Sign in

Glenn

@ntkramer.bsky.social
2.6K followers 261 following 162 posts

Elder Millennial | 💼 Cybersecurity | I ask 'why?' a lot | Pro Oxford Comma | Fix it! | He/Him | #BLM | Views are my own.

PostsRepliesMedia
Glenn @ntkramer.bsky.social · 28/08/2026
🍟 & #threatintel It’s been a minute since I climbed onto my KEV known-ransomware-use “silent flip” soapbox, so this Friday afternoon seemed like a good time to get back up there: 20(!) flips in August, the most since May 2025.
100
Glenn @ntkramer.bsky.social · 18/05/2026
It seems that CISA is, in fact, shortening the time-to-fix for vulns added to the KEV of late. (Casual reminder that the KEV should not be used as "what we should patch" but it is a signal worth watching for awareness). #threatintel
010
Glenn @ntkramer.bsky.social · 13/04/2026
When the signal gets lost in the noise, you learn to tune into a new frequency. Sometimes change doesn’t ask; it hums beneath the static. #TheSignalShift
000
Glenn @ntkramer.bsky.social · 31/01/2026
🍩 & #threatintel - 95% of exploitation attempts targeting CVE-2026-20045, a critical vulnerability in Cisco Unified Communications Manager, have used a distinctive user-agent: Mozilla/5.0 (compatible; CiscoExploit/1.0) and are heavily targeting our Cisco Unified Communications Manager sensors. 1/2
200
Glenn @ntkramer.bsky.social · 10/12/2025
☕ & #threatintel: CISA has moved the due date for mitigating CVE-2025-55182 (Meta React Server Components Remote Code Execution Vulnerability) up by two weeks. It was initially set for December 26, but it is now due on December 12. 1/2
131
Glenn @ntkramer.bsky.social · 21/10/2025
Ron (@iagox86.bsky.social) and I are presenting at #Suricon (Montreal) next month! If you're around, you'll definitely want to find us for some sweet swag (oh, and our talk is pretty cool too!). suricon.net/agenda-m...
Network protocols are messy! Sure, there are standards — RFCs, IEEEs, you name it — but there are also multiple ways to do basically everything. If you’re relying on network IDS/IPS tools like Suricata, I have bad news — a sufficiently clever attacker can bypass *a lot* of your signatures, leaving you completely blind.

The cool part about HTTP is that, at every level of the stack, your software tries to make sense of the user’s (aka: the attacker’s) requests. From the web server (Apache, IIS, etc) to the language parser (PHP, .NET, etc) — everything just wants your requests to work, often at the expense of security! That’s great for ensuring the internet keeps working, but creates makes it *really* hard to write signatures!

This talk will start with the basics: we’ll look at HTTP requests and learn the in-depth quirks of how the protocol works. Then we’ll look at a variety of different HTTP-based exploits (path traversal, SQL injection, shell command injection, and more!). We’ll exam
031
Glenn @ntkramer.bsky.social · 03/10/2025
It’s time for many folks’ annual cultural learning session. 🤣
010
Glenn @ntkramer.bsky.social · 15/05/2025
🥤& #threat-intel: CISA added Langflow Code Injection CVE-2025-3248 to the KEV on May 5. Recently, it has garnered considerable attention, with South Korea leading the pack. This vuln enables unauthenticated attackers to execute arbitrary code via /api/v1/validate/code viz.greynoise.io/tag...
042
Glenn @ntkramer.bsky.social · 12/05/2025
This change legitimately pisses me off. TL;DR—They appear to be removing RSS for KEV alerts and moving them to email or X. They gave orgs 0 days to prepare. RSS is already a thing. The emails arrive many hours later. X is NOT a gov website(!); it even warns you when you click their link! 1/2
45619
Glenn @ntkramer.bsky.social · 22/03/2025
And another one. Two in one day.
010
Glenn @ntkramer.bsky.social · 21/03/2025
March 21, 2025, I received this: 3/4
100
Glenn @ntkramer.bsky.social · 21/03/2025
March 13, 2025, I received this: 2/4
100
Glenn @ntkramer.bsky.social · 21/03/2025
Absolutely disgusting. The Trump admin (DHS) has repurposed opt-in email signups to spread their propaganda. Years ago (4+) I signed up for Homeland Security emails; I don't recall doing this but based on the ones in my email it was related to something cyber -- not surprising. 1/4
141
Glenn @ntkramer.bsky.social · 19/02/2025
🍵 & #threatintel: @greynoise.io is observing a massive spike in exploitation attempts for CVE-2017-18368, Zyxel Command Injection Vulnerability. The source countries for this spike are pretty diverse; perhaps added to a botnet? viz.greynoise.io/tag...
020
Glenn @ntkramer.bsky.social · 21/01/2025
Regarding the Murdoc botnet delivering Mirai malware (www.darkreading.com/...) GreyNoise has 👀 1) viz.greynoise.io/tag... 2) viz.greynoise.io/tag...
144
Glenn @ntkramer.bsky.social · 07/01/2025
Censys released an advisory regarding Kerio CVE-2024-52875. We at GreyNoise began observing exploit attempts on December 28. Although the IP addresses involved are currently quite noisy, it's notable that they predominantly trace from Singapore to Lithuania. #threatintel viz.greynoise.io/tag...
021
Glenn @ntkramer.bsky.social · 23/12/2024
Happy Festivus! _|_
010
Glenn @ntkramer.bsky.social · 23/12/2024
Was there a CVE for this? 😆 support.microsoft.com/en-us/office...
Keyboard shortcut for Bold changed in Word after update
121
Glenn @ntkramer.bsky.social · 04/12/2024
Amplifying this from our /noiseletter/. Today marks a significant milestone for GreyNoise as we (essentially) launch GreyNoise v2. 1/5
252
Glenn @ntkramer.bsky.social · 30/10/2024
We, @greynoise.bsky.social, are seeing a massive uptick in IPs attempting to authenticate via telnet using one of several known backdoor accounts in FiberHome routers. viz.greynoise.io/tag...
060
Glenn @ntkramer.bsky.social · 18/10/2024
🎃 & #threatintel: We/GreyNoise have observed a significant increase in Fortinet SSL brute force attempts recently. This is the highest level in the past two months and the third highest of 2024. viz.greynoise.io/tag...
Chart showing the rise of Fortinet SSL brute force attempts over the last 10 days. It is climbing quickly.
0112
Glenn @ntkramer.bsky.social · 22/09/2024
🗞️ & #threatintel: Increased interest in IPs attempting to exploit CVE-2023-4966, an unauthenticated information disclosure vulnerability in Citrix ADC & NetScaler platforms. viz.greynoise.io/tag...
010
Glenn @ntkramer.bsky.social · 05/09/2024
You disappoint ME! 😅 You must have a short name thing going on.
110
Glenn @ntkramer.bsky.social · 14/08/2024
☕️ & #threatintel: GreyNoise is observing a sizable increase in IPs attempting to brute-force credentials against Fortinet SSL VPNs. This is the most activity we've observed since mid January 2024. viz.greynoise.io/tag...
Chart showing a recent increase.
001
Glenn @ntkramer.bsky.social · 05/08/2024
🎰 & #threatintel: GreyNoise has observed an increase in the exploitation of CVE-2021-28799 over the past few days. This vulnerability affects QNAP NAS devices and allows unauthorized remote access. viz.greynoise.io/tag...
Chart showing increase in the exploitation of CVE-2021-28799 over the past few days.
000
Glenn @ntkramer.bsky.social · 05/08/2024
I'll be around the hackery summery campy things this week starting late Tues; looking forward to all the things except the germs and exhaustion. See you around! #blackhat #BHUSA #DEFCON #defcon32 #brathacker #bsideslv #HackerSummercamp #didimissone
brat hacker meme
010
Glenn @ntkramer.bsky.social · 03/08/2024
🌭 & #threatintel: Not loving the bump in interest of Cisco CVE-2019-1935 right before #blackhat #defcon week. viz.greynoise.io/tag...
011
Glenn @ntkramer.bsky.social · 15/07/2024
Looking back further, you can see how unusual it is: 2/2
010
Glenn @ntkramer.bsky.social · 15/07/2024
🥪 & #threatintel: something suspicious a-bot this spike in IP addresses attempting to exploit Mikrotik CVE-2018-14847... new botnet/addition? viz.greynoise.io/tag... 1/2
Chart showing huge increase in IP addresses attempting to exploit Mikrotik CVE-2018-14847.
111
Glenn @ntkramer.bsky.social · 13/06/2024
🥪 & #threatintel: We're seeing a significant uptick (the most in the last 6+ months) in the inventorying of Outlook Web Access (OWA) instances; I can't imagine why... [Narrator: Microsoft’s June 2024 Patch Tuesday] viz.greynoise.io/tag...
Chart showing a significant uptick in inventorying Outlook Web Access (OWA) instances
110
Glenn @ntkramer.bsky.social · 08/06/2024
⛱️ and #threatintel: GreyNoise has observed exploitation for CVE-2024-4577, a remote code execution vulnerability in Windows-based PHP installations. viz.greynoise.io/tag...
031
Glenn @ntkramer.bsky.social · 08/05/2024
☕️ & #threatintel: Based on the research from Bishop Fox, we created a tag for this week's (no-CVE-yet) Citrix Netscaler Info Disclosure and are seeing activity as far back as March 7, 2024. Tag: viz.greynoise.io/tag... Research: bishopfox.com/blog/n...
021
Glenn @ntkramer.bsky.social · 07/05/2024
For reference, its the highest we've observed with our telemetry. 2/2
Chart showing the recent spikes far exceed any previously recorded interest.
010
Glenn @ntkramer.bsky.social · 07/05/2024
☕️☕️ & #threatintel: GreyNoise has observed a renewed interest in CVE-2023-4966 and CVE-2023-4967 in Citrix Netscaler (this isn't surprising given recent news). viz.greynoise.io/tag... 1/2
Chart showing two recent spikes at the end of April.
121
Glenn @ntkramer.bsky.social · 07/05/2024
2/2
Image showing the top source country of these attempts is from Egypt.
000
Glenn @ntkramer.bsky.social · 07/05/2024
☕️ & #threatintel: GreyNoise is observing a sudden and significant increase in the number of IPs attempting to exploit the Linksys E-Series TheMoon command injection vulnerability. viz.greynoise.io/tag... 1/2
Chart showing a sudden increase in the last few days.
100
Glenn @ntkramer.bsky.social · 26/04/2024
🥪 & #threatintel: we published a tag for CVE-2024-2389, a command-injection vulnerability in Progress Flowmon accessible without authentication. (fixed CVE # from a previous post) viz.greynoise.io/tag...
011
Glenn @ntkramer.bsky.social · 17/04/2024
☕️ & #threatintel: as expected, Palo Alto's PAN-OS CVE-2024-3400 exploitation has transitioned to widespread and opportunistic. Be sure to keep up with PA's advisory as it was updated on the last day. viz.greynoise.io/tag...
022
Glenn @ntkramer.bsky.social · 09/04/2024
Top source/dest countries: 2/2
Source Countries
China
202
India
156
United States
156
South Korea
121
Brazil
70
Destination Countries
United States
1,525
Israel
1,484
United Kingdom
1,481
Spain
1,467
Ukraine
1,448
010
Glenn @ntkramer.bsky.social · 09/04/2024
🥪 & #threatintel: Seeing a massive uptick in IPs attempting to access a known SSH backdoor using undocumented credentials (CVE-2020-29583) for Zyxel USG devices. viz.greynoise.io/tag... 1/2
Chart showing an increase from near 0 to over 1500 in the last day.
121
Glenn @ntkramer.bsky.social · 05/03/2024
⚡️ & #threatintel: to no one's surprise, we are already observing IPs attempting to exploit an authentication bypass in JetBrains' TeamCity (CVE-2024-27198) following yesterday's POC release. viz.greynoise.io/tag...
011
Glenn @ntkramer.bsky.social · 04/03/2024
🥪 & #threatintel: seeing a predictable spike in activity around TeamCity with the impending release of technical information related to CVE-2024-27198, CVE-2024-27199. *this tag is not for the CVEs listed above PATCH UP! viz.greynoise.io/tag... blog.jetbrains.com/t...
Chart showing nearly 200 IPs looking for CVE-2023-42793; a vuln in JetBrains TeamCity.
020
Glenn @ntkramer.bsky.social · 23/02/2024
000
Glenn @ntkramer.bsky.social · 23/02/2024
🥪 & #threatintel: Increased interest in CVE-2019-8950, a known backdoor account in certain versions of DASAN H665 (a compact GPON Optical Network Terminal (ONT) for both residential and business customers.) viz.greynoise.io/tag...
Chart showing a significant increase in IPs attempting to exploit this CVE.
100
Glenn @ntkramer.bsky.social · 14/02/2024
This heatmap is a few days old but the Ivanti love is overflowing for a few!
000
Glenn @ntkramer.bsky.social · 14/02/2024
💞 & #threatintel: Attackers are showing their love for Ivanti; there's been quite the uptick in IP addresses attempting to perform a remote code execution attack against Ivanti Connect Secure (ICS) (CVE-2023-46805, CVE-2024-21887) in the past day. viz.greynoise.io/tag...
Graph showing a large increase in attacks in the past day.
120
Glenn @ntkramer.bsky.social · 06/02/2024
🍽️ & #threatintel | The Cisco, F5, Ivanti, Juniper, JetBrains, and OwnCloud exploitation attempts have jumped so much in the last two days that they squashed the normal scale of the charts. viz.greynoise.io/tre...
Graph showing huge spike in attempts yesterday.
000
Glenn @ntkramer.bsky.social · 02/02/2024
🐸 & #threatintel: A reminder that log4j is a forever-day. - Don't forget about your internal hosts. - Don't forget about your restored hosts. - Don't forget about your newly incorporated hosts. www.darkreading.com/... viz.greynoise.io/tag...
Chart showing log4j exploitation attempts continue.
000
Glenn @ntkramer.bsky.social · 20/01/2024
🥶 & #threatintel: There has been a significant increase in attempts to exploit a remote code execution vulnerability in the popular Java logging library Apache Log4j, identified as CVE-2021-44228 and CVE-2021-45046. viz.greynoise.io/tag...
Chart showing a near 5x increase in IPs attempting to exploit CVE-2021-44228 and CVE-2021-45046, a remote code execution vulnerability in the popular Java logging library Apache Log4j over the last day or so.
020
Glenn @ntkramer.bsky.social · 12/01/2024
🥪 & #threatintel: Holy Batman, there's been a massive increase in the number of IP addresses attempting to bruteforce credentials against Fortinet SSL VPNs in the past 24 hours. viz.greynoise.io/tag...
The chart shows 2000+ IPs attempting to brute force Fortinet in the last 24 hours.
000