<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Labs &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/labs/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Mon, 24 Nov 2025 14:21:37 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>From Extortion to E-commerce: How Ransomware Groups Turn Breaches into Bidding Wars</title>
		<link>https://noise.getoto.net/2025/11/24/from-extortion-to-e-commerce-how-ransomware-groups-turn-breaches-into-bidding-wars/</link>
		
		<dc:creator><![CDATA[Alexandra Blia]]></dc:creator>
		<pubDate>Mon, 24 Nov 2025 14:21:37 +0000</pubDate>
				<category><![CDATA[dark web]]></category>
		<category><![CDATA[Labs]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=d6687a388a2c90a7ec4fd7e392d5b1ef</guid>

					<description><![CDATA[Ransomware has evolved from simple digital extortion into a structured, profit-driven criminal enterprise. Over time, it has led to the development of a complex ecosystem where stolen data is not only leveraged for ransom, but also sold to the highest ...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf3ae6fb8e07d88e0/67ee88468d0b99031be0ea84/resources-research.jpg" length="0" type="" />

			</item>
		<item>
		<title>Attackers accelerate, adapt, and automate: Rapid7’s Q3 2025 Threat Landscape Report</title>
		<link>https://noise.getoto.net/2025/11/12/attackers-accelerate-adapt-and-automate-rapid7s-q3-2025-threat-landscape-report/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Wed, 12 Nov 2025 13:55:11 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=888e09e8938ef6b76532dc25dfedde4e</guid>

					<description><![CDATA[The Q3 2025 Threat Landscape Report, authored by the Rapid7 Labs team, paints a clear picture of an environment where attackers are moving faster, working smarter, and using artificial intelligence to stay ahead of defenders. The findings reveal a thre...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf1878ef573c5427e/691491f1a62c1d1b126572f8/Threat-Landscape-Q3-2025-card.jpg" length="0" type="" />

			</item>
		<item>
		<title>When Your Calendar Becomes the Compromise</title>
		<link>https://noise.getoto.net/2025/11/06/when-your-calendar-becomes-the-compromise/</link>
		
		<dc:creator><![CDATA[Rapid7 Labs]]></dc:creator>
		<pubDate>Thu, 06 Nov 2025 18:42:23 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5489a553041dba16b71be2e6d90d3de5</guid>

					<description><![CDATA[A new meeting on your calendar or a new attack vector?It starts innocently enough. A new meeting appears in your Google calendar and the subject seems ordinary, perhaps even urgent: “Security Update Briefing,” “Your Account Verification Meeting,” or “I...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" length="0" type="" />

			</item>
		<item>
		<title>CVE-2025-48045, CVE-2025-48046, CVE-2025-48047: MICI NetFax Server Product Vulnerabilities (NOT FIXED)</title>
		<link>https://noise.getoto.net/2025/05/29/cve-2025-48045-cve-2025-48046-cve-2025-48047-mici-netfax-server-product-vulnerabilities-not-fixed/</link>
		
		<dc:creator><![CDATA[Anna Katarina Quinn]]></dc:creator>
		<pubDate>Thu, 29 May 2025 12:00:00 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Vulnerability Disclosure]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=b91052f6c07b6c559e40e7b7fb0fe94c</guid>

					<description><![CDATA[Over a penetration testing engagement, Rapid7 discovered 3 vulnerabilities in MICI Network Co., Ltd’s NetFax server allowing for an authenticated attack chain resulting in Remote Code Execution (RCE) against the device as the root user.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/vuln-disclosure-banner--1-.jpeg" length="0" type="" />

			</item>
		<item>
		<title>NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign</title>
		<link>https://noise.getoto.net/2025/05/22/nsis-abuse-and-srdi-shellcode-anatomy-of-the-winos-4-0-campaign/</link>
		
		<dc:creator><![CDATA[Anna Širokova]]></dc:creator>
		<pubDate>Thu, 22 May 2025 12:00:00 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e5222165da12733735fb6b8bc6d0ba29</guid>

					<description><![CDATA[Rapid7 has been tracking a malware campaign that uses fake software installers disguised as popular apps like VPN and QQBrowser—to deliver Winos v4.0, a hard-to-detect malware that runs entirely in memory and gives attackers remote access.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/05/GettyImages-1307354522.jpg" length="0" type="" />

			</item>
		<item>
		<title>From Noise to Action: Introducing Intelligence Hub</title>
		<link>https://noise.getoto.net/2025/04/23/from-noise-to-action-introducing-intelligence-hub/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Wed, 23 Apr 2025 13:00:00 +0000</pubDate>
				<category><![CDATA[Exposure Management]]></category>
		<category><![CDATA[Labs]]></category>
		<category><![CDATA[Threat Intel]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=549f7352fca7021f0aea752aa422e104</guid>

					<description><![CDATA[We are delighted to announce the availability of Intelligence Hub, an evolution in threat intelligence delivery that is designed to provide meaningful context and actionable insights integrated with the Rapid7 Command Platform.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/04/GettyImages-1473841682.jpg" length="0" type="" />

			</item>
		<item>
		<title>2025 Ransomware: Business as Usual, Business is Booming</title>
		<link>https://noise.getoto.net/2025/04/08/2025-ransomware-business-as-usual-business-is-booming/</link>
		
		<dc:creator><![CDATA[Chris Boyd]]></dc:creator>
		<pubDate>Tue, 08 Apr 2025 13:01:00 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=d5dc3b7bf56c9c9c16b4dca454c9724a</guid>

					<description><![CDATA[Rapid7 Labs took a look at internal and publicly-available ransomware data for Q1 2025 and added our own insights to provide a picture of the year thus far—and what you can do now to reduce your attack surface against ransomware.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/04/GettyImages-2198938705.jpg" length="0" type="" />

			</item>
		<item>
		<title>A Rebirth of a Cursed Existence? &#8211; The Babuk Locker 2.0</title>
		<link>https://noise.getoto.net/2025/04/02/a-rebirth-of-a-cursed-existence-the-babuk-locker-2-0/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Wed, 02 Apr 2025 13:00:00 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=3dea50383ab57b792742aaaf042c52e6</guid>

					<description><![CDATA[In early 2025, we came across a channel promoting itself as Babuk Locker. Since the original group had shut down in 2021, we decided to investigate whether this was a rebrand or a new threat.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/04/GettyImages-2169754654.jpg" length="0" type="" />

			</item>
		<item>
		<title>Fake BianLian Ransomware Letters in Circulation</title>
		<link>https://noise.getoto.net/2025/03/19/fake-bianlian-ransomware-letters-in-circulation/</link>
		
		<dc:creator><![CDATA[Chris Boyd]]></dc:creator>
		<pubDate>Wed, 19 Mar 2025 16:00:00 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=7f93d553c33395d1d7793db5ab6691f4</guid>

					<description><![CDATA[On March 5, the FBI issued an alert regarding a mail scam targeting U.S. business executives with extortion. The letters claim to be from noted ransomware group BianLian, demanding a payment in Bitcoin ranging from $250,000 to $500,000 within ten days of receipt.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/03/GettyImages-2180078018.jpg" length="0" type="" />

			</item>
		<item>
		<title>How To Protect Your Organization&#8217;s Bluesky Account From Security Threats</title>
		<link>https://noise.getoto.net/2025/02/11/how-to-protect-your-organizations-bluesky-account-from-security-threats/</link>
		
		<dc:creator><![CDATA[Chris Boyd]]></dc:creator>
		<pubDate>Tue, 11 Feb 2025 14:00:00 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e39d434a3c9b876d2e47edd56141fd5d</guid>

					<description><![CDATA[This blog explains how to secure your Bluesky account from security threats such as malware and phishing, as well as establishing your identity to help prevent fraud and impersonation.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/02/GettyImages-1524210326.jpg" length="0" type="" />

			</item>
		<item>
		<title>The 2024 Ransomware Landscape: Looking back on another painful year</title>
		<link>https://noise.getoto.net/2025/01/27/the-2024-ransomware-landscape-looking-back-on-another-painful-year/</link>
		
		<dc:creator><![CDATA[Christiaan Beek]]></dc:creator>
		<pubDate>Mon, 27 Jan 2025 14:00:00 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=4b41a54f89b34faa72d485c68f5ce3f2</guid>

					<description><![CDATA[In this post, we’ll examine the latest data points, discuss notable groups, and estimate the potential impact on victims — helping security teams plan their defenses for the months ahead.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/01/GettyImages-2040069487.jpg" length="0" type="" />

			</item>
		<item>
		<title>Perfect Fit or Business Threat? How to Mitigate the Risk of Rogue Employees</title>
		<link>https://noise.getoto.net/2025/01/16/perfect-fit-or-business-threat-how-to-mitigate-the-risk-of-rogue-employees/</link>
		
		<dc:creator><![CDATA[Chris Boyd]]></dc:creator>
		<pubDate>Thu, 16 Jan 2025 16:00:32 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=c2be41545b61afd28fd7e54357234f86</guid>

					<description><![CDATA[Recruitment fraud is an expensive and time-consuming threat to business. The risk of malware deployment and data exfiltration is high from threat actors trained to bypass each stage of a typical recruitment process. This blog outlines how an organization can secure the hiring process weak points.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2025/01/GettyImages-1434892101.jpg" length="0" type="" />

			</item>
		<item>
		<title>2024 Threat Landscape Statistics: Ransomware Activity, Vulnerability Exploits, and Attack Trends</title>
		<link>https://noise.getoto.net/2024/12/16/2024-threat-landscape-statistics-ransomware-activity-vulnerability-exploits-and-attack-trends/</link>
		
		<dc:creator><![CDATA[Rapid7 Labs]]></dc:creator>
		<pubDate>Mon, 16 Dec 2024 14:09:23 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=7049e8ee16a8f7ddb75ad82408c6aceb</guid>

					<description><![CDATA[In this blog, the global experts across our Rapid7 Labs and Managed Services teams share real-time vulnerability insights and threat intelligence so that our customers can anticipate and prevent breaches, pinpoint critical threats, and confidently take command of their attack surface.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/12/GettyImages-1828036562.jpg" length="0" type="" />

			</item>
		<item>
		<title>Ransomware Groups Demystified: CyberVolk Ransomware</title>
		<link>https://noise.getoto.net/2024/10/03/ransomware-groups-demystified-cybervolk-ransomware/</link>
		
		<dc:creator><![CDATA[Rapid7 Labs]]></dc:creator>
		<pubDate>Thu, 03 Oct 2024 17:00:00 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5ec67303d50b9044ff1fc5cafa12c315</guid>

					<description><![CDATA[As part of our ongoing efforts to monitor emerging cyber threats, we have analyzed the activities of CyberVolk, a politically motivated hacktivist group that transitioned into using ransomware and has been active since June 2024.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/10/GettyImages-1479650035.jpg" length="0" type="" />

			</item>
		<item>
		<title>Ransomware Groups Demystified: Lynx Ransomware</title>
		<link>https://noise.getoto.net/2024/09/12/ransomware-groups-demystified-lynx-ransomware/</link>
		
		<dc:creator><![CDATA[Rapid7 Labs]]></dc:creator>
		<pubDate>Thu, 12 Sep 2024 15:30:48 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=37b239d025ea97e7d24e6e451184127c</guid>

					<description><![CDATA[As part of our research and tracking of threats, Rapid7 Labs is actively monitoring new and upcoming threat groups and the ransomware domain is known for having a large number of them.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/09/GettyImages-1678710261.jpg" length="0" type="" />

			</item>
		<item>
		<title>Rapid7’s Ransomware Radar Report Shows Threat Actors are Evolving …Fast.</title>
		<link>https://noise.getoto.net/2024/08/06/rapid7s-ransomware-radar-report-shows-threat-actors-are-evolving-fast/</link>
		
		<dc:creator><![CDATA[Tom Caiazza]]></dc:creator>
		<pubDate>Tue, 06 Aug 2024 13:00:00 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[reports]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=79081bb23a271520b1da61a2ac986867</guid>

					<description><![CDATA[The Ransomware Radar Report offers some startling insights into who ransomware threat actors are and how they’ve been operating in the first half of 2024.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/08/GettyImages-1499410369.jpg" length="0" type="" />

			</item>
		<item>
		<title>Defending Against APTs: A Learning Exercise with Kimsuky</title>
		<link>https://noise.getoto.net/2024/07/16/defending-against-apts-a-learning-exercise-with-kimsuky/</link>
		
		<dc:creator><![CDATA[Raj Samani]]></dc:creator>
		<pubDate>Tue, 16 Jul 2024 20:00:00 +0000</pubDate>
				<category><![CDATA[Labs]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=4a6bb0bdb607b91bcead4a15a04c7812</guid>

					<description><![CDATA[The latest research paper coming out of Rapid7 Labs examines the tactics of North Korea’s Kimsuky threat group.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/07/GettyImages-1467921856.jpg" length="0" type="" />

			</item>
		<item>
		<title>What’s New in Rapid7 Products &#038; Services: Q2 2024 in Review</title>
		<link>https://noise.getoto.net/2024/07/11/whats-new-in-rapid7-products-services-q2-2024-in-review/</link>
		
		<dc:creator><![CDATA[Margaret Wei]]></dc:creator>
		<pubDate>Thu, 11 Jul 2024 13:00:00 +0000</pubDate>
				<category><![CDATA[InsightCloudSec]]></category>
		<category><![CDATA[InsightIDR]]></category>
		<category><![CDATA[InsightVM]]></category>
		<category><![CDATA[Labs]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=9c35a85355f036ca299bc119db829e40</guid>

					<description><![CDATA[In Q2, we focused on enhancing visualization, prioritization, and integration capabilities across our key products and services.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/07/GettyImages-1693759239.jpg" length="0" type="" />

			</item>
		<item>
		<title>State-Sponsored Threat Actors Target Security Researchers</title>
		<link>https://noise.getoto.net/2021/01/26/state-sponsored-threat-actors-target-security-researchers/</link>
		
		<dc:creator><![CDATA[boB Rudis]]></dc:creator>
		<pubDate>Tue, 26 Jan 2021 15:01:33 +0000</pubDate>
				<category><![CDATA[google]]></category>
		<category><![CDATA[Labs]]></category>
		<category><![CDATA[news]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=be902c7628d3f969596f8be1dd0207c1</guid>

					<description><![CDATA[On Monday, Google’s Threat Analysis Group published a blog on a widespread social engineering campaign that targeted security researchers working on vulnerability research and development.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/01/lock.jpg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 40/309 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-07 08:31:57 by W3 Total Cache
-->