linux-device-vulnerable-to-new-logofail-firmware-attack/">logo images</a>:</p>
<blockquote><p>LogoFAIL is a constellation of two dozen newly discovered vulnerabilities that have lurked for years, if not decades, in Unified Extensible Firmware Interfaces responsible for booting modern devices that run Windows or Linux….</p>
<p>The vulnerabilities are the subject of a coordinated mass disclosure released Wednesday. The participating companies comprise nearly the entirety of the x64 and ARM CPU ecosystem, starting with UEFI suppliers AMI, Insyde, and Phoenix (sometimes still called IBVs or independent BIOS vendors); device manufacturers such as Lenovo, Dell, and HP; and the makers of the CPUs that go inside the devices, usually Intel, AMD or designers of ARM CPUs…...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Zero-Click Exploit in iPhones</title>
		<link>https://noise.getoto.net/2023/09/13/zero-click-exploit-in-iphones/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 13 Sep 2023 11:13:39 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=67777</guid>

					<description><![CDATA[<p>Make sure you <a href="https://www.bleepingcomputer.com/news/security/apple-zero-click-imessage-exploit-used-to-infect-iphones-with-spyware/">update your iPhones</a>:</p>
<blockquote><p>Citizen Lab says two zero-days fixed by Apple today in emergency security updates were actively abused as part of a zero-click exploit chain (dubbed BLASTPASS) to deploy NSO Group’s Pegasus commercial spyware onto fully patched iPhones.</p>
<p>The two bugs, <a href="https://www.bleepingcomputer.com/news/apple/apple-discloses-2-new-zero-days-exploited-to-attack-iphones-macs/">tracked as CVE-2023-41064 and CVE-2023-41061</a>, allowed the attackers to infect a fully-patched iPhone running iOS 16.6 and belonging to a Washington DC-based civil society organization via PassKit attachments containing malicious images.</p>
<p>“We refer to the exploit chain as BLASTPASS. The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” Citizen Lab ...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Operation Triangulation: Zero-Click iPhone Malware</title>
		<link>https://noise.getoto.net/2023/06/09/operation-triangulation-zero-click-iphone-malware/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 09 Jun 2023 11:12:42 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=67431</guid>

					<description><![CDATA[<p>Kaspersky is <a href="https://securelist.com/operation-triangulation/109842/">reporting</a> a zero-click iOS exploit in the wild:</p>
<blockquote><p>Mobile device backups contain a partial copy of the filesystem, including some of the user data and service databases. The timestamps of the files, folders and the database records allow to roughly reconstruct the events happening to the device. The mvt-ios utility produces a sorted timeline of events into a file called “timeline.csv,” similar to a super-timeline used by conventional digital forensic tools.</p>
<p>Using this timeline, we were able to identify specific artifacts that indicate the compromise. This allowed to move the research forward, and to reconstruct the general infection sequence:...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>New Zero-Click Exploits against iOS</title>
		<link>https://noise.getoto.net/2023/04/20/new-zero-click-exploits-against-ios/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 20 Apr 2023 10:47:17 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Human Rights]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=67251</guid>

					<description><![CDATA[Citizen Lab has identified three zero-click exploits against iOS 15 and 16. These were used by NSO Group&#8217;s Pegasus spyware in 2022, and deployed by Mexico against human rights defenders. These vulnerabilities have all been patched.
One interestin...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Zoom Exploit on MacOS</title>
		<link>https://noise.getoto.net/2022/08/17/zoom-exploit-on-macos/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 17 Aug 2022 11:11:17 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[privilege escalation]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=65787</guid>

					<description><![CDATA[<p>This <a href="https://www.theverge.com/2022/8/12/23303411/zoom-defcon-root-access-privilege-escalation-hack-patrick-wardle">vulnerability</a> was reported to Zoom last December:</p>
<blockquote><p>The exploit works by targeting the installer for the Zoom application, which needs to run with special user permissions in order to install or remove the main Zoom application from a computer. Though the installer requires a user to enter their password on first adding the application to the system, Wardle found that an auto-update function then continually ran in the background with superuser privileges.</p>
<p>When Zoom issued an update, the updater function would install the new package after checking that it had been cryptographically signed by Zoom. But a bug in how the checking method was implemented meant that giving the updater any file with the same name as Zoom’s signing certificate would be enough to pass the test—so an attacker could substitute any kind of malware program and have it be run by the updater with elevated privilege...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Weekly Wrap-Up</title>
		<link>https://noise.getoto.net/2022/03/04/metasploit-weekly-wrap-up-6/</link>
		
		<dc:creator><![CDATA[Shelby Pace]]></dc:creator>
		<pubDate>Fri, 04 Mar 2022 21:52:42 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=4bfd931715758c7b7e2711a580bfea5e</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><p>This week’s Metasploit Framework release brings us seven new modules.</p>
<h2>IP Camera Exploitation</h2>
<p>Rapid7’s <a href="https://github.com/jbaines-r7">Jacob Baines</a> was busy this week with two exploit modules that target IP cameras. The <a href="https://github.com/rapid7/metasploit-framework/pull/16190">first</a> module exploits an authenticated file upload on Axis IP cameras. Due to lack of proper sanitization, an attacker</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/03/metasploit-fence.png" length="0" type="" />

			</item>
		<item>
		<title>More on NSO Group and Cytrox: Two Cyberweapons Arms Manufacturers</title>
		<link>https://noise.getoto.net/2021/12/20/more-on-nso-group-and-cytrox-two-cyberweapons-arms-manufacturers/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 20 Dec 2021 15:17:41 +0000</pubDate>
				<category><![CDATA[Citizen Lab]]></category>
		<category><![CDATA[cyberweapons]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=64686</guid>

					<description><![CDATA[<p>Citizen Lab published <a href="https://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/">another report</a> on the spyware used against two Egyptian nationals. One was hacked by NSO Group’s Pegasus spyware. The other was hacked both by Pegasus and by the spyware from another cyberweapons arms manufacturer: Cytrox.</p>
<p>We haven’t heard a lot about Cytrox and its Predator spyware. According to Citzen Lab:</p>
<blockquote><p>We conducted Internet scanning for Predator spyware servers and found likely Predator customers in Armenia, Egypt, Greece, Indonesia, Madagascar, Oman, Saudi Arabia, and Serbia.</p>
<p>Cytrox was reported to be part of <a href="https://intellexa.com/">Intellexa...</a></p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>The Everyperson’s Guide to Log4Shell (CVE-2021-44228)</title>
		<link>https://noise.getoto.net/2021/12/15/the-everypersons-guide-to-log4shell-cve-2021-44228/</link>
		
		<dc:creator><![CDATA[boB Rudis]]></dc:creator>
		<pubDate>Wed, 15 Dec 2021 19:44:42 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[log4j]]></category>
		<category><![CDATA[log4shell]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=9cb105938bde92f573a2de68bc20cf46</guid>

					<description><![CDATA[This blog is for everyone who wants to understand what’s going on with the Log4Shell vulnerability in Log4j and why the internet seems to be on fire again.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/12/log4shell-faq.jpg" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up</title>
		<link>https://noise.getoto.net/2021/12/10/metasploit-wrap-up-36/</link>
		
		<dc:creator><![CDATA[Jeffrey Martin]]></dc:creator>
		<pubDate>Fri, 10 Dec 2021 21:36:13 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ae824d3989c792700a622c455d8ee160</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Word and Javascript are a rare duo.</h2>
<p>Thanks to <a href="https://github.com/thesunRider">thesunRider</a>. you too can experience the wonder of this mystical duo. The sole new metasploit module this release adds a file format attack to generate a very special document. By utilizing Javascript embedded in a Word document to trigger a chain</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/12/metasploit-fence.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up</title>
		<link>https://noise.getoto.net/2021/12/03/metasploit-wrap-up-35/</link>
		
		<dc:creator><![CDATA[Spencer McIntyre]]></dc:creator>
		<pubDate>Fri, 03 Dec 2021 21:03:18 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=43565380fd80b3943178a543a65f9ade</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Metasploit CTF 2021 starts today</h2>
<p>It’s that time of year again! Time for the <a href="https://www.rapid7.com/blog/post/2021/11/16/announcing-the-2021-metasploit-community-ctf/">2021 Metasploit Community CTF</a>. Earlier today over 1,100 users in more than 530 teams were registered and opened for participation to solve this year’s 18 challenges. Next week a recap and the winners</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/12/metasploit-sky.png" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up</title>
		<link>https://noise.getoto.net/2021/11/26/metasploit-wrap-up-34/</link>
		
		<dc:creator><![CDATA[Christophe De La Fuente]]></dc:creator>
		<pubDate>Fri, 26 Nov 2021 17:21:03 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=db7ac7e9278aed114b1bba8dc96dd124</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Self-Service Remote Code Execution</h2>
<p>This week, our own <a href="https://github.com/wvu-r7">@wvu-r7</a> added an exploit <a href="https://github.com/rapid7/metasploit-framework/pull/15874">module</a> that achieves unauthenticated remote code execution in ManageEngine ADSelfService Plus, a self-service password management and single sign-on solution for Active Directory. This new module  leverages a REST API authentication bypass vulnerability identified as <a href="https://attackerkb.com/topics/DMSNq5zgcW/cve-2021-40539?referrer=blog">CVE-2021-40539</a>, where an error</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/11/metasploit-ascii-1-2.png" length="0" type="" />

			</item>
		<item>
		<title>Apple Sues NSO Group</title>
		<link>https://noise.getoto.net/2021/11/24/apple-sues-nso-group/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 24 Nov 2021 15:29:13 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[courts]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=64579</guid>

					<description><![CDATA[<p>Piling more on NSO Group’s legal troubles, Apple is <a href="https://www.apple.com/newsroom/2021/11/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware/">suing it</a>:</p>
<blockquote><p>The complaint provides new information on how NSO Group infected victims’ devices with its Pegasus spyware. To prevent further abuse and harm to its users, Apple is also seeking a permanent injunction to ban NSO Group from using any Apple software, services, or devices.</p></blockquote>
<p>NSO Group’s Pegasus spyware is favored by totalitarian governments around the world, who use it to hack Apple phones and computers.</p>
<p>More <a href="https://www.theverge.com/2021/11/23/22798917/apple-nso-group-spyware-pegasus-cybersecurity-research">news</a>:</p>
<blockquote><p>Apple’s legal complaint provides new information on NSO Group’s FORCEDENTRY, an exploit for a now-patched vulnerability previously used to break into a victim’s Apple device and install the latest version of NSO Group’s spyware product, Pegasus. The exploit was originally identified by the Citizen Lab, a research group at the University of Toronto. ...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Metasploit Wrap-Up</title>
		<link>https://noise.getoto.net/2021/11/19/metasploit-wrap-up-33/</link>
		
		<dc:creator><![CDATA[Erin Bleiweiss]]></dc:creator>
		<pubDate>Fri, 19 Nov 2021 19:51:17 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Metasploit Weekly Wrapup]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=6b7627c66695872037aec3e9ac981c49</guid>

					<description><![CDATA[<!--kg-card-begin: markdown--><h2>Azure Active Directory login scanner module</h2>
<p>Community contributor <a href="https://github.com/k0pak4">k0pak4</a> added a new <a href="https://github.com/rapid7/metasploit-framework/pull/15755">login scanner module for Azure Active Directory</a>. This module exploits a <a href="https://attackerkb.com/topics/rZ1JlQhXhc/cve-2020-16152?referrer=blog">vulnerable</a> authentication endpoint in order to enumerate usernames without generating log events. The error code returned by the endpoint can be used to discover the validity of</p>]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/11/metasploit-fence.png" length="0" type="" />

			</item>
		<item>
		<title>MacOS Zero-Day Used against Hong Kong Activists</title>
		<link>https://noise.getoto.net/2021/11/12/macos-zero-day-used-against-hong-kong-activists/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 12 Nov 2021 15:07:36 +0000</pubDate>
				<category><![CDATA[activism]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[zero day]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=63863</guid>

					<description><![CDATA[<p>Google researchers <a href="https://blog.google/threat-analysis-group/analyzing-watering-hole-campaign-using-macos-exploits/">discovered</a> a MacOS zero-day exploit being used against Hong Kong activists. It was a “watering hole” attack, which means the malware was hidden in a legitimate website. Users visiting that website would get infected.</p>
<p>From an <a href="https://www.vice.com/en/article/93bw8y/google-caught-hackers-using-a-mac-zero-day-against-hong-kong-users">article</a>:</p>
<blockquote><p>Google’s researchers were able to trigger the exploits and study them by visiting the websites compromised by the hackers. The sites served both iOS and MacOS exploit chains, but the researchers were only able to retrieve the MacOS one. The zero-day exploit was similar to another in-the-wild vulnerability analyzed by another Google researcher in the past, according to the report...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 40/334 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-09 19:08:49 by W3 Total Cache
-->