home.social

#greynoise — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #greynoise, aggregated by home.social.

fetched live
  1. NoiseFest is just a few weeks away!🎉 If you're in Las Vegas for #BlackHat or #DEFCON, come join us for a night of cold drinks, good company, and 60s and 70s vibes. 🏵️

    📅Thursday, August 6th | 6–9 PM PT | Las Vegas
    🔗RSVP: info.greynoise.io/events/black

    #NoiseFest #GreyNoise #cybersecurity

  2. NoiseFest is just a few weeks away!🎉 If you're in Las Vegas for #BlackHat or #DEFCON, come join us for a night of cold drinks, good company, and 60s and 70s vibes. 🏵️

    📅Thursday, August 6th | 6–9 PM PT | Las Vegas
    🔗RSVP: info.greynoise.io/events/black

    #NoiseFest #GreyNoise #cybersecurity

  3. Three things that caught our eye at the edge this week:

    - One host mapped the enterprise edge.
    - A pair ran a Hikvision camera RCE (CISA KEV) on shared tooling.
    - VPN logins stayed under steady pressure.

    Defend on behavior, not IPs. This week's At The Edge Clear👉 greynoise.io/resources/at-the-

    #ThreatIntelligence #CyberSecurity #GreyNoise #InfoSec

  4. Three things that caught our eye at the edge this week:

    - One host mapped the enterprise edge.
    - A pair ran a Hikvision camera RCE (CISA KEV) on shared tooling.
    - VPN logins stayed under steady pressure.

    Defend on behavior, not IPs. This week's At The Edge Clear👉 greynoise.io/resources/at-the-

    #ThreatIntelligence #CyberSecurity #GreyNoise #InfoSec

  5. GreyNoise At The Edge Intel Brief | June 1-8, 2026

    This week's story: credential attacks on the front door of remote access, not new vulnerabilities.
    🔗 greynoise.io/resources/at-the-

    1. A single Netherlands host (94.102.49.82, malicious) produced more than a quarter of all RDP crawling we observed — a 48-hour burst across a wide port range, then silence.

    2. Every major SSL VPN vendor — Fortinet, Cisco, SonicWall, and Palo Alto — drew sustained credential brute-forcing and login scanning.

    3. A two-node MikroTik RouterOS brute-force campaign (NL + BR) continued for a third week on TCP/8728.

    4. Nine of the top ten source IPs trace to rented hosting — apply GreyNoise dynamic blocklists for the relevant tags — the IPs rotate, the tag-based coverage does not.

    The actionable intelligence is the specific IPs, ASNs, and GreyNoise tags — not generic hardening advice.

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  6. GreyNoise At The Edge Intel Brief | June 1-8, 2026

    This week's story: credential attacks on the front door of remote access, not new vulnerabilities.
    🔗 greynoise.io/resources/at-the-

    1. A single Netherlands host (94.102.49.82, malicious) produced more than a quarter of all RDP crawling we observed — a 48-hour burst across a wide port range, then silence.

    2. Every major SSL VPN vendor — Fortinet, Cisco, SonicWall, and Palo Alto — drew sustained credential brute-forcing and login scanning.

    3. A two-node MikroTik RouterOS brute-force campaign (NL + BR) continued for a third week on TCP/8728.

    4. Nine of the top ten source IPs trace to rented hosting — apply GreyNoise dynamic blocklists for the relevant tags — the IPs rotate, the tag-based coverage does not.

    The actionable intelligence is the specific IPs, ASNs, and GreyNoise tags — not generic hardening advice.

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  7. NoiseFest is BACK 🎉
    We're throwing our 4th annual party during Black Hat / DEF CON 2026 with a 60s and 70s theme 🏵️🎸✌️. Cold drinks, new connections, and stories from the front lines of cybersecurity at House of Blues B-Side in Las Vegas.

    🔗RSVP: info.greynoise.io/events/black

    #BlackHat #DEFCON #NoiseFest #GreyNoise #cybersecurity

  8. NoiseFest is BACK 🎉
    We're throwing our 4th annual party during Black Hat / DEF CON 2026 with a 60s and 70s theme 🏵️🎸✌️. Cold drinks, new connections, and stories from the front lines of cybersecurity at House of Blues B-Side in Las Vegas.

    🔗RSVP: info.greynoise.io/events/black

    #BlackHat #DEFCON #NoiseFest #GreyNoise #cybersecurity

  9. GreyNoise At The Edge (May 19–26, 2026): a week of rented-infrastructure reconnaissance against the internet's edge — routers, VPN gateways, container planes, and embedded devices, probed in parallel.

    1. A long-running MikroTik RouterOS brute-force operation (VPSVAULT, AS215925) reversed a multi-week decline, adding a second node and climbing back to ~1.9M sessions against TCP/8728.

    2. A fingerprinted Netherlands cluster cataloged Fortinet, Ivanti, Pulse Secure, Sophos, and F5 appliances, running auth-bypass checks including Palo Alto PAN-OS GlobalProtect (CVE-2020-2034).

    3. Telnet dominated volume; low-level probing continued for the tracked GNU telnetd out-of-bounds write watch item CVE-2026-32746 (CVSS 9.8).

    4. Kubernetes and Docker control-plane recon now runs from a compromised consumer broadband host.

    The infrastructure rotates constantly — detect on behavior, not addresses.

    greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  10. GreyNoise At The Edge (May 19–26, 2026): a week of rented-infrastructure reconnaissance against the internet's edge — routers, VPN gateways, container planes, and embedded devices, probed in parallel.

    1. A long-running MikroTik RouterOS brute-force operation (VPSVAULT, AS215925) reversed a multi-week decline, adding a second node and climbing back to ~1.9M sessions against TCP/8728.

    2. A fingerprinted Netherlands cluster cataloged Fortinet, Ivanti, Pulse Secure, Sophos, and F5 appliances, running auth-bypass checks including Palo Alto PAN-OS GlobalProtect (CVE-2020-2034).

    3. Telnet dominated volume; low-level probing continued for the tracked GNU telnetd out-of-bounds write watch item CVE-2026-32746 (CVSS 9.8).

    4. Kubernetes and Docker control-plane recon now runs from a compromised consumer broadband host.

    The infrastructure rotates constantly — detect on behavior, not addresses.

    greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  11. A scanning pattern similar to the one preceding CVE-2026-0400 in February is active again. May 12 saw the largest single-day session volume on this SonicWall tag in 90 days.

    🔗 greynoise.io/blog/sonicwall-sc

    #GreyNoise #ThreatIntel #SonicWall

  12. A scanning pattern similar to the one preceding CVE-2026-0400 in February is active again. May 12 saw the largest single-day session volume on this SonicWall tag in 90 days.

    🔗 greynoise.io/blog/sonicwall-sc

    #GreyNoise #ThreatIntel #SonicWall

  13. GreyNoise At The Edge — April 13–20, 2026. Four themes dominated activity on the GreyNoise sensor network this week — spanning reconnaissance, exploitation attempts, credential brute-forcing, and botnet recruitment.

    1. A broad credential and configuration discovery campaign ran at ~6.2M sessions across hundreds of IPs — ENV files, .git/config, AWS metadata, path traversal, sensitive file access. The biggest real story, distributed rather than concentrated.

    2. VNC scanning surged to the third-most-targeted port on the internet — port 5900 at 17.4M sessions. Not in prior briefs.

    3. A new multi-cloud Masscan framework activated this week. Shared JA3 across a new Poland IP and an existing DigitalOcean Singapore cluster.

    4. VPSVAULT IoT worm weaponized CVE-2025-54322 (Xspeeder SXZOS, CVSS 10.0). CVE-2026-24061 (GNU telnetd, CVSS 9.8, CISA KEV) also in payload.

    Full Report: greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  14. GreyNoise At The Edge — April 13–20, 2026. Four themes dominated activity on the GreyNoise sensor network this week — spanning reconnaissance, exploitation attempts, credential brute-forcing, and botnet recruitment.

    1. A broad credential and configuration discovery campaign ran at ~6.2M sessions across hundreds of IPs — ENV files, .git/config, AWS metadata, path traversal, sensitive file access. The biggest real story, distributed rather than concentrated.

    2. VNC scanning surged to the third-most-targeted port on the internet — port 5900 at 17.4M sessions. Not in prior briefs.

    3. A new multi-cloud Masscan framework activated this week. Shared JA3 across a new Poland IP and an existing DigitalOcean Singapore cluster.

    4. VPSVAULT IoT worm weaponized CVE-2025-54322 (Xspeeder SXZOS, CVSS 10.0). CVE-2026-24061 (GNU telnetd, CVSS 9.8, CISA KEV) also in payload.

    Full Report: greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  15. See you in Glasgow for #CyberUK! 🇬🇧

    Find GreyNoise at Booth D2 + catch our talks:
    🗓 Apr 22, 12:20 – Nishawn Smagh
    🗓 Apr 23, 14:30 – Glenn Thorpe III

    Happy Hour @ Golf Fang on Apr 22 ⛳️

    Book 1:1 time: info.greynoise.io/cyberuk-meet

    #CyberSecurity #ThreatIntelligence #GreyNoise

  16. See you in Glasgow for #CyberUK! 🇬🇧

    Find GreyNoise at Booth D2 + catch our talks:
    🗓 Apr 22, 12:20 – Nishawn Smagh
    🗓 Apr 23, 14:30 – Glenn Thorpe III

    Happy Hour @ Golf Fang on Apr 22 ⛳️

    Book 1:1 time: info.greynoise.io/cyberuk-meet

    #CyberSecurity #ThreatIntelligence #GreyNoise

  17. NEW: GreyNoise At The Edge Intel Brief (March 23-30)

    187,998,900 sessions from 100 top source IPs observed by GreyNoise sensors between March 23-30, 2026. Daily volumes surged 4x mid-week — from 8.5M to 36.6M in 72 hours.

    1. VPSVAULT IoT botnet recruitment across 22 CVEs — 3,347,443 sessions from 4 Brazilian IPs targeting Hikvision, MikroTik, TP-Link, D-Link devices. Includes CVE-2026-24061, now on CISA KEV.

    2. VisionHeight fleet of 6 AWS IPs generated 5,892,055 sessions mapping enterprise perimeters across Palo Alto, Sophos, Ivanti, Citrix, F5, and ConnectWise — probing CVE-2024-1709 (CVSS 10.0).

    3. React/Next.js exploit chaining (CVE-2025-55182 + CVE-2025-29927) produced 1,338,336 sessions, with attackers spoofing GoogleBot user-agents to bypass detection.

    4. At least 4 new scanning operations activated simultaneously mid-week, driving the sharp volume surge across the observation period.

    Here's what we found: 🔗 greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  18. NEW: GreyNoise At The Edge Intel Brief (March 23-30)

    187,998,900 sessions from 100 top source IPs observed by GreyNoise sensors between March 23-30, 2026. Daily volumes surged 4x mid-week — from 8.5M to 36.6M in 72 hours.

    1. VPSVAULT IoT botnet recruitment across 22 CVEs — 3,347,443 sessions from 4 Brazilian IPs targeting Hikvision, MikroTik, TP-Link, D-Link devices. Includes CVE-2026-24061, now on CISA KEV.

    2. VisionHeight fleet of 6 AWS IPs generated 5,892,055 sessions mapping enterprise perimeters across Palo Alto, Sophos, Ivanti, Citrix, F5, and ConnectWise — probing CVE-2024-1709 (CVSS 10.0).

    3. React/Next.js exploit chaining (CVE-2025-55182 + CVE-2025-29927) produced 1,338,336 sessions, with attackers spoofing GoogleBot user-agents to bypass detection.

    4. At least 4 new scanning operations activated simultaneously mid-week, driving the sharp volume surge across the observation period.

    Here's what we found: 🔗 greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  19. 200,886,675 sessions. 101 unique source IPs. March 16–23, 2026.

    GreyNoise At The Edge intelligence brief highlights:

    1. The MEVSPACE RDP brute-force operator returned after a 99.8% infrastructure collapse — single IP generated 7,975,241 sessions before deliberately withdrawing after 4 days. GreyNoise has tracked a surge-withdraw-reconstitute cycle since January 2026, reinforcing that well-resourced operators can reconstitute capacity within days.

    2. Two coordinated campaigns emerged: VPSVAULT.HOST (IoT worm weaponizing 21+ CVEs against 12+ manufacturers) and Omegatech (TLS fingerprint randomization with 5,854 unique JA3s per node).

    3. Sophos CVE-2022-1040 exploitation stabilized at 638,654 sessions in its fifth consecutive week. Enterprise VPN credential pressure reached week 9 across five vendors with 2.9M+ combined sessions.

    4. n8n CVE-2026-21858 (CVSS 10.0) reached 118,086 sessions with links to MuddyWater and ZeroBot. ICS/SCADA reconnaissance expanded with new HMI and PLC vulnerabilities trending.

    🔗 greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  20. 200,886,675 sessions. 101 unique source IPs. March 16–23, 2026.

    GreyNoise At The Edge intelligence brief highlights:

    1. The MEVSPACE RDP brute-force operator returned after a 99.8% infrastructure collapse — single IP generated 7,975,241 sessions before deliberately withdrawing after 4 days. GreyNoise has tracked a surge-withdraw-reconstitute cycle since January 2026, reinforcing that well-resourced operators can reconstitute capacity within days.

    2. Two coordinated campaigns emerged: VPSVAULT.HOST (IoT worm weaponizing 21+ CVEs against 12+ manufacturers) and Omegatech (TLS fingerprint randomization with 5,854 unique JA3s per node).

    3. Sophos CVE-2022-1040 exploitation stabilized at 638,654 sessions in its fifth consecutive week. Enterprise VPN credential pressure reached week 9 across five vendors with 2.9M+ combined sessions.

    4. n8n CVE-2026-21858 (CVSS 10.0) reached 118,086 sessions with links to MuddyWater and ZeroBot. ICS/SCADA reconnaissance expanded with new HMI and PLC vulnerabilities trending.

    🔗 greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  21. 52% of RCE attempts came from IPs with no prior GreyNoise history. New research on where edge defenses fall short + what to do about it: greynoise.io/resources/2026-st

    #ThreatIntel #Cybersecurity #GreyNoise

  22. 52% of RCE attempts came from IPs with no prior GreyNoise history. New research on where edge defenses fall short + what to do about it: greynoise.io/resources/2026-st

    #ThreatIntel #Cybersecurity #GreyNoise

  23. This week's At the Edge: CLEAR is out — a preview of the intel brief GreyNoise customers get every week.

    🔗 greynoise.io/resources/at-the-

    That's just the preview. greynoise.io/contact

    #ThreatIntel #CyberSecurity #GreyNoise

  24. This week's At the Edge: CLEAR is out — a preview of the intel brief GreyNoise customers get every week.

    🔗 greynoise.io/resources/at-the-

    That's just the preview. greynoise.io/contact

    #ThreatIntel #CyberSecurity #GreyNoise

  25. Three campaigns. One has Cobalt Strike ready.

    RDP nearly quadrupled. A botnet picked up a new CVE. And someone built a Kubernetes cluster just to exploit n8n.

    A preview of what GreyNoise customers get every week. Full brief has the IOCs, attribution, and analysis.

    #ThreatIntelligence #InfoSec #GreyNoise #CyberSecurity

  26. Three campaigns. One has Cobalt Strike ready.

    RDP nearly quadrupled. A botnet picked up a new CVE. And someone built a Kubernetes cluster just to exploit n8n.

    A preview of what GreyNoise customers get every week. Full brief has the IOCs, attribution, and analysis.

    #ThreatIntelligence #InfoSec #GreyNoise #CyberSecurity

  27. We observed a 65% drop in global telnet traffic in a single hour on Jan 14, settling into a sustained 59% reduction. 18 ASNs went silent, 5 countries disappeared, but cloud providers were unaffected.

    Our analysis of 51.2M sessions points to backbone-level port 23 filtering by a North American Tier 1 transit provider.

    🔗 labs.greynoise.io/grimoire/202

    #GreyNoise #ThreatIntel #CyberSecurity #InfoSec

  28. We observed a 65% drop in global telnet traffic in a single hour on Jan 14, settling into a sustained 59% reduction. 18 ASNs went silent, 5 countries disappeared, but cloud providers were unaffected.

    Our analysis of 51.2M sessions points to backbone-level port 23 filtering by a North American Tier 1 transit provider.

    🔗 labs.greynoise.io/grimoire/202

    #GreyNoise #ThreatIntel #CyberSecurity #InfoSec

  29. ⚠️ Unlike typical exploits, no buffer overflow or memory corruption needed - just one manipulated environment variable grants root access

    🛡️ Not all Telnet implementations affected - only #GNU inet utils; proprietary versions like #Cisco and #BusyBox are safe

    📊 #GreyNoise threat intelligence reports multiple exploit attempts per hour already detected in the wild

    🔄 Telnet's unencrypted nature makes attacks visible to defenders monitoring plaintext traffic for "-f root" patterns

  30. ⚠️ Unlike typical exploits, no buffer overflow or memory corruption needed - just one manipulated environment variable grants root access

    🛡️ Not all Telnet implementations affected - only #GNU inet utils; proprietary versions like #Cisco and #BusyBox are safe

    📊 #GreyNoise threat intelligence reports multiple exploit attempts per hour already detected in the wild

    🔄 Telnet's unencrypted nature makes attacks visible to defenders monitoring plaintext traffic for "-f root" patterns

  31. New on the GreyNoise blog: We borrow from some unexpected fields, enzyme kinetics, species biodiversity models, astrophotography, to understand internet-wide scanning activity and measure what we might be missing.

    greynoise.io/blog/filtering-no

    #GreyNoise #Cybersecurity

  32. New on the GreyNoise blog: We borrow from some unexpected fields, enzyme kinetics, species biodiversity models, astrophotography, to understand internet-wide scanning activity and measure what we might be missing.

    greynoise.io/blog/filtering-no

    #GreyNoise #Cybersecurity

  33. GreyNoise analyzed activity targeting exposed Ollama and LLM infrastructure, identifying SSRF abuse attempts and large-scale probing of LLM model endpoints.
    Analysis: greynoise.io/blog/threat-actor
    #GreyNoise #ThreatIntelligence #LLMSecurity

  34. GreyNoise analyzed activity targeting exposed Ollama and LLM infrastructure, identifying SSRF abuse attempts and large-scale probing of LLM model endpoints.
    Analysis: greynoise.io/blog/threat-actor
    #GreyNoise #ThreatIntelligence #LLMSecurity

  35. Ransomware starts with reconnaissance: we observed a recent large-scale scanning campaign validating exploitable systems, data that feeds the initial access market and shows up later in real attacks. 🕵️‍♀️

    greynoise.io/blog/christmas-sc

    #GreyNoise #Ransomware #InitialAccess #IAB #Recon

  36. Ransomware starts with reconnaissance: we observed a recent large-scale scanning campaign validating exploitable systems, data that feeds the initial access market and shows up later in real attacks. 🕵️‍♀️

    greynoise.io/blog/christmas-sc

    #GreyNoise #Ransomware #InitialAccess #IAB #Recon

  37. @briankrebs Hi Sir sorry for the disturb. A swift question is it possible to detect such activity via check.labs.greynoise.io/ #greynoise #botnet

    Or does one have to use dedicated scans via wireshark and #shodan and the likes?

  38. @briankrebs Hi Sir sorry for the disturb. A swift question is it possible to detect such activity via check.labs.greynoise.io/ #greynoise #botnet

    Or does one have to use dedicated scans via wireshark and #shodan and the likes?

  39. GreyNoise IP Check – narzędzie pozwalające sprawdzić adres IP

    Firma GreyNoise, zajmująca się zbieraniem informacji o trwających skanach sieci i próbach wykorzystania podatności, stworzyła narzędzie, które może przydać się każdemu. TLDR: GreyNoise IP Check, bo o nim mowa, pozwala sprawdzić, czy adres IP, którym aktualnie wychodzimy do Internetu, jest widziany jako bezpieczny, czy może zauważono jakieś jego powiązania ze skanowaniem...

    #WBiegu #Awareness #Greynoise #Internet #Ip

    sekurak.pl/greynoise-ip-check-

  40. GreyNoise IP Check – narzędzie pozwalające sprawdzić adres IP

    Firma GreyNoise, zajmująca się zbieraniem informacji o trwających skanach sieci i próbach wykorzystania podatności, stworzyła narzędzie, które może przydać się każdemu. TLDR: GreyNoise IP Check, bo o nim mowa, pozwala sprawdzić, czy adres IP, którym aktualnie wychodzimy do Internetu, jest widziany jako bezpieczny, czy może zauważono jakieś jego powiązania ze skanowaniem...

    #WBiegu #Awareness #Greynoise #Internet #Ip

    sekurak.pl/greynoise-ip-check-

  41. Just in: Watch #React2Shell exploitation unfold over time in the map below (geo of source IPs attempting to exploit CVE-2025-55182).

    #GreyNoise #ThreatIntel #CVE202555182 #Nextjs #Cybersecurity

  42. Just in: Watch #React2Shell exploitation unfold over time in the map below (geo of source IPs attempting to exploit CVE-2025-55182).

    #GreyNoise #ThreatIntel #CVE202555182 #Nextjs #Cybersecurity