Sign in

Andrew Morris

@andrewmorr.is
1.3K followers 263 following 213 posts

🔳 founder of @greynoise.io. computers, networks, technology enthusiast. big goober.

PostsRepliesMedia
Andrew Morris @andrewmorr.is · 10/02/2026
posting my ass off on linkedin is sick but there's like mad gay dudes coming out woodwork. sick but, you know, dawg
010
Reposted by Andrew Morris
Robert Wilson @frcolumba.bsky.social · 06/02/2026
We had the good fortune of having @andrewmorr.is in the SOC for most of the day learning up the kids!
051
Andrew Morris @andrewmorr.is · 27/01/2026
I am absolutely POSTING on linkedin now btw. It's like bluesky but nobody is funny and I can write like five million characters per post.
2120
Andrew Morris @andrewmorr.is · 23/01/2026
React bug (CVE-2025-55182) just keeps buggin
040
Andrew Morris @andrewmorr.is · 20/01/2026
We're aware of the regrettably easy-to-exploit telnetd auth bypass and are preparing a tag for it in @greynoise.io
041
Andrew Morris @andrewmorr.is · 18/01/2026
wiring my house up with fiber and I'm insanely humbled by my complete lack of even the most basic concepts. LC??? OM3???? multi mode???
2100
Andrew Morris @andrewmorr.is · 18/01/2026
asked claude to fix a VM that doesn't have internet or network access and its screenshotting and reading the terminal and using qm sendkeys to the proxmox host via SSH to fix it. that goes kinda hard.
120
Andrew Morris @andrewmorr.is · 18/01/2026
waking up at 4am and hitting Bitchat #dj (all of america) with a "gm" text. three users active. no response.
120
Andrew Morris @andrewmorr.is · 18/01/2026
gm. open face sausage egg and cheese sandwich on brioche
250
Andrew Morris @andrewmorr.is · 08/01/2026
All internet traffic from Iran ceased in @greynoise.io one hour ago. Tier 1 dropped off two hours ago.
0148
Andrew Morris @andrewmorr.is · 28/12/2025
am I gonna get in trouble for shoplifting spotify
020
Andrew Morris @andrewmorr.is · 22/12/2025
unbelieveable
010
Andrew Morris @andrewmorr.is · 16/12/2025
www.labs.greynoise.io/grimoire/202...
labs.greynoise.io
React2Shell Side Quest: Tracking Down Malicious MeshCentral Nodes – GreyNoise Labs
While spelunking through React2Shell initial access payloads, MeshCentral entered the building, so we decided to see just how Mesh-y GreyNoise Data Is
020
Andrew Morris @andrewmorr.is · 13/12/2025
between the ~1,400 networks we've seen exploiting React2Shell (CVE-2025-55182) we've captured about 100 different distinct malware payloads. Lots of vibe coded slop, coin miners, chinese comments, mirai variants, etc. hit us up if you're tracking this and want deets research@greynoise.io
020
Andrew Morris @andrewmorr.is · 10/12/2025
TL;DR a couple hundred IPs suddenly started exploiting Cisco devices today - Entire exploitation cluster is originating from OVH (@ovhcloudus.bsky.social). - Payloads are interesting- attacker is even checking hardware temperatures most likely to ensure they are not honeypots
1185
Andrew Morris @andrewmorr.is · 10/12/2025
Also please be aware if your org runs a lot of Cisco gear we're seeing a very large spike in exploitation against Cisco devices right now.
0102
Andrew Morris @andrewmorr.is · 09/12/2025
Lots of React4Shell in @greynoise.io. Visualization a la @hrbrmstr.dev
163
Andrew Morris @andrewmorr.is · 08/12/2025
my step brother calls gemini "jimmy"
000
Andrew Morris @andrewmorr.is · 08/12/2025
The @hrbrmstr.dev himself has an entire web page of these stats he's keeping up to date if you want to keep an eye on them btw: rud.is/r2s/r2s.html
rud.is
r2s
040
Andrew Morris @andrewmorr.is · 07/12/2025
React2Shell exploitation frequency in GreyNoise dec 5-dec 6
12611
Andrew Morris @andrewmorr.is · 06/12/2025
Remember folks- it's only a crypto miner until it isn't
050
Andrew Morris @andrewmorr.is · 05/12/2025
React Server CVE-2025-55182 popping off in @greynoise.io right now. Blog from @hrbrmstr.dev up: www.greynoise.io/blog/cve-202...
341
Andrew Morris @andrewmorr.is · 02/12/2025
one thing about me is that I love windows. the building fixture. not the operating system.
120
Andrew Morris @andrewmorr.is · 29/11/2025
Shamlessly reposting from elsewhere- you can easily communicate between Linux VMs and guests using VSOCK (man7.org/linux/man-pa...). Here's some silly examples of bidirectional chat btwn host & guest using Socat. Or connecting via SSH to my home router from the VM without TCP/IP. No code required.
1133
Andrew Morris @andrewmorr.is · 21/11/2025
on the surface this appears to be a massive credential stuffing campaign against Palo Alto's. please audit your successful logins and enable MFA. good catch @remyhax.bsky.social www.greynoise.io/blog/palo-al...
greynoise.io
Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High
GreyNoise has identified a significant escalation in malicious activity targeting Palo Alto Networks GlobalProtect portals. Beginning on 14 November 2025, activity rapidly intensified, culminating in ...
050
Andrew Morris @andrewmorr.is · 20/11/2025
People always make fun of me for being polite to LLMs and I like to joke that I want to be on the good side of the robots when they take over the world. But really it just feels like a nasty habit to reinforce being an asshole on the computer. Unless we're playing Modern Warfare and you're 12.
0101
Andrew Morris @andrewmorr.is · 20/11/2025
POV you're my new 42U server rack in the garage and I just turned the lights off and saw your lights blinking in the dark for the first time
170
Andrew Morris @andrewmorr.is · 19/11/2025
did you know you can quickly figure out if an ethernet port/cable supports PoE by putting it on your lips and feeling whether it electrocutes you or not
120
Andrew Morris @andrewmorr.is · 18/11/2025
We've hired Colonel Shawn Smagh to up our @greynoise.io intel reporting game and we've started producing weekly intelligence briefs. This week's is a banger.
082
Reposted by Andrew Morris
GreyNoise @greynoise.io · 31/10/2025
Happy Halloween from your fave GreyNerds 🍬🍫
4124
Andrew Morris @andrewmorr.is · 31/10/2025
Annual candy bracket is done. I'm gonna need some time to reflect.
160
Andrew Morris @andrewmorr.is · 31/10/2025
ned flanders
2220
Andrew Morris @andrewmorr.is · 31/10/2025
we did a pew pew map btw threat-map.greynoise.io
152
Andrew Morris @andrewmorr.is · 27/10/2025
I've just received word that we're preparing for this years annual @greynoise.io halloween candy bracket. Twix won years 1-2. 100 Grand won last year on a complete fluke. I might write a blog post about how last year's candy bracket undermined my faith in the democratic process.
180
Andrew Morris @andrewmorr.is · 23/10/2025
excuse me for talking to you like a human ass being
010
Andrew Morris @andrewmorr.is · 23/10/2025
when it comes to a head it will have been obvious in hindsight
071
Andrew Morris @andrewmorr.is · 23/10/2025
big week in the morris household. we've started tracking ORBs at @greynoise.io and I'm shitposting again btw (h/t @hrbrmstr.dev)
2131
Andrew Morris @andrewmorr.is · 23/10/2025
DuckDB GraphQL btw duckdb.org/2025/10/22/d...
290
Andrew Morris @andrewmorr.is · 22/10/2025
Played Broken Arrow last night on Steam and its sick
010
Andrew Morris @andrewmorr.is · 06/09/2025
full moon AND full lunar eclipse tomorrow btw
160
Andrew Morris @andrewmorr.is · 31/08/2025
doing some ground floor reporting (celebrating my uncles 80th birthday)
080
Andrew Morris @andrewmorr.is · 27/08/2025
just accidentally spilled some water on my shorts which dried instantly. This is how I realized I've been wearing a swimsuit as shorts.
240
Andrew Morris @andrewmorr.is · 21/08/2025
psychic.labs.greynoise.io - Offline, in-memory bitmaps of GreyNoise data. Available now.
081
Andrew Morris @andrewmorr.is · 29/05/2025
Super proud of the folks at @thinkstcanary.canary.tools. They continue to inspire me every day. techcrunch.com/2025/05/29/a...
techcrunch.com
A decade in, bootstrapped Thinkst Canary reaches $20M in ARR without VC funding | TechCrunch
Reflecting on 10 years since its launch, the honeypot maker explains why the company did not take on any VC funding.
0250
Andrew Morris @andrewmorr.is · 28/05/2025
www.labs.greynoise.io/grimoire/202...
labs.greynoise.io
AyySSHush: Tradecraft of an emergent ASUS botnet – GreyNoise Labs
Using an AI powered network traffic analysis tool we built called SIFT, GreyNoise has caught multiple anomalous network payloads with zero-effort that are attempting to disable TrendMicro security fea...
173
Andrew Morris @andrewmorr.is · 13/05/2025
011
Andrew Morris @andrewmorr.is · 11/05/2025
anyways I'm putting real ass routers on the GreyNoise grid now and they're getting popped. shoved this one in my apartment onto a sensor in Russia.
0120
Andrew Morris @andrewmorr.is · 10/05/2025
hxxps[:]//youtu[.]be/6skuCiLCjRA?si=JIbO4aZP0MlW6G04
000
Andrew Morris @andrewmorr.is · 09/05/2025
210
Andrew Morris @andrewmorr.is · 06/05/2025
I'm doing a little bit of research on model context protocol (MCP) servers. I ripped back a few thousand repos from github and am doing some automated analysis on their codebases. Here's the language stats on ~2,100 MCP repos. More to come.
240