Sign in

GreyNoise

@greynoise.io
4.1K followers 25 following 475 posts

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats.

PostsRepliesMedia
GreyNoise @greynoise.io · 9h
At The Edge Clear: September 21 – 28, 2026 An adversary tried Citrix NetScaler CVE-2026-88771 against a GreyNoise Swarm participant sensor more than three days before public disclosure. 🔗 www.greynoise.io/resources/at...
031
GreyNoise @greynoise.io · 29/09/2026
A timeline of Citrix NetScaler CVE-2026-88771, from the CVE reservation on Sep 10 to public disclosure on Sep 27, including the exploitation attempts GreyNoise observed on Sep 24. 🔗 Full analysis: www.greynoise.io/blog/swarmin...
094
GreyNoise @greynoise.io · 23/09/2026
At The Edge Clear: September 14 – 21, 2026 This week adversaries escalated attempts against flaws whose patches have been available for years. Customers get the full weekly brief. Our public At The Edge one-pager is attached + 🔗 www.greynoise.io/resources/at...
022
GreyNoise @greynoise.io · 23/09/2026
Welcome to the team 💪 "With the addition of these new leaders to GreyNoise, we are deepening our commitment to protecting the national security missions of the United States and our allies." Read the full announcement: www.greynoise.io/press/greyno...
010
GreyNoise @greynoise.io · 16/09/2026
At The Edge Clear: September 8 – 14, 2026 Two CISA known-exploited remote code execution flaws in the AI application platform Langflow turned up this week inside ordinary commodity crawling. Customers get the full weekly brief. Our public At The Edge one-pager: www.greynoise.io/resources/at...
011
GreyNoise @greynoise.io · 11/09/2026
If you missed it: 395 organizations compromised across 48 countries. Hundreds of AI agents. One campaign against PaperCut NG/MF. We mapped the attack flow below⬇️ Read Agents Gone Wild: www.greynoise.io/blog/ai-orch...
032
GreyNoise @greynoise.io · 10/09/2026
The highest-volume malicious activity GreyNoise observed this week was a request for a file. Environment files, cloud configuration and repository configuration are all returned by a correctly functioning web server to anyone who asks for the right path. www.greynoise.io/resources/at...
000
GreyNoise @greynoise.io · 02/09/2026
This week exploitation attempts arrived in same-day cohorts across unrelated flaws. Customers get the full weekly brief. Our public At The Edge one-pager is attached + 🔗 www.greynoise.io/resources/at...
030
GreyNoise @greynoise.io · 01/09/2026
Great Day 1 at Fal.Con 2026 ✅ Lots of good conversations on the floor. If you're here this week, come find us at Booth #1757.
000
GreyNoise @greynoise.io · 26/08/2026
Most of the Log4Shell probing GreyNoise observed this week came from a single commercial scanning service. Our public At The Edge one-pager is attached. Customers get the full weekly brief. 🔗 www.greynoise.io/resources/at...
021
GreyNoise @greynoise.io · 19/08/2026
Four findings this period, one shared exposure pattern: each involves a surface an organization puts on the internet deliberately and then rarely inventories completely. 🔗https://www.greynoise.io/resources/at-the-edge-clear-081726
121
GreyNoise @greynoise.io · 17/08/2026
The new GreyNoise Visualizer just dropped 💥 We redesigned the GreyNoise Visualizer to match how defenders actually work. Log in and hit "Try the New Visualizer" to explore it today. 🔗https://www.greynoise.io/blog/new-way-to-navigate-greynoise
151
GreyNoise @greynoise.io · 14/08/2026
NoiseFest 2026 is a wrap. What a ride 🚎 🏵️✌️ Thank you to everyone who came out last week and made it such an incredible night. And a huge thank you to our wonderful sponsors: Sublime Security, Mallory, StepSecurity, and ProjectDiscovery. See you next year for NoiseFest 2027.....
020
GreyNoise @greynoise.io · 12/08/2026
Four findings this period, one shared exposure pattern: each involves a system that holds credentials or files for a secondary environment, so a successful attempt against one would likely open the next without a second exploit. 🔗https://www.greynoise.io/resources/at-the-edge-clear-081026
000
GreyNoise @greynoise.io · 22/07/2026
This week in GreyNoise data, rented crawlers probed for credentials and configuration secrets across widely deployed web software. Customers get the full weekly brief. Our public At The Edge Clear one-pager: www.greynoise.io/resources/at...
010
GreyNoise @greynoise.io · 21/07/2026
New in the GreyNoise Visualizer: the Intelligence Dashboard. Build one saved view of the threats you actually track, then watch it stay current on its own. Read the launch blog: greynoise.io/blog/intelli...
010
GreyNoise @greynoise.io · 13/07/2026
The Threat Brief Library is now live in the GreyNoise Visualizer! Browse, search, filter, and download weekly At The Edge briefs, Executive Situation Reports, and more. All built on primary-source data from our global sensor network. Check it out: www.greynoise.io/blog/threat-...
010
GreyNoise @greynoise.io · 08/07/2026
This week a long-dormant Palo Alto flaw came back to life in GreyNoise data. Separately, two coordinated hosting fleets ran the week's highest-volume web exploitation, roughly 7.5M connection attempts. 🔗https://www.greynoise.io/resources/at-the-edge-clear-070626
020
GreyNoise @greynoise.io · 24/06/2026
Four things that caught our eye at the edge this week: www.greynoise.io/resources/at...
020
GreyNoise @greynoise.io · 18/06/2026
Three things that caught our eye at the edge this week: - One host mapped the enterprise edge. - A pair ran a Hikvision camera RCE (CISA KEV) on shared tooling. - VPN logins stayed under steady pressure. This week's At The Edge Clear 👉 www.greynoise.io/resources/at...
000
GreyNoise @greynoise.io · 16/06/2026
We're in London tomorrow for CrowdStrike #CrowdTour2026. If you're attending our team would love to connect! Schedule some time to meet with us: info.greynoise.io/crowdtour-20... #CyberSecurity #GreyNoise #ThreatIntel
010
GreyNoise @greynoise.io · 12/06/2026
GreyNoise At The Edge Intel Brief (June 1-8, 2026) This week attackers went after the front door of remote access — RDP, SSL VPN, router management — not new CVEs. 🔗 www.greynoise.io/resources/at...
010
GreyNoise @greynoise.io · 29/05/2026
The week's signal: a long-running MikroTik RouterOS brute-force operation (VPSVAULT, AS215925) reversed a multi-week decline — adding a second node and climbing back to ~1.9M sessions against the management API. Rented infrastructure, inventorying the edge. 🔗 www.greynoise.io/resources/at...
010
GreyNoise @greynoise.io · 27/05/2026
We're in Toronto for CrowdStrike #CrowdTour2026 tomorrow, May 28th! Attending the event or local to the area? We'd love to connect. Book time with our team: info.greynoise.io/crowdtour-20...
000
GreyNoise @greynoise.io · 19/05/2026
The mission: make sure no attack works twice. 🚀 We're hiring a Detection Engineer and a Federal Customer Success Manager to help us get there. Remote-friendly, high-impact, great benefits. Sound like you? 👇 www.greynoise.io/careers
001
GreyNoise @greynoise.io · 30/04/2026
Today's the perfect day for a matinee double feature: GreyNoise University LIVE: www.greynoise.io/events/greyn... The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse Webinar: info.greynoise.io/webinar/invi...
000
GreyNoise @greynoise.io · 29/04/2026
Introducing Project Swarm: a research initiative to defend the network edge and we're inviting you to join. Deploy a sensor on your infrastructure, capture real attacker traffic + compare what's hitting you to the GreyNoise global baseline. Join today! 🐝
120
GreyNoise @greynoise.io · 01/04/2026
GreyNoise is headed to 🇸🇪 Stockholm for CrowdStrike #CrowdTour2026 on 🗓️ April 15th. Attending the event or local to the area? We’d love to connect. 🔗 Book a dedicated time to meet with our team here: lnkd.in/e4_FA-7h #CyberSecurity #CrowdStrike #GreyNoise #ThreatIntel #Stockholm
000
GreyNoise @greynoise.io · 31/03/2026
NEW: GreyNoise At The Edge Intel Brief (March 23-30) 187,998,900 sessions. 100 top source IPs. Daily volumes surged 4x mid-week as at least 4 new scanning operations activated simultaneously. Here's what we found: 🔗 www.greynoise.io/resources/at...
000
GreyNoise @greynoise.io · 26/03/2026
GreyNoise is proud to be sponsoring the CrowdStrike CrowdTour across 8 cities! 🌏 We’re excited to highlight how our integration with Falcon Next-Gen SIEM helps SOC teams stop chasing ghosts and start catching real threats. 👇Book a meeting with us here: info.greynoise.io/crowdtour-20...
022
GreyNoise @greynoise.io · 25/03/2026
Last week, half of all new scanning IPs observed by GreyNoise geolocated to Hong Kong. A quarter-million never completed a TCP handshake. The ones that did were scanning MySQL, SSH, SMB, and RDP across 20+ countries. One of these is the signal. The other is noise. www.greynoise.io/blog/ghost-f...
001
GreyNoise @greynoise.io · 24/03/2026
NEW: GreyNoise At The Edge Intel Brief (Mar 16–23) 200,886,675 sessions. 101 unique source IPs. Here's what we found: www.greynoise.io/resources/at...
000
GreyNoise @greynoise.io · 19/03/2026
New GreyNoise At The Edge brief: The internet's scanning infrastructure is reorganizing. UCLOUD (HK) surged +578% to become the #1 scanning ASN, now 15.6% of all observed traffic. Western providers declining simultaneously. 301.8M sessions. 439K IPs. Here's what we found.
Dark-themed GreyNoise Intelligence summary slide titled ‘The Scanning Landscape Is Reorganizing’ for March 9–16, 2026, showing total scanning stats and brief blurbs on uCloud’s 578% surge, escalating edge device exploits, fast‑rotating RDP operators, and a renewed React2Shell campaign, with a call to action to get the full report.
100
GreyNoise @greynoise.io · 11/03/2026
Hey London! We are closing down day 1 at #ecrimecongress today + cant wait to see you tomorrow! If you're around, say hi to the team, watch a demo, and grab some great swag! 🔥
000
GreyNoise @greynoise.io · 04/03/2026
Here's a taste of what GreyNoise customers got in this week's At The Edge intelligence brief. 268M sessions. 540K unique IPs. Four findings that matter. Full brief: IOCs, attribution, recommendations. 🔗 www.greynoise.io/resources/at... greynoise.io/contact
A GreyNoise Intelligence Weekly Intelligence Brief cover page titled “Weekly Intelligence Brief” with the subhead “The Scanning Landscape Collapsed. Enterprise Campaigns Intensified.” The design features large bold statistics across the center, including “268M sessions observed,” “435% Sophos surge,” “9.1M RDP sessions,” and “Week 6 VPN siege.” Supporting text summarizes key findings about collapsing global scanning volume, intensified Sophos firewall exploitation, massive RDP scanning from two IPs, and ongoing VPN credential campaigns targeting enterprise perimeter infrastructure. The footer includes a call to action to contact GreyNoise for the full brief, the GreyNoise logo, and the company website and social handle on a clean, professional white background with branded typography.
022
GreyNoise @greynoise.io · 18/02/2026
This week's At the Edge: CLEAR is out — a preview of the intel brief GreyNoise customers get every week. 🔗 www.greynoise.io/resources/at... That's just the preview. greynoise.io/contact #ThreatIntel #CyberSecurity #GreyNoise
A GreyNoise Intelligence weekly brief cover page titled “Weekly Intelligence Brief” for February 9–16, 2026, using a clean corporate layout with the GreyNoise logo at the top. Large headline text reads “IoT, Edge, Credentials. All Surging at Once.” followed by a short summary paragraph describing rising IoT botnet recruitment, Fortinet VPN brute-forcing, and credential harvesting. Four bold numeric callouts highlight “91% IoT default password surge,” “98% increase Fortinet VPN brute-force,” “8.28M credential harvesting sessions,” and “84 days of crypto C2 beaconing.” Below, four brief section teasers describe IoT botnet activity, enterprise edge credential attacks, broad credential harvesting, and an 84-day crypto exchange C2 operation. The footer includes a “Want the full brief?” marketing call-to-action with the GreyNoise contact URL and social handle, plus a “TLP: CLEAR” label indicating public sharing is allowed.
010
GreyNoise @greynoise.io · 11/02/2026
Three campaigns. One has Cobalt Strike ready. RDP nearly quadrupled. A botnet picked up a new CVE. And someone built a Kubernetes cluster just to exploit n8n. A preview of what GreyNoise customers get every week. Full brief has the IOCs, attribution, and analysis.
A dark-themed “Weekly Intelligence Brief” report from GreyNoise covering February 2–9, 2026, summarizing global malicious scanning activity. Large headline text highlights a 113% week‑over‑week surge in Remote Desktop Protocol (RDP) attacks, with 29.9 million RDP attempts, 83,000 N8N exploits, and 352 callback domains associated with OAST. Below, the layout is divided into four sections: one explaining that RDP attacks more than doubled in a week driven by a single noisy IP; one titled “Ivanti ‘Three‑Headed Hydra’” describing three independent campaigns abusing CVE‑2022‑1281 with Cobalt Strike; one on N8N exploitation describing 83,334 attempts against CVE‑2022‑21858 from a specific IP range and warning about exposed API keys; and one on the Rondodx botnet summarizing high session counts and links to previous activity. A footer invites readers to contact GreyNoise for the full brief and includes a link to the company website.
000
GreyNoise @greynoise.io · 04/02/2026
Check out this month's NoiseLetter for the latest on Ghostie + all things GreyNoise! 🗞️ www.greynoise.io/resources/no...
000
GreyNoise @greynoise.io · 27/01/2026
Three campaigns. One fingerprint. React RCE, VPN brute forcing, and router scanning—all linked to the same infrastructure.→ 1.7M React attacks → 506K VPN targets → 3 IPs behind 1.8M router attempts This week's At The Edge preview: greynoise.io/contact
A digital intelligence brief from GreyNoise titled “AT THE EDGE,” dated January 19–23, 2026, summarizing three coordinated cyber campaigns under the headline “Three Campaigns. One Fingerprint.” The top of the graphic highlights key statistics in large text: 1.7M React attacks, 506K VPN targets, 1.8M router attempts, and a note that 3 IPs are responsible for 99% of observed activity. Below, four text blocks describe: (1) React exploitation attempts related to CVE-2025-55182, including real command injection, a Metasploit module, and one hosting provider generating 57% of traffic; (2) sustained attacks on enterprise VPNs (Fortinet SSL VPN and Palo Alto GlobalProtect) with 506K sessions, a 25% increase over baseline for Fortinet, and emphasis that VPN credentials are valuable for ransomware; (3) router attacks where three IPs drive 1.8M attempts, focusing on a MikroTik RouterOS brute-force campaign with a 64,000:1 session-to-IP ratio and noting compromised routers as pivot points and botnet nodes; and (4) an explanation that a shared JA1T network fingerprint links the React RCE, VPN brute force, and environment crawling to common infrastructure, suggesting organized operations rather than random scanning. The bottom banner invites GreyNoise customers to access the full brief, mentioning complete IOCs, attribution, detection guidance, and weekly role-based recommendations, with a contact URL “greynoise.io/contact” and a small 2026 GreyNoise, Inc. copyright notice.
052
GreyNoise @greynoise.io · 13/01/2026
Check out @hrbrmstr.dev today on @huntress.com's Tradecraft Tuesday at 1pm ET to chat about all things #React2Shell. 🤘 🔗 www.huntress.com/upcoming-web...
000
GreyNoise @greynoise.io · 12/01/2026
🚨 We are hiring across sales, alliances, and customer experience for our US + EMEA teams 🌍 See a role you'd crush? We would love to hear from you! 👉 Apply now: greynoise.io/careers #hiring #cybersecuritycareers
Black GreyNoise hiring graphic with bold text reading ‘We Are Hiring!’ followed by a list of open roles: Director of Strategic Alliances; Regional Sales Manager – US DoD + IC; Sales Engineer – US DoD + IC; Regional Sales Manager – US Federal Civilian; Sales Development Representative – EMEA; and Customer Experience Specialist – EMEA. The design features teal wave lines and the GreyNoise logo, with a call to action to apply at greynoise.io/careers.
041
GreyNoise @greynoise.io · 31/12/2025
New year, new opportunities? Check out our current openings for a new start in the new year! 🪩🎉 🔗 greynoise.io/careers
042
GreyNoise @greynoise.io · 11/12/2025
Just in: Watch #React2Shell exploitation unfold over time in the map below (geo of source IPs attempting to exploit CVE-2025-55182). #GreyNoise #ThreatIntel #CVE202555182 #Nextjs #Cybersecurity
084
GreyNoise @greynoise.io · 09/12/2025
Going LIVE in 30 to talk all things React2Shell with the Storm ⚡️ Watch crew! www.linkedin.com/events/storm...
010
GreyNoise @greynoise.io · 09/12/2025
👀 React2Shell attacker profiles fresh from GreyNoise telemetry: info.greynoise.io/hubfs/PDFs-S..., don't miss the latest contribution from GreyNoise Labs on React2Shell: www.labs.greynoise.io/grimoire/202... #React2Shell #Nextjs #CVE202555182 #CVE #GreyNoise
Graphic summarizing five React2Shell attacker profiles: Mass Scanners, VPN/Proxy Users, Cryptomining Operators, Malware Distribution Infrastructure, and Reconnaissance Specialists. Each group shows distinct characteristics, JA4+ signatures, and assessments ranging from benign scanning to organized cybercrime activity. GreyNoise notes customers receive full signatures in their intelligence brief.
0106
GreyNoise @greynoise.io · 17/11/2025
Hey Canada, we're packed up + headed to #SuriCon25! 🇨🇦 Check out our booth and don't miss @ntkramer.bsky.social + @iagox86.bsky.social talk ...and if you happen to run into them or @hrbrmstr.dev around the con, they might have something special for you 🥧...
041
GreyNoise @greynoise.io · 13/11/2025
🚨 GreyNoise for @microsoft.com Sentinel is here! Filter out internet background noise automatically. Focus on real threats. #MicrosoftSentinel #AppAssure 🔗 techcommunity.microsoft.com/blog/Microso...
031
GreyNoise @greynoise.io · 06/11/2025
We’ve launched At The Edge, a weekly brief for GreyNoise customers highlighting shifts in attacker behavior seen across the Global Observation Grid (GOG). Human-led analysis that turns internet noise into insight defenders can act on. #ThreatIntel #GreyNoise
031
GreyNoise @greynoise.io · 31/10/2025
Happy Halloween from your fave GreyNerds 🍬🍫
4124
GreyNoise @greynoise.io · 16/10/2025
GreyNoise's Threat Intelligence Map visualizes network events across the internet, scans, probes, attacks + connects them to geopolitical context. Real-time intelligence, that looks pretty cool too 😎 🗺️ threat-map.greynoise.io
030