Sign in

Glenn

@ntkramer.bsky.social
2.6K followers 261 following 160 posts

Elder Millennial | 💼 Cybersecurity | I ask 'why?' a lot | Pro Oxford Comma | Fix it! | He/Him | #BLM | Views are my own.

PostsRepliesMedia
Glenn @ntkramer.bsky.social · 28/08/2026
🍟 & #threatintel It’s been a minute since I climbed onto my KEV known-ransomware-use “silent flip” soapbox, so this Friday afternoon seemed like a good time to get back up there: 20(!) flips in August, the most since May 2025.
100
Glenn @ntkramer.bsky.social · 14/07/2026
I’ll be at Black Hat / DEF CON next month, so DM me if you want to meet up! I’ve lost count of how many I’ve been to now (actually it'd be depressing to know). As logistically chaotic as the week is, it’s always worth it to catch up with old friends and make new ones. 1/2
100
Glenn @ntkramer.bsky.social · 18/05/2026
It seems that CISA is, in fact, shortening the time-to-fix for vulns added to the KEV of late. (Casual reminder that the KEV should not be used as "what we should patch" but it is a signal worth watching for awareness). #threatintel
010
Glenn @ntkramer.bsky.social · 04/05/2026
Big day! Today I start at Censys leading Applied AI, Intelligence (A²I²?). Threat hunting is getting a major upgrade with what we’re scheming. Stay tuned…
020
Glenn @ntkramer.bsky.social · 27/04/2026
Bittersweet yet exciting transition ahead. This week marks my last at GreyNoise. Lately I've spent a lot of time thinking about what I value most in this field: research and findings grounded in clarity, integrity, actionability, and truth that drives outcomes. #TheSignalShift
010
Glenn @ntkramer.bsky.social · 13/04/2026
When the signal gets lost in the noise, you learn to tune into a new frequency. Sometimes change doesn’t ask; it hums beneath the static. #TheSignalShift
000
Glenn @ntkramer.bsky.social · 16/02/2026
Looking forward to sharing the stage at [un]prompted with the wizard himself, @hrbrmstr.dev, as we showcase "Orbie" (a custom-built AI agent that analyzes internet-scale honeypot data to surface emerging threats and even identify campaigns).
unpromptedcon.org
Agenda - [un]prompted
100
Glenn @ntkramer.bsky.social · 12/02/2026
Excited to share that I've been asked to speak at the Minorities in Cybersecurity Conference this March! I’ll be on a panel “How Do You Define Cybersecurity Experience? A Change in Perspective” where we’ll dig into what really counts as cybersecurity experience
100
Glenn @ntkramer.bsky.social · 02/02/2026
My latest pet project, an RSS feed to alert you to the silent KEV knownRansomwareCampaignUse flips! (Did you know there were four CVEs flipped last week?) #threatintel
020
Glenn @ntkramer.bsky.social · 31/01/2026
🍩 & #threatintel - 95% of exploitation attempts targeting CVE-2026-20045, a critical vulnerability in Cisco Unified Communications Manager, have used a distinctive user-agent: Mozilla/5.0 (compatible; CiscoExploit/1.0) and are heavily targeting our Cisco Unified Communications Manager sensors. 1/2
200
Glenn @ntkramer.bsky.social · 29/01/2026
☕ & #threatintel - Two campaigns (100x spike!) are hitting Ivanti Connect Secure; one loud (34K sessions from Romania/Moldova), one stealthy (~6K distributed IPs). Both target a pre-exploitation endpoint for CVE-2025-0282.
labs.greynoise.io
Inside the Infrastructure: Who’s Scanning for Ivanti Connect Secure? – GreyNoise Labs
GreyNoise detected a 100x surge in Ivanti Connect Secure reconnaissance targeting CVE-2025-0282 (EPSS 93%). Analysis reveals two distinct campaigns: an aggressive AS213790-based operation generating 34K+ sessions and a stealthier distributed botnet approach across 6K IPs. Infrastructure analysis and defender recommendations included.
010
Glenn @ntkramer.bsky.social · 28/01/2026
CISA's KEV hit 1,500 yesterday. I'm working on a cool #threatintel blog (yes, I'm biased) about additional hidden intel in KEV that should be published soon, along with a helpful tool hosted by GreyNoise! :)
010
Glenn @ntkramer.bsky.social · 10/12/2025
☕ & #threatintel: CISA has moved the due date for mitigating CVE-2025-55182 (Meta React Server Components Remote Code Execution Vulnerability) up by two weeks. It was initially set for December 26, but it is now due on December 12. 1/2
131
Glenn @ntkramer.bsky.social · 09/12/2025
Ron & my talk from SuriCon 2025 | Abusing HTTP Quirks to Evade Detection I think it turned out pretty well; pardon the disco effect where a stage light was failing :) www.youtube.com/watc... CC: @iagox86.bsky.social @greynoise.io
youtube.com
SuriCon 2025 | Abusing HTTP Quirks to Evade Detection
Presented at SuriCon 2025 by Ron Bowes and Glenn Thorpe Network protocols are messy! Sure, there are standards — RFCs, IEEEs, you name it — but there are also multiple ways to do basically everything. If you’re relying on network IDS/IPS tools like Suricata, I have bad news — a sufficiently cl
063
Glenn @ntkramer.bsky.social · 23/10/2025
I hate everything. www.texastrib...
texastribune.org
Noise from crypto mine pushes Texas neighbors to start a town
Leaders of the effort say they moved to rural Hood County for its quiet country charm, which was shattered by what locals call “that roar” from the facility.
052
Glenn @ntkramer.bsky.social · 21/10/2025
Ron (@iagox86.bsky.social) and I are presenting at #Suricon (Montreal) next month! If you're around, you'll definitely want to find us for some sweet swag (oh, and our talk is pretty cool too!). suricon.net/agenda-m...
Network protocols are messy! Sure, there are standards — RFCs, IEEEs, you name it — but there are also multiple ways to do basically everything. If you’re relying on network IDS/IPS tools like Suricata, I have bad news — a sufficiently clever attacker can bypass *a lot* of your signatures, leaving you completely blind.

The cool part about HTTP is that, at every level of the stack, your software tries to make sense of the user’s (aka: the attacker’s) requests. From the web server (Apache, IIS, etc) to the language parser (PHP, .NET, etc) — everything just wants your requests to work, often at the expense of security! That’s great for ensuring the internet keeps working, but creates makes it *really* hard to write signatures!

This talk will start with the basics: we’ll look at HTTP requests and learn the in-depth quirks of how the protocol works. Then we’ll look at a variety of different HTTP-based exploits (path traversal, SQL injection, shell command injection, and more!). We’ll exam
031
Glenn @ntkramer.bsky.social · 03/10/2025
It’s time for many folks’ annual cultural learning session. 🤣
010
Reposted by Glenn
GreyNoise @greynoise.io · 02/10/2025
On 28 September, GreyNoise observed a sharp one-day surge in attempts to exploit Grafana CVE-2021-43798. Full analysis & malicious IPs ⬇️ #Grafana #GreyNoise #ThreatIntel
greynoise.io
Coordinated Grafana Exploitation Attempts on 28 September
GreyNoise observed a sharp one-day surge of exploitation attempts targeting CVE-2021-43798 — a Grafana path traversal vulnerability that enables arbitrary file reads. All observed IPs are classified a...
074
Glenn @ntkramer.bsky.social · 01/08/2025
We all know that @hrbrmstr.dev is a mad scientist, and when you give him the amazing telemetry our new fleet has been collecting lately, you get knowledge drops like this! Super proud of our @greynoise.io team’s work on the deception capabilities we now have! hashtag#threatintel
012
Reposted by Glenn
GreyNoise @greynoise.io · 24/07/2025
An unexpected cluster of malicious IPs in a remote U.S. town led GreyNoise researchers to uncover a 500+ device botnet. Full analysis ⬇️ #Cybersecurity #ThreatIntel #Botnet #VoIP #GreyNoise #Cyber #Tech
greynoise.io
A Spike in the Desert: How GreyNoise Uncovered a Global Pattern of VOIP-Based Telnet Attacks
A spike in botnet traffic from a single utility in a rural part of New Mexico led to the discovery of a global botnet. Explore how human-led, AI-powered analysis exposed compromised devices, uncovered...
0128
Glenn @ntkramer.bsky.social · 16/07/2025
🫖 & #threatintel - noticing a few other spikes orgs should be mindful of: 🔥 CVE-2025-49132 (Pterodactyl Panel RCE) (10/10 RCE) ⚡ CVE-2024-20439 (Cisco Smart Licensing Utility) (9.8/10, KEV) 📝 CVE-2017-18370 (Zyxel P660HN) 1/4
100
Glenn @ntkramer.bsky.social · 16/07/2025
🩸& #threatintel | We (GreyNoise) just published a quick note (www.greynoise.io/blo...) regarding CVE-2025-5777 - CitrixBleed 2 1/2
greynoise.io
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept was released on July 4.
1129
Glenn @ntkramer.bsky.social · 07/07/2025
🥜 & #threatintel - Thanks to @horizon3ai.bsky.social, we pushed a tag out today for CitrixBleed 2 CVE-2025-5777 and are backfilling. Currently, we see 233 hits starting on July 1 from: 64.176.50[.]109 38.154.237[.]100 102.129.235[.]108 121.237.80[.]241 45.135.232[.]2 Follow along... 1/2
120
Glenn @ntkramer.bsky.social · 12/06/2025
Just a totally normal trip home from the airport last night… passing the national guard rolling down the highway as they prepare for NO KINGS DAY protests. F this administration. About 3 more months before they start trying to censor social media via tech controls.
030
Glenn @ntkramer.bsky.social · 29/05/2025
Seems like a lot of work when you could have found 200 year old brain proteins in the US Congress rn. phys.org/news/2025-0...
phys.org
Paleoproteomic profiling recovers diverse proteins from 200-year-old human brains
A new method developed by researchers at the Nuffield Department of Medicine, University of Oxford, could soon unlock the vast repository of biological information held in the proteins of ancient soft ...
020
Glenn @ntkramer.bsky.social · 28/05/2025
It's hard to beat good deception. :)
070
Glenn @ntkramer.bsky.social · 27/05/2025
If you're ever feeling lonely, just close Zoom. This works because a funny thing always happens: a random last-minute Zoom will appear if you close it completely.
000
Glenn @ntkramer.bsky.social · 15/05/2025
🥤& #threat-intel: CISA added Langflow Code Injection CVE-2025-3248 to the KEV on May 5. Recently, it has garnered considerable attention, with South Korea leading the pack. This vuln enables unauthenticated attackers to execute arbitrary code via /api/v1/validate/code viz.greynoise.io/tag...
042
Glenn @ntkramer.bsky.social · 12/05/2025
This change legitimately pisses me off. TL;DR—They appear to be removing RSS for KEV alerts and moving them to email or X. They gave orgs 0 days to prepare. RSS is already a thing. The emails arrive many hours later. X is NOT a gov website(!); it even warns you when you click their link! 1/2
45619
Glenn @ntkramer.bsky.social · 15/04/2025
Join us live! Or later? Looking forward to chatting with Tracy!
020
Glenn @ntkramer.bsky.social · 07/04/2025
Hi yes. Help your local cybersecurity researchers. If you blog a thing, please date the blog. kthx.
0131
Reposted by Glenn
GreyNoise @greynoise.io · 27/03/2025
🚨 New GreyNoise Tag Alert: We've added a fresh tag tracking CrushFTP Authentication Bypass (CVE-2025-2825) exploitation attempts. Thanks to @horizon3ai.bsky.social for the intel! Dive into the details: viz.greynoise.io/tags/crushft...
033
Glenn @ntkramer.bsky.social · 27/03/2025
Today is Opening Day for baseball season in the US. At least now I have my fav sport to put on when I want to watch something but avoid TV news.
000
Glenn @ntkramer.bsky.social · 27/03/2025
Dammit
150
Reposted by Glenn
GreyNoise @greynoise.io · 26/03/2025
Headed to RSAC next month? 👀 NoiseFest will be just a few blocks away...no nonsense (well maybe a little 😈), just drinks, good people, and real security talk. House of Shields | April 30 | 7–10PM Spots are limited. RSVP now. info.greynoise.io/events/noise...
info.greynoise.io
GreyNoise - NoiseFest at RSAC 2025
Join us for NoiseFest at RSAC 2025 on April 30th, At the House of Shields. Enjoy drinks, snacks, and engaging conversations with your peers. RSVP now!
001
Glenn @ntkramer.bsky.social · 21/03/2025
Absolutely disgusting. The Trump admin (DHS) has repurposed opt-in email signups to spread their propaganda. Years ago (4+) I signed up for Homeland Security emails; I don't recall doing this but based on the ones in my email it was related to something cyber -- not surprising. 1/4
141
Glenn @ntkramer.bsky.social · 04/03/2025
Happy ~Fat~ Tariff Tuesday to all that celebrate stupidity.
020
Glenn @ntkramer.bsky.social · 27/02/2025
Greetings, esteemed colleagues of LUMON. Our annual report highlights the accelerated pace of mass exploitation, transcending new vulnerabilities. It guides CISOs toward strategic refinement and equips security teams with real-time intelligence, surpassing mere theoretical risks.
140
Glenn @ntkramer.bsky.social · 25/02/2025
Live in 2 hours! Very much looking forward to this conversation. Join us live and ask questions!
010
Glenn @ntkramer.bsky.social · 22/02/2025
Words have meanings. Words have consequences. apple.news/AcP5I9x7Q...
apple.news
Texas girl, 11, died by suicide; her parents say she was bullied with threats of ICE
A vigil is planned for Jocelynn Rojo Carranza on Saturday. Her family wants accountability and an investigation into what led to her death.
000
Reposted by Glenn
George Takei @georgetakei.bsky.social · 21/02/2025
DOGE = Department of Gross Errors
1017324875072
Glenn @ntkramer.bsky.social · 20/02/2025
Our show planning meeting (yes, we DO* plan) today was some real talk -- looking forward to Tuesday's conversation! *try to
031
Glenn @ntkramer.bsky.social · 19/02/2025
🍵 & #threatintel: @greynoise.io is observing a massive spike in exploitation attempts for CVE-2017-18368, Zyxel Command Injection Vulnerability. The source countries for this spike are pretty diverse; perhaps added to a botnet? viz.greynoise.io/tag...
020
Glenn @ntkramer.bsky.social · 19/02/2025
<reads latest asteroid hitting earth percentages> "Don't Look Up" is turning into a documentary; much like Idiocracy. ☄️
020
Glenn @ntkramer.bsky.social · 15/02/2025
We’re really about to lose the G in MAGA.
010
Glenn @ntkramer.bsky.social · 13/02/2025
🫖 & #threatintel - it took no time for the POC of CVE-2025-0108 (PAN-OS Authentication Bypass) to start being fired off across the internet. We're back-processing some data now to pick up some prior exploitation as well.
053
Glenn @ntkramer.bsky.social · 31/01/2025
If you're not subscribed to the GreyNoise-Noiseletter (next edition ships Monday), you are about to miss out on a BANGER... 1/2
121
Glenn @ntkramer.bsky.social · 29/01/2025
2025-01-29 Update After identifying a significant overlap between IPs exploiting CVE-2024-40891 and those classified as Mirai, the team investigated a recent variant of Mirai and confirmed that the ability to exploit CVE-2024-40891 has been incorporated into some Mirai strains.
032
Glenn @ntkramer.bsky.social · 28/01/2025
⤵️
020
Glenn @ntkramer.bsky.social · 22/01/2025
The little flag has, what, 38 stars on it? If they’re cutting costs by dropping states sign me up for one of those. (TBH I expected the flag to have 51 or 52 stars on it but they aren’t that clever).
110