<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>incident response &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/incident-response/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Fri, 21 Nov 2025 21:07:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Practical steps to minimize key exposure using AWS Security Services</title>
		<link>https://noise.getoto.net/2025/11/21/practical-steps-to-minimize-key-exposure-using-aws-security-services/</link>
		
		<dc:creator><![CDATA[Jennifer Paz]]></dc:creator>
		<pubDate>Fri, 21 Nov 2025 21:07:32 +0000</pubDate>
				<category><![CDATA[AWS IAM]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=760d7d36bff194f78d6ca70904be227b</guid>

					<description><![CDATA[Exposed long-term credentials continue to be the top entry point used by threat actors in security incidents observed by the AWS Customer Incident Response Team (CIRT). The exposure and subsequent use of long-term credentials or access keys by threat actors poses security risks in cloud environments. Additionally, poor key rotation practices, sharing of access keys […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Accelerate investigations with AWS Security Incident Response AI-powered capabilities</title>
		<link>https://noise.getoto.net/2025/11/21/accelerate-investigations-with-aws-security-incident-response-ai-powered-capabilities/</link>
		
		<dc:creator><![CDATA[Daniel Begimher]]></dc:creator>
		<pubDate>Fri, 21 Nov 2025 18:47:13 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Amazon GuardDuty]]></category>
		<category><![CDATA[announcements]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[AWS Incident Response]]></category>
		<category><![CDATA[AWS Security Hub]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=91ea14e6ffec9d3a1e5eeea51655e236</guid>

					<description><![CDATA[If you’ve ever spent hours manually digging through AWS CloudTrail logs, checking AWS Identity and Access Management (IAM) permissions, and piecing together the timeline of a security event, you understand the time investment required for incident investigation. Today, we’re excited to announce the addition of AI-powered investigation capabilities to AWS Security Incident Response that automate […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Introducing REACT: Why We Built an Elite Incident Response Team</title>
		<link>https://noise.getoto.net/2025/10/09/introducing-react-why-we-built-an-elite-incident-response-team/</link>
		
		<dc:creator><![CDATA[Chris O’Rourke]]></dc:creator>
		<pubDate>Thu, 09 Oct 2025 14:00:00 +0000</pubDate>
				<category><![CDATA[Cloudforce One]]></category>
		<category><![CDATA[Digital forensics]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=da4f5825d7ab164b180a59ce0b802b92</guid>

					<description><![CDATA[We're launching Cloudforce One REACT, a team of expert security responders designed to eliminate the gap between perimeter defense and internal incident response.]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Empowering Netflix Engineers with Incident Management</title>
		<link>https://noise.getoto.net/2025/09/19/empowering-netflix-engineers-with-incident-management/</link>
		
		<dc:creator><![CDATA[Netflix Technology Blog]]></dc:creator>
		<pubDate>Fri, 19 Sep 2025 16:48:00 +0000</pubDate>
				<category><![CDATA[incident response]]></category>
		<category><![CDATA[incident-management]]></category>
		<category><![CDATA[reliability]]></category>
		<category><![CDATA[site-reliability-engineer]]></category>
		<guid isPermaLink="false">https://medium.com/p/ebb967871de4</guid>

					<description><![CDATA[By: Molly StruveNetflix’s mission to provide seamless entertainment to hundreds of millions of users globally demands exceptional reliability. At the heart of this reliability is how we handle incidents — those inevitable moments when something doesn’t...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>AWS CIRT announces the launch of the Threat Technique Catalog for AWS</title>
		<link>https://noise.getoto.net/2025/06/13/aws-cirt-announces-the-launch-of-the-threat-technique-catalog-for-aws/</link>
		
		<dc:creator><![CDATA[Steve de Vera]]></dc:creator>
		<pubDate>Fri, 13 Jun 2025 15:22:16 +0000</pubDate>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[threat detection]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=8976d04515ed5378898cf8e01d16f273</guid>

					<description><![CDATA[Greetings from the AWS Customer Incident Response Team (AWS CIRT). AWS CIRT is a 24/7, specialized global Amazon Web Services (AWS) team that provides support to customers during active security events on the customer side of the AWS Shared Responsibility Model. We’re excited to announce the launch of the Threat Technique Catalog for AWS. When […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>BlackSuit Continues Social Engineering Attacks in Wake of Black Basta’s Internal Conflict</title>
		<link>https://noise.getoto.net/2025/06/10/blacksuit-continues-social-engineering-attacks-in-wake-of-black-bastas-internal-conflict/</link>
		
		<dc:creator><![CDATA[Tyler McGraw]]></dc:creator>
		<pubDate>Tue, 10 Jun 2025 15:00:00 +0000</pubDate>
				<category><![CDATA[incident response]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ac170da65e19d8d1d28672bb7059c326</guid>

					<description><![CDATA[Despite a significant decrease in social engineering attacks linked to the Black Basta ransomware group since late December 2024, Rapid7 has observed sustained social engineering attacks. Evidence suggests that BlackSuit affiliates have either adopted Black Basta’s strategy or absorbed its members.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/06/GettyImages-2169855131.jpg" length="0" type="" />

			</item>
		<item>
		<title>Rapid7 Q1 2025 Incident Response Findings</title>
		<link>https://noise.getoto.net/2025/06/04/rapid7-q1-2025-incident-response-findings/</link>
		
		<dc:creator><![CDATA[Chris Boyd]]></dc:creator>
		<pubDate>Wed, 04 Jun 2025 08:00:00 +0000</pubDate>
				<category><![CDATA[incident response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e94bd554bd5cb59160b5d8e75390ab41</guid>

					<description><![CDATA[Rapid7’s 2025Q1 incident response data highlights several key IAV trends, shares salient examples of incidents investigated by the Rapid7 IR team, and digs into threat data by industry as well as some of the more commonly seen pieces of malware.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/GettyImages-1422990988.jpg" length="0" type="" />

			</item>
		<item>
		<title>How to automate incident response for Amazon EKS on Amazon EC2</title>
		<link>https://noise.getoto.net/2025/05/20/how-to-automate-incident-response-for-amazon-eks-on-amazon-ec2/</link>
		
		<dc:creator><![CDATA[Jonathan Nguyen]]></dc:creator>
		<pubDate>Tue, 20 May 2025 16:53:57 +0000</pubDate>
				<category><![CDATA[Amazon Elastic Kubernetes Service]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[EKS]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Integration & Automation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=016c3777ec46c0267b0cdbf1b50e61a5</guid>

					<description><![CDATA[Triaging and quickly responding to security events is important to minimize impact within an AWS environment. Acting in a standardized manner is equally important when it comes to capturing forensic evidence and quarantining resources. By implementing automated solutions, you can respond to security events quickly and in a repeatable manner. Before implementing automated security solutions, […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Use an Amazon Bedrock powered chatbot with Amazon Security Lake to help investigate incidents</title>
		<link>https://noise.getoto.net/2025/05/01/use-an-amazon-bedrock-powered-chatbot-with-amazon-security-lake-to-help-investigate-incidents/</link>
		
		<dc:creator><![CDATA[Madhunika Reddy Mikkili]]></dc:creator>
		<pubDate>Thu, 01 May 2025 14:46:34 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Amazon Bedrock]]></category>
		<category><![CDATA[Amazon Security Lake]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[generative AI]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[SOC]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5f6a8c51a052a2e9aab12c3e46eb43b7</guid>

					<description><![CDATA[In part 2 of this series, we showed you how to use Amazon SageMaker Studio notebooks with natural language input to assist with threat hunting. This is done by using SageMaker Studio to automatically generate and run SQL queries on Amazon Athena with Amazon Bedrock and Amazon Security Lake. The Security Lake service team and […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>AWS empowers global security culture at Wicked6 Cyber Games</title>
		<link>https://noise.getoto.net/2025/04/22/aws-empowers-global-security-culture-at-wicked6-cyber-games/</link>
		
		<dc:creator><![CDATA[Anne Grahn]]></dc:creator>
		<pubDate>Tue, 22 Apr 2025 16:31:17 +0000</pubDate>
				<category><![CDATA[cloud security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Cybersecurity awareness]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Nonprofit]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Thought Leadership]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=d56f25f7527271af72d6935a3ac0618c</guid>

					<description><![CDATA[Wicked6 Cyber Games 2025 brought hundreds of women together worldwide from March 28–30. This dynamic virtual competition, sponsored by Amazon Web Services (AWS), helped attendees tackle real-world cybersecurity challenges through e-sports experiences. With 72 hours of women talking about cybersecurity, 11 cybersecurity games, and an attack and defense tournament streamed live, the weekend-long event highlighted […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Testing and evaluating GuardDuty detections</title>
		<link>https://noise.getoto.net/2025/01/28/testing-and-evaluating-guardduty-detections/</link>
		
		<dc:creator><![CDATA[Marshall Jones]]></dc:creator>
		<pubDate>Tue, 28 Jan 2025 19:47:55 +0000</pubDate>
				<category><![CDATA[Amazon GuardDuty]]></category>
		<category><![CDATA[announcements]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<category><![CDATA[threat detection]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=2e0baa5ccf3f7d2928e2a69a698ba1ae</guid>

					<description><![CDATA[Amazon GuardDuty is a threat detection service that continuously monitors, analyzes, and processes Amazon Web Services (AWS) data sources and logs in your AWS environment. GuardDuty uses threat intelligence feeds, such as lists of malicious IP addresses and domains, file hashes, and machine learning (ML) models to identify suspicious and potentially malicious activity in your […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Preventing unintended encryption of Amazon S3 objects</title>
		<link>https://noise.getoto.net/2025/01/16/preventing-unintended-encryption-of-amazon-s3-objects/</link>
		
		<dc:creator><![CDATA[Steve de Vera]]></dc:creator>
		<pubDate>Thu, 16 Jan 2025 02:43:53 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Best practices]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[S3]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[threat detection]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=2d784658c31e97cfa97ebad47244be67</guid>

					<description><![CDATA[At Amazon Web Services (AWS), the security of our customers’ data is our top priority, and it always will be. Recently, the AWS Customer Incident Response Team (CIRT) and our automated security monitoring systems identified an increase in unusual encryption activity associated with Amazon Simple Storage Service (Amazon S3) buckets. Working with customers, our security […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware</title>
		<link>https://noise.getoto.net/2024/12/04/black-basta-ransomware-campaign-drops-zbot-darkgate-and-custom-malware/</link>
		
		<dc:creator><![CDATA[Tyler McGraw]]></dc:creator>
		<pubDate>Wed, 04 Dec 2024 15:45:04 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=2c9775b70e57a2ce095a7c96e4b1f71e</guid>

					<description><![CDATA[Beginning in early October, Rapid7 has observed a resurgence of activity related to the ongoing social engineering campaign being conducted by Black Basta ransomware operators.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/12/GettyImages-2180078018.jpg" length="0" type="" />

			</item>
		<item>
		<title>Unauthorized tactic spotlight: Initial access through a third-party identity provider</title>
		<link>https://noise.getoto.net/2024/11/04/unauthorized-tactic-spotlight-initial-access-through-a-third-party-identity-provider/</link>
		
		<dc:creator><![CDATA[Steve de Vera]]></dc:creator>
		<pubDate>Mon, 04 Nov 2024 14:00:19 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[threat detection]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5f6d57140fa5db92a81af037422608c9</guid>

					<description><![CDATA[Security is a shared responsibility between Amazon Web Services (AWS) and you, the customer. As a customer, the services you choose, how you connect them, and how you run your solutions can impact your security posture. To help customers fulfill their responsibilities and find the right balance for their business, under the shared responsibility model, […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Investigating a SharePoint Compromise: IR Tales from the Field</title>
		<link>https://noise.getoto.net/2024/10/30/investigating-a-sharepoint-compromise-ir-tales-from-the-field/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Wed, 30 Oct 2024 20:19:14 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=afde110ab71146f8f6bf1be76ee329ed</guid>

					<description><![CDATA[Our investigation uncovered an attacker who accessed a server without authorization and moved laterally across the network, compromising the entire domain.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/10/GettyImages-1422990988.jpg" length="0" type="" />

			</item>
		<item>
		<title>How to deploy an Amazon OpenSearch cluster to ingest logs from Amazon Security Lake</title>
		<link>https://noise.getoto.net/2024/07/30/how-to-deploy-an-amazon-opensearch-cluster-to-ingest-logs-from-amazon-security-lake/</link>
		
		<dc:creator><![CDATA[Kevin Low]]></dc:creator>
		<pubDate>Tue, 30 Jul 2024 16:02:19 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Amazon Security Lake]]></category>
		<category><![CDATA[AWS security]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[Customer Solutions]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[OpenSearch]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<category><![CDATA[threat detection]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=d5afb7cfda214e38f69e660401d737ab</guid>

					<description><![CDATA[January 30, 2025: This post was republished to make the instructions clearer and compatible with OCSF 1.1. Customers often require multiple log sources across their AWS environment to empower their teams to respond and investigate security events. In part one of this two-part blog post, I show you how you can use Amazon OpenSearch Service […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Accelerate incident response with Amazon Security Lake – Part 2</title>
		<link>https://noise.getoto.net/2024/07/29/accelerate-incident-response-with-amazon-security-lake-part-2/</link>
		
		<dc:creator><![CDATA[Frank Phillis]]></dc:creator>
		<pubDate>Mon, 29 Jul 2024 16:12:02 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Amazon Security Lake]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3562a5dc63aa8c07cdbd7b832aba311a</guid>

					<description><![CDATA[This blog post is the second of a two-part series where we show you how to respond to a specific incident by using Amazon Security Lake as the primary data source to accelerate incident response workflow. The workflow is described in the Unintended Data Access in Amazon S3 incident response playbook, published in the AWS […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Malvertising Campaign Leads to Execution of Oyster Backdoor</title>
		<link>https://noise.getoto.net/2024/06/17/malvertising-campaign-leads-to-execution-of-oyster-backdoor/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Mon, 17 Jun 2024 20:28:23 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3e3cdb628acb9d36e96fee76a43274ec</guid>

					<description><![CDATA[Rapid7 has observed a recent malvertising campaign that lures users into downloading malicious installers for popular software such as Google Chrome and Microsoft Teams.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/06/Managed.jpg" length="0" type="" />

			</item>
		<item>
		<title>Accelerate incident response with Amazon Security Lake</title>
		<link>https://noise.getoto.net/2024/05/28/accelerate-incident-response-with-amazon-security-lake/</link>
		
		<dc:creator><![CDATA[Jerry Chen]]></dc:creator>
		<pubDate>Tue, 28 May 2024 15:54:05 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Amazon Security Lake]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e38af2c7f55d55b6318cc5dc973db892</guid>

					<description><![CDATA[This blog post is the first of a two-part series that will demonstrate the value of Amazon Security Lake and how you can use it and other resources to accelerate your incident response (IR) capabilities. Security Lake is a purpose-built data lake that centrally stores your security logs in a common, industry-standard format. In part […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators</title>
		<link>https://noise.getoto.net/2024/05/10/ongoing-social-engineering-campaign-linked-to-black-basta-ransomware-operators/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Fri, 10 May 2024 17:31:59 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Emergent Threat Response]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=681b197783c83554cc064ff84933474d</guid>

					<description><![CDATA[Rapid7 observes ongoing social engineering campaign consistent with Black Basta]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/05/GettyImages-1518854805.jpg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 56/397 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-08 02:31:51 by W3 Total Cache
-->