GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 30/09/2026An adversary tried Citrix NetScaler CVE-2026-88771 against a GreyNoise Swarm participant sensor more than three days before public disclosure, and GreyNoise labeled it malicious within seconds, before any CVE-specific detection existed. New sources followed […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 29/09/2026A timeline of Citrix NetScaler CVE-2026-88771, from the CVE reservation on Sep 10 to public disclosure on Sep 27, including the exploitation attempts GreyNoise observed on Sep 24. 🔗 Full analysis: www.greynoise.io/blog/swarming-agai… 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 28/09/2026On September 24, GreyNoise observed zero-day exploitation attempts against Citrix NetScaler Gateway, now tracked as CVE-2026-88771. Existing GreyNoise detections flagged the source IP as malicious within seconds, three days before the vulnerability was […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 25/09/2026Andrew joined Detection Dispatch (Alex's Version) to talk Project Swarm, deception-based detection, why real attack data matters more than ever in the age of AI-driven threats, and more. Watch/listen to the episode Youtube […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 23/09/2026This week adversaries escalated attempts against flaws whose patches have been available for years. Adversaries escalated attempts against a known exploited Spring Cloud Function code execution flaw and an Elastic Kibana file inclusion flaw from single […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 23/09/2026Welcome to the team 💪 "With the addition of these new leaders to GreyNoise, we are deepening our commitment to protecting the national security missions of the United States and our allies." Read the full announcement […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 21/09/2026A single malicious cyber actor. One IP address. GreyNoise tracked a suspected Chinese-speaking actor across months of activity, from UniFi to WordPress to ZyXEL, including a novel CVE exploit hitting 996 switches across 48 countries. Here's what we saw […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 16/09/2026Two remote code execution flaws that CISA lists as known exploited turned up this week inside ordinary commodity crawling. Adversaries attempted CVE-2025-3248 and CVE-2026-0770 in Langflow, the AI application platform, at 3,968 and 4,770 connection attempts […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 11/09/2026If you missed it: 395 organizations compromised across 48 countries. Hundreds of AI agents. One campaign against PaperCut NG/MF. We mapped the attack flow below⬇️ Read Agents Gone Wild: www.greynoise.io/blog/ai-orchestrat… 001
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 10/09/2026The highest-volume malicious activity GreyNoise observed this week was a request for a file. Environment files, cloud configuration and repository configuration are all returned by a correctly functioning web server to anyone who asks for the right path […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 09/09/2026Hundreds of AI agents powered a campaign against PaperCut NG/MF. What did the operation reveal about agentic attacks and their limits? 🔗 Read GreyNoise’s latest blog: www.greynoise.io/blog/ai-orchestrat… #GreyNoise #threatIntel #CyberSecurity 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 02/09/2026This week exploitation attempts arrived in same-day cohorts across unrelated flaws. Adversaries escalated a Next.js authorization bypass, CVE-2025-29927, across the final three days of the period, from no more than three daily sources to 495 across a […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 01/09/2026Great Day 1 at Fal.Con 2026 ✅ Lots of good conversations on the floor and the GreyNoise socks are going fast. If you're here this week, come find us at Booth #1757. We'll show you how GreyNoise + CrowdStrike helps analysts stop chasing internet noise and […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 31/08/2026We're excited to announce an expanded integration between GreyNoise and the CrowdStrike Falcon® platform 🎉 The integration delivers three categories of new content: ➡️ A Falcon Next-Gen SIEM dashboard that visualizes successful inbound connections from […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 28/08/2026Threat actors are forging the crawler names of OpenAI, Anthropic, DeepSeek and five other AI companies to request .env files and keys. Full analysis: www.greynoise.io/blog/threat-actors… Six of those names came from 824 […] [Original post on infosec.exchange] 001
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 26/08/2026Most of the Log4Shell probing GreyNoise observed this week came from a single commercial scanning service. Roughly three fifths of the traffic carrying the Log4Shell exploitation tag came from one commercial vulnerability management service, so a […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 20/08/2026Back to Vegas we go! 🎲🎰 If you're headed to Fal.Con 2026, come find us at Booth #1757. We'll be showing how the GreyNoise + CrowdStrike integration helps analysts cut through internet noise and focus on threats that are actually targeting them. Book a […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 19/08/2026Four findings this period, one shared exposure pattern: each involves a surface an organization puts on the internet deliberately and then rarely inventories completely. In GreyNoise data this period, rented hosts swept separate contiguous bands of TCP […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 17/08/2026The new GreyNoise Visualizer just dropped 💥 We redesigned the GreyNoise Visualizer to match how defenders actually work. A new sidebar organized around Intelligence, Observation, and Automation. Search from anywhere, take action without leaving your workflow […] [Original post on infosec.exchange] 010
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 13/08/2026We’re thrilled to welcome our new SVP of Adversary Operations⚡ With deep experience spanning Google Threat Intelligence Group, Mandiant, and U.S. Marine Corps Forces Cyberspace Command, Andrew joins GreyNoise with a clear mission: build on our early […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 12/08/2026Four findings this period, one shared exposure pattern: each involves a system that holds credentials or files for a secondary environment, so a successful attempt against one would likely open the next without a second exploit. In GreyNoise data this […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 22/07/2026This week in GreyNoise data, rented crawlers probed for credentials and configuration secrets across widely deployed web software. A matched pair of crawlers sharing one client fingerprint probed NGINX UI (CVE-2026-27944) and LiteSpeed Cache […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 21/07/2026New in the GreyNoise Visualizer: the Intelligence Dashboard. Most mornings start the same way, rerunning the same CVE, tag, and country searches to see what moved overnight. The Intelligence Dashboard replaces that routine. Build one saved view of the […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 14/07/2026The June NoiseLetter is live! In this edition, we're diving into GreyNoise use cases, sharing the latest product releases, and getting ready for our biggest event of the year, NoiseFest. 🔗 www.greynoise.io/resources/noiselet… 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 13/07/2026The Threat Brief Library is now live in the GreyNoise Visualizer! Browse, search, filter, and download weekly At The Edge briefs, Executive Situation Reports, and more. All built on primary-source data from our global sensor network. Check it out: www.greynoise.io/blog/threat-brief-… 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 13/07/2026NoiseFest is just a few weeks away!🎉 If you're in Las Vegas for #BlackHat or #DEFCON, come join us for a night of cold drinks, good company, and 60s and 70s vibes. 🏵️ 📅Thursday, August 6th | 6–9 PM PT | Las Vegas 🔗RSVP […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 08/07/2026This week a long-dormant Palo Alto flaw came back to life in GreyNoise data. GlobalProtect CVE-2019-1579 (unauth RCE, CISA KEV) drew only isolated activity through late June, then more than 120 malicious hosts probed it on 06 July, almost all from a single […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 24/06/2026Four things that caught our eye at the edge this week: Following the FortiBleed reporting, GreyNoise is providing telemetry on the same Fortinet surfaces, without attributing the activity; the SSL VPN brute-force we track stood down in early June. Cisco SSL […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 18/06/2026Three things that caught our eye at the edge this week: - One host mapped the enterprise edge. - A pair ran a Hikvision camera RCE (CISA KEV) on shared tooling. - VPN logins stayed under steady pressure. Defend on behavior, not IPs. This week's At The Edge […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 16/06/2026We're in London tomorrow for @crowdstrike #CrowdTour2026. If you're attending our team would love to connect! Schedule some time to meet with us: info.greynoise.io/crowdtour-2026-me… #CyberSecurity #GreyNoise #ThreatIntel 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 12/06/2026GreyNoise At The Edge Intel Brief | June 1-8, 2026 This week's story: credential attacks on the front door of remote access, not new vulnerabilities. 🔗 www.greynoise.io/resources/at-the-e… 1. A single Netherlands host (94.102.49.82 […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 10/06/2026NoiseFest is BACK 🎉 We're throwing our 4th annual party during Black Hat / DEF CON 2026 with a 60s and 70s theme 🏵️🎸✌️. Cold drinks, new connections, and stories from the front lines of cybersecurity at House of Blues B-Side in Las Vegas. 🔗RSVP […] [Original post on infosec.exchange] 002
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 04/06/2026Less noise. Better signal. Faster response. We break down 4 ways GreyNoise helps SOC teams cut through internet background noise and focus on what actually matters: www.greynoise.io/blog/ways-greynois… 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 04/06/2026The May NoiseLetter is live! Early warning signals, blocklist gaps, and a SonicWall spike that echoes the pattern that preceded a CVE: www.greynoise.io/resources/noiselet… 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 29/05/2026GreyNoise At The Edge (May 19–26, 2026): a week of rented-infrastructure reconnaissance against the internet's edge — routers, VPN gateways, container planes, and embedded devices, probed in parallel. 1. A long-running MikroTik RouterOS brute-force […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 27/05/2026Got questions? We've got answers. Tune in tomorrow at 12 ET for GreyNoise University LIVE! 📺 www.greynoise.io/events/greynoise-u… 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 22/05/2026Your blocklist is probably missing 98% of what's actively hitting your edge right now. We tested 11 major feeds against 119,842 malicious IPs GreyNoise observed on a single day. The best feed covered less than 5%. Most were under 2%. The feeds aren't broken […] [Original post on infosec.exchange] 010
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 21/05/2026A scanning pattern similar to the one preceding CVE-2026-0400 in February is active again. May 12 saw the largest single-day session volume on this SonicWall tag in 90 days. 🔗 […] [Original post on infosec.exchange] 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 19/05/2026The mission: make sure no attack works twice. 🚀 We're hiring a Detection Engineer and a Federal Customer Success Manager to help us get there. Remote-friendly, high-impact, great benefits. Sound like you? 👇 www.greynoise.io/careers 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 04/05/2026May the 4th be with you + so be the signal. 🚀 The April Noiseletter is live: Project Swarm is open to the global security community, new research drops, and a packed events calendar. Let's get into it. 👇 www.greynoise.io/resources/noiselet…greynoise.ioNoiseLetter April 2026Get GreyNoise updates! Read the April 2026 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more. 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 30/04/2026GreyNoise University LIVE: www.greynoise.io/events/greynoise-u… The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse Webinar: info.greynoise.io/webinar/invisible… 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 29/04/2026We're so back, after taking last month off, we are refreshed + ready for April's GreyNoise University LIVE!! 📺 Tune in TOMORROW at 12 ET! www.greynoise.io/events/greynoise-u… 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 29/04/2026Introducing Project Swarm: a research initiative to defend the network edge and we're inviting you to join. Deploy a sensor on your infrastructure, capture real attacker traffic + compare what's hitting you to the GreyNoise global baseline. Join today! 🐝 100
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 28/04/2026Residential proxies, sleep cycles, and 4 BILLION sessions 👀 Join us Thursday, April 30th at 2pm ET to see why IP reputation is broken against home traffic + what actually works instead. Save your spot now 👇https://info.greynoise.io/webinar/invisible-armyinfo.greynoise.ioWebinar - The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy AbuseThis webinar presents the full findings of the latest report on residential proxy abuse — why IP reputation is structurally broken against this traffic, behavioral patterns consistent with compromised home PCs following the human sleep cycle, and what four separate threats hiding behind one label mean for detection strategy. 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 23/04/2026GreyNoise At The Edge — April 13–20, 2026. Four themes dominated activity on the GreyNoise sensor network this week — spanning reconnaissance, exploitation attempts, credential brute-forcing, and botnet recruitment. 1. A broad credential and configuration discovery campaign ran at ~6.2M […]infosec.exchangeOriginal post on infosec.exchange 001
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 23/04/202611 hosting ASNs appeared in pre-disclosure surges across 3+ vendor families. When targeting concentrates, lead time drops from 21 days to 7.5. The infrastructure behind these surges is recognizable. www.greynoise.io/resources/ten-days…greynoise.ioTen Days Before Zero: How Activity Surges in GreyNoise Data Precede Vulnerability DisclosureAttackers are moving before disclosures. GreyNoise shows how surge activity can signal vulnerabilities days before CVEs are published. 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 21/04/2026See you in Glasgow for #CyberUK! 🇬🇧 Find GreyNoise at Booth D2 + catch our talks: 🗓 Apr 22, 12:20 – Nishawn Smagh 🗓 Apr 23, 14:30 – Glenn Thorpe III Happy Hour @ Golf Fang on Apr 22 ⛳️ Book 1:1 time: info.greynoise.io/cyberuk-meet-with… #CyberSecurity #ThreatIntelligence #GreyNoiseinfo.greynoise.ioCyberUK| Meet With Us | GreyNoise IntelligenceGreyNoise is proud to be a sponsor and speaker at this years CyberUK conference. Here are all the different ways you can engage with GreyNoise during the event. 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 20/04/2026Atlanta!!! 🍑 We will be in town for the CrowdStrike #CrowdTour this week + we're kicking things off early with a Happy Hour TOMORROW! Come hang out with us from 4-6 at the Blue Moon Brewery & Grill. 🍻 info.greynoise.io/event/happy-hour-…info.greynoise.ioGreyNoise | Happy Hour AtlantaWe’re leaving the slide decks and sales pitches at the office in favor of cold beers and genuine conversation. Join us to unwind, talk shop (or not), and enjoy a relaxed evening with your Atlanta peers. 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 20/04/2026The internet changes before the advisory drops. New from GreyNoise: activity surges preceded 33 CVEs across 16 vendor families with a median 11-day lead. The pattern holds up to rigorous testing. www.greynoise.io/resources/ten-days…greynoise.ioTen Days Before Zero: How Activity Surges in GreyNoise Data Precede Vulnerability DisclosureAttackers are moving before disclosures. GreyNoise shows how surge activity can signal vulnerabilities days before CVEs are published. 000
GreyNoise @greynoise.infosec.exchange.ap.brid.gy · 17/04/202639% of IPs targeting the edge are residential. Geolocation catches 0% of them. We analyzed 4 billion sessions and the findings break A LOT of assumptions. Join us April 30 at 2 PM ET as we unpack what's really hiding in your traffic. 👉 info.greynoise.io/webinar/invisible…info.greynoise.ioWebinar - The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy AbuseThis webinar presents the full findings of the latest report on residential proxy abuse — why IP reputation is structurally broken against this traffic, behavioral patterns consistent with compromised home PCs following the human sleep cycle, and what four separate threats hiding behind one label mean for detection strategy. 000