Sign in

GreyNoise

@greynoise.io
4.1K followers 25 following 475 posts

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats.

PostsRepliesMedia
GreyNoise @greynoise.io · 8h
At The Edge Clear: September 21 – 28, 2026 An adversary tried Citrix NetScaler CVE-2026-88771 against a GreyNoise Swarm participant sensor more than three days before public disclosure. 🔗 www.greynoise.io/resources/at...
031
GreyNoise @greynoise.io · 29/09/2026
A timeline of Citrix NetScaler CVE-2026-88771, from the CVE reservation on Sep 10 to public disclosure on Sep 27, including the exploitation attempts GreyNoise observed on Sep 24. 🔗 Full analysis: www.greynoise.io/blog/swarmin...
094
GreyNoise @greynoise.io · 28/09/2026
On September 24, GreyNoise observed zero-day exploitation attempts against Citrix NetScaler Gateway, now tracked as CVE-2026-88771. Existing GreyNoise detections flagged the source IP as malicious within seconds, three days before the vulnerability was publicly disclosed.
greynoise.io
Swarming Against Citrix 0-Day Exploitation
On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the ...
020
GreyNoise @greynoise.io · 25/09/2026
Andrew joined Detection Dispatch (Alex's Version) to talk Project Swarm, deception-based detection, why real attack data matters more than ever in the age of AI-driven threats, and more. Watch the episode on Youtube ⬇️
youtube.com
The Golden Era of Deception feat. Andrew Morris
YouTube video by Detection Dispatch (Alex's Version)
010
GreyNoise @greynoise.io · 23/09/2026
At The Edge Clear: September 14 – 21, 2026 This week adversaries escalated attempts against flaws whose patches have been available for years. Customers get the full weekly brief. Our public At The Edge one-pager is attached + 🔗 www.greynoise.io/resources/at...
022
GreyNoise @greynoise.io · 23/09/2026
Welcome to the team 💪 "With the addition of these new leaders to GreyNoise, we are deepening our commitment to protecting the national security missions of the United States and our allies." Read the full announcement: www.greynoise.io/press/greyno...
010
GreyNoise @greynoise.io · 21/09/2026
A single malicious cyber actor. One IP address. GreyNoise tracked a suspected Chinese-speaking actor across months of activity, from UniFi to WordPress to ZyXEL, including a novel CVE exploit hitting 996 switches across 48 countries. Here's what we saw ⬇️
greynoise.io
Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We detail a few of the more notable int...
082
GreyNoise @greynoise.io · 16/09/2026
At The Edge Clear: September 8 – 14, 2026 Two CISA known-exploited remote code execution flaws in the AI application platform Langflow turned up this week inside ordinary commodity crawling. Customers get the full weekly brief. Our public At The Edge one-pager: www.greynoise.io/resources/at...
011
GreyNoise @greynoise.io · 11/09/2026
If you missed it: 395 organizations compromised across 48 countries. Hundreds of AI agents. One campaign against PaperCut NG/MF. We mapped the attack flow below⬇️ Read Agents Gone Wild: www.greynoise.io/blog/ai-orch...
032
GreyNoise @greynoise.io · 10/09/2026
The highest-volume malicious activity GreyNoise observed this week was a request for a file. Environment files, cloud configuration and repository configuration are all returned by a correctly functioning web server to anyone who asks for the right path. www.greynoise.io/resources/at...
000
GreyNoise @greynoise.io · 09/09/2026
Hundreds of AI agents powered a campaign against PaperCut NG/MF. What did the operation reveal about agentic attacks and their limits? Read GreyNoise’s latest blog ⬇️
greynoise.io
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
11 organizations compromised in 26 seconds. GreyNoise breaks down the AI-enabled campaign against PaperCut NG/MF that hit 440 instances across 48 countries.
000
GreyNoise @greynoise.io · 02/09/2026
This week exploitation attempts arrived in same-day cohorts across unrelated flaws. Customers get the full weekly brief. Our public At The Edge one-pager is attached + 🔗 www.greynoise.io/resources/at...
030
GreyNoise @greynoise.io · 01/09/2026
GreyNoise turns 9️⃣ today! 🥳 We've been busy this past month, and to mark the occasion, we've got a packed NoiseLetter. Thank you all for being a part of the GreyNoise Community and here's to nine years of cutting through the noise, together.
greynoise.io
NoiseLetter August 2026
In the latest edition of the NoiseLetter we've got new integrations, product updates, and fresh content to dig into.
010
GreyNoise @greynoise.io · 01/09/2026
Great Day 1 at Fal.Con 2026 ✅ Lots of good conversations on the floor. If you're here this week, come find us at Booth #1757.
000
GreyNoise @greynoise.io · 31/08/2026
We're excited to announce an expanded integration between GreyNoise and the CrowdStrike Falcon® platform 🎉 The expanded integration includes a purpose-built Falcon Next-Gen SIEM dashboard, correlation rules, and SOAR playbooks.
greynoise.io
GreyNoise + CrowdStrike: Real-Time Edge Intelligence in Falcon Next-Gen SIEM and Charlotte Agentic SOAR
Today we’re announcing an expanded integration between GreyNoise and the CrowdStrike Falcon® platform including a purpose-built Falcon Next-Gen SIEM dashboard, correlation rules that detect allowed in...
010
GreyNoise @greynoise.io · 28/08/2026
Threat actors are forging the crawler names of OpenAI, Anthropic, DeepSeek and five other AI companies to request .env files and keys. Six of those names came from 824 addresses in matched volume. None asked for robots.txt in this traffic. Full analysis ⬇️
greynoise.io
Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets
GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies, using forged user agents while requesting the files where misconfigured ...
122
GreyNoise @greynoise.io · 26/08/2026
Most of the Log4Shell probing GreyNoise observed this week came from a single commercial scanning service. Our public At The Edge one-pager is attached. Customers get the full weekly brief. 🔗 www.greynoise.io/resources/at...
021
GreyNoise @greynoise.io · 20/08/2026
Back to Vegas we go! 🎲🎰 If you're headed to Fal.Con 2026, come find us at Booth #1757. We'll be showing how the GreyNoise + CrowdStrike integration helps analysts cut through internet noise and focus on threats that are actually targeting them. Book a meeting: info.greynoise.io/greynoise-fa...
info.greynoise.io
GreyNoise at Fal.Con 2026
Engage with GreyNoise at Fal.Con. Stop by our booth #1757, meet with us, or attend our event.
000
GreyNoise @greynoise.io · 19/08/2026
Four findings this period, one shared exposure pattern: each involves a surface an organization puts on the internet deliberately and then rarely inventories completely. 🔗https://www.greynoise.io/resources/at-the-edge-clear-081726
121
GreyNoise @greynoise.io · 17/08/2026
The new GreyNoise Visualizer just dropped 💥 We redesigned the GreyNoise Visualizer to match how defenders actually work. Log in and hit "Try the New Visualizer" to explore it today. 🔗https://www.greynoise.io/blog/new-way-to-navigate-greynoise
151
GreyNoise @greynoise.io · 14/08/2026
NoiseFest 2026 is a wrap. What a ride 🚎 🏵️✌️ Thank you to everyone who came out last week and made it such an incredible night. And a huge thank you to our wonderful sponsors: Sublime Security, Mallory, StepSecurity, and ProjectDiscovery. See you next year for NoiseFest 2027.....
020
GreyNoise @greynoise.io · 13/08/2026
We’re thrilled to welcome @imposecost.bsky.social to GreyNoise as our new SVP of Adversary Operations⚡
greynoise.io
GreyNoise Welcomes New SVP of Adversary Operations
Former Google Threat Intelligence leader joins GreyNoise as SVP of Adversary Operations to advance proactive discovery and disruption of cyber threats.
020
GreyNoise @greynoise.io · 12/08/2026
Four findings this period, one shared exposure pattern: each involves a system that holds credentials or files for a secondary environment, so a successful attempt against one would likely open the next without a second exploit. 🔗https://www.greynoise.io/resources/at-the-edge-clear-081026
000
GreyNoise @greynoise.io · 22/07/2026
This week in GreyNoise data, rented crawlers probed for credentials and configuration secrets across widely deployed web software. Customers get the full weekly brief. Our public At The Edge Clear one-pager: www.greynoise.io/resources/at...
010
GreyNoise @greynoise.io · 21/07/2026
New in the GreyNoise Visualizer: the Intelligence Dashboard. Build one saved view of the threats you actually track, then watch it stay current on its own. Read the launch blog: greynoise.io/blog/intelli...
010
GreyNoise @greynoise.io · 14/07/2026
The June NoiseLetter is live! In this edition, we're diving into GreyNoise use cases, sharing the latest product releases, and getting ready for our biggest event of the year, NoiseFest.
greynoise.io
NoiseLetter June 2026
In this edition, we're diving into GreyNoise use cases, sharing the latest product releases, and getting ready for our biggest event of the year, NoiseFest.
010
GreyNoise @greynoise.io · 13/07/2026
The Threat Brief Library is now live in the GreyNoise Visualizer! Browse, search, filter, and download weekly At The Edge briefs, Executive Situation Reports, and more. All built on primary-source data from our global sensor network. Check it out: www.greynoise.io/blog/threat-...
010
GreyNoise @greynoise.io · 13/07/2026
NoiseFest is just a few weeks away!🎉 If you're in Las Vegas for #BlackHat or #DEFCON, come join us for a night of cold drinks, good company, and 60s and 70s vibes. 🏵️ 📅Thursday, August 6th | 6–9 PM PT | Las Vegas 🔗RSVP: info.greynoise.io/events/black... #NoiseFest #GreyNoise #cybersecurity
info.greynoise.io
GreyNoise - NoiseFest at BlackHat 2026
Join us for NoiseFest at BlackHat/DEFCON on Thursday, August 6th. Enjoy drinks, snacks, and engaging conversations with your peers. RSVP now!
011
GreyNoise @greynoise.io · 08/07/2026
This week a long-dormant Palo Alto flaw came back to life in GreyNoise data. Separately, two coordinated hosting fleets ran the week's highest-volume web exploitation, roughly 7.5M connection attempts. 🔗https://www.greynoise.io/resources/at-the-edge-clear-070626
020
GreyNoise @greynoise.io · 24/06/2026
Four things that caught our eye at the edge this week: www.greynoise.io/resources/at...
020
GreyNoise @greynoise.io · 18/06/2026
Three things that caught our eye at the edge this week: - One host mapped the enterprise edge. - A pair ran a Hikvision camera RCE (CISA KEV) on shared tooling. - VPN logins stayed under steady pressure. This week's At The Edge Clear 👉 www.greynoise.io/resources/at...
000
GreyNoise @greynoise.io · 16/06/2026
We're in London tomorrow for CrowdStrike #CrowdTour2026. If you're attending our team would love to connect! Schedule some time to meet with us: info.greynoise.io/crowdtour-20... #CyberSecurity #GreyNoise #ThreatIntel
010
GreyNoise @greynoise.io · 12/06/2026
GreyNoise At The Edge Intel Brief (June 1-8, 2026) This week attackers went after the front door of remote access — RDP, SSL VPN, router management — not new CVEs. 🔗 www.greynoise.io/resources/at...
010
GreyNoise @greynoise.io · 10/06/2026
NoiseFest is BACK 🎉 We're throwing our 4th annual party during Black Hat / DEF CON 2026 with a 60s and 70s theme 🏵️🎸✌️. Cold drinks, new connections, and stories from the front lines of cybersecurity at House of Blues B-Side in Las Vegas. #BlackHat #DEFCON #NoiseFest #GreyNoise #cybersecurity
info.greynoise.io
GreyNoise - NoiseFest at BlackHat 2025
Join us for NoiseFest at BlackHat/DEFCON on Thursday, August 6th. Enjoy drinks, snacks, and engaging conversations with your peers. RSVP now!
032
GreyNoise @greynoise.io · 04/06/2026
Less noise. Better signal. Faster response. New blog breaks down 4 ways GreyNoise helps SOC teams cut through internet background noise and focus on what actually matters: www.greynoise.io/blog/ways-gr... #CyberSecurity #ThreatIntel #SOC #GreyNoise
greynoise.io
4 Ways GreyNoise Improves SOC Outcomes
Learn four practical ways GreyNoise improves SOC outcomes—from reducing alert volume and surfacing targeted threats to identifying compromised hosts.
010
GreyNoise @greynoise.io · 04/06/2026
The May NoiseLetter is live! Early warning signals, blocklist gaps, and a SonicWall spike that echoes the pattern that preceded a CVE: www.greynoise.io/resources/no...
greynoise.io
NoiseLetter May 2026
Get GreyNoise updates! Read the May 2026 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.
021
GreyNoise @greynoise.io · 29/05/2026
The week's signal: a long-running MikroTik RouterOS brute-force operation (VPSVAULT, AS215925) reversed a multi-week decline — adding a second node and climbing back to ~1.9M sessions against the management API. Rented infrastructure, inventorying the edge. 🔗 www.greynoise.io/resources/at...
010
GreyNoise @greynoise.io · 27/05/2026
We're in Toronto for CrowdStrike #CrowdTour2026 tomorrow, May 28th! Attending the event or local to the area? We'd love to connect. Book time with our team: info.greynoise.io/crowdtour-20...
000
GreyNoise @greynoise.io · 27/05/2026
Got questions? We've got answers. Tune in tomorrow at 12 ET for GreyNoise University LIVE! 📺
greynoise.io
GreyNoise University LIVE
000
GreyNoise @greynoise.io · 22/05/2026
We measured 11 major IP blocklists against 119,842 malicious IPs we observed on one day. The best feed covered less than 5%. Most were under 2%. Your blocklist isn't broken. It was built for a slower threat landscape. Full breakdown ⬇️
greynoise.io
The Coverage Gap: Why Your Blocklist Is Missing 119,000 Malicious IPs Today
GreyNoise compared 119,842 malicious IPs against 11 major threat feeds. The average coverage: just 2%, exposing the limits of static blocklists.
030
GreyNoise @greynoise.io · 21/05/2026
A scanning pattern similar to the one preceding CVE-2026-0400 in February is active again. May 12 saw the largest single-day session volume on this SonicWall tag in 90 days. #GreyNoise #ThreatIntel #SonicWall
greynoise.io
A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400
A new SonicWall scanning surge mirrors the pattern that preceded CVE-2026-0400. GreyNoise details the activity and what defenders should watch.
032
Reposted by GreyNoise
Feedly @feedly.com · 19/05/2026
GreyNoise enrichment is now built into #IOC Insight Cards so you get behavioral signals, classification data, and validated #OSINT from 10,000+ #CTI sources, in one place. feedly.com/new-features...
011
GreyNoise @greynoise.io · 19/05/2026
The mission: make sure no attack works twice. 🚀 We're hiring a Detection Engineer and a Federal Customer Success Manager to help us get there. Remote-friendly, high-impact, great benefits. Sound like you? 👇 www.greynoise.io/careers
001
GreyNoise @greynoise.io · 04/05/2026
May the 4th be with you + so be the signal. 🚀 The April Noiseletter is live: Project Swarm is open to the global security community, new research drops, and a packed events calendar. Let's get into it. 👇
greynoise.io
NoiseLetter April 2026
Get GreyNoise updates! Read the April 2026 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.
010
GreyNoise @greynoise.io · 30/04/2026
Today's the perfect day for a matinee double feature: GreyNoise University LIVE: www.greynoise.io/events/greyn... The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse Webinar: info.greynoise.io/webinar/invi...
000
GreyNoise @greynoise.io · 29/04/2026
We're so back, after taking last month off, we are refreshed + ready for April's GreyNoise University LIVE!! 📺 Tune in TOMORROW at 12 ET! www.greynoise.io/events/greyn...
greynoise.io
GreyNoise University LIVE
000
GreyNoise @greynoise.io · 29/04/2026
Introducing Project Swarm: a research initiative to defend the network edge and we're inviting you to join. Deploy a sensor on your infrastructure, capture real attacker traffic + compare what's hitting you to the GreyNoise global baseline. Join today! 🐝
120
GreyNoise @greynoise.io · 28/04/2026
Residential proxies, sleep cycles, and 4 BILLION sessions 👀 Join us Thursday, April 30th at 2pm ET to see why IP reputation is broken against home traffic + what actually works instead. Save your spot now 👇
info.greynoise.io
Webinar - The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse
This webinar presents the full findings of the latest report on residential proxy abuse — why IP reputation is structurally broken against this traffic, behavioral patterns consistent with compromised...
010
GreyNoise @greynoise.io · 23/04/2026
GN At The Edge: 4 themes dominated activity on our sensor network: recon, exploitation, brute-force, + botnet recruitment. Top story: a broad credential and configuration discovery campaign with ~6.2M sessions across hundreds of IPs hunting exposed .env, .git, AWS metadata, + path traversal.
greynoise.io
At The Edge Clear: April 13 - 20, 2026
This week's report covers credential discovery, VNC exposure, and a new multi-cloud scanning framework.
010
GreyNoise @greynoise.io · 23/04/2026
11 hosting ASNs appeared in pre-disclosure surges across 3+ vendor families. When targeting concentrates, lead time drops from 21 days to 7.5. The infrastructure behind these surges is recognizable.
greynoise.io
Ten Days Before Zero: How Activity Surges in GreyNoise Data Precede Vulnerability Disclosure
Attackers are moving before disclosures. GreyNoise shows how surge activity can signal vulnerabilities days before CVEs are published.
010