home.social

#greynoise — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #greynoise, aggregated by home.social.

  1. GreyNoise At The Edge — April 13–20, 2026. Four themes dominated activity on the GreyNoise sensor network this week — spanning reconnaissance, exploitation attempts, credential brute-forcing, and botnet recruitment.

    1. A broad credential and configuration discovery campaign ran at ~6.2M sessions across hundreds of IPs — ENV files, .git/config, AWS metadata, path traversal, sensitive file access. The biggest real story, distributed rather than concentrated.

    2. VNC scanning surged to the third-most-targeted port on the internet — port 5900 at 17.4M sessions. Not in prior briefs.

    3. A new multi-cloud Masscan framework activated this week. Shared JA3 across a new Poland IP and an existing DigitalOcean Singapore cluster.

    4. VPSVAULT IoT worm weaponized CVE-2025-54322 (Xspeeder SXZOS, CVSS 10.0). CVE-2026-24061 (GNU telnetd, CVSS 9.8, CISA KEV) also in payload.

    Full Report: greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  2. See you in Glasgow for #CyberUK! 🇬🇧

    Find GreyNoise at Booth D2 + catch our talks:
    🗓 Apr 22, 12:20 – Nishawn Smagh
    🗓 Apr 23, 14:30 – Glenn Thorpe III

    Happy Hour @ Golf Fang on Apr 22 ⛳️

    Book 1:1 time: info.greynoise.io/cyberuk-meet

    #CyberSecurity #ThreatIntelligence #GreyNoise

  3. NEW: GreyNoise At The Edge Intel Brief (March 23-30)

    187,998,900 sessions from 100 top source IPs observed by GreyNoise sensors between March 23-30, 2026. Daily volumes surged 4x mid-week — from 8.5M to 36.6M in 72 hours.

    1. VPSVAULT IoT botnet recruitment across 22 CVEs — 3,347,443 sessions from 4 Brazilian IPs targeting Hikvision, MikroTik, TP-Link, D-Link devices. Includes CVE-2026-24061, now on CISA KEV.

    2. VisionHeight fleet of 6 AWS IPs generated 5,892,055 sessions mapping enterprise perimeters across Palo Alto, Sophos, Ivanti, Citrix, F5, and ConnectWise — probing CVE-2024-1709 (CVSS 10.0).

    3. React/Next.js exploit chaining (CVE-2025-55182 + CVE-2025-29927) produced 1,338,336 sessions, with attackers spoofing GoogleBot user-agents to bypass detection.

    4. At least 4 new scanning operations activated simultaneously mid-week, driving the sharp volume surge across the observation period.

    Here's what we found: 🔗 greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  4. 200,886,675 sessions. 101 unique source IPs. March 16–23, 2026.

    GreyNoise At The Edge intelligence brief highlights:

    1. The MEVSPACE RDP brute-force operator returned after a 99.8% infrastructure collapse — single IP generated 7,975,241 sessions before deliberately withdrawing after 4 days. GreyNoise has tracked a surge-withdraw-reconstitute cycle since January 2026, reinforcing that well-resourced operators can reconstitute capacity within days.

    2. Two coordinated campaigns emerged: VPSVAULT.HOST (IoT worm weaponizing 21+ CVEs against 12+ manufacturers) and Omegatech (TLS fingerprint randomization with 5,854 unique JA3s per node).

    3. Sophos CVE-2022-1040 exploitation stabilized at 638,654 sessions in its fifth consecutive week. Enterprise VPN credential pressure reached week 9 across five vendors with 2.9M+ combined sessions.

    4. n8n CVE-2026-21858 (CVSS 10.0) reached 118,086 sessions with links to MuddyWater and ZeroBot. ICS/SCADA reconnaissance expanded with new HMI and PLC vulnerabilities trending.

    🔗 greynoise.io/resources/at-the-

    #ThreatIntel #CyberSecurity #InfoSec #GreyNoise

  5. 52% of RCE attempts came from IPs with no prior GreyNoise history. New research on where edge defenses fall short + what to do about it: greynoise.io/resources/2026-st

    #ThreatIntel #Cybersecurity #GreyNoise

  6. This week's At the Edge: CLEAR is out — a preview of the intel brief GreyNoise customers get every week.

    🔗 greynoise.io/resources/at-the-

    That's just the preview. greynoise.io/contact

    #ThreatIntel #CyberSecurity #GreyNoise

  7. Three campaigns. One has Cobalt Strike ready.

    RDP nearly quadrupled. A botnet picked up a new CVE. And someone built a Kubernetes cluster just to exploit n8n.

    A preview of what GreyNoise customers get every week. Full brief has the IOCs, attribution, and analysis.

    #ThreatIntelligence #InfoSec #GreyNoise #CyberSecurity

  8. We observed a 65% drop in global telnet traffic in a single hour on Jan 14, settling into a sustained 59% reduction. 18 ASNs went silent, 5 countries disappeared, but cloud providers were unaffected.

    Our analysis of 51.2M sessions points to backbone-level port 23 filtering by a North American Tier 1 transit provider.

    🔗 labs.greynoise.io/grimoire/202

    #GreyNoise #ThreatIntel #CyberSecurity #InfoSec

  9. ⚠️ Unlike typical exploits, no buffer overflow or memory corruption needed - just one manipulated environment variable grants root access

    🛡️ Not all Telnet implementations affected - only #GNU inet utils; proprietary versions like #Cisco and #BusyBox are safe

    📊 #GreyNoise threat intelligence reports multiple exploit attempts per hour already detected in the wild

    🔄 Telnet's unencrypted nature makes attacks visible to defenders monitoring plaintext traffic for "-f root" patterns

  10. New on the GreyNoise blog: We borrow from some unexpected fields, enzyme kinetics, species biodiversity models, astrophotography, to understand internet-wide scanning activity and measure what we might be missing.

    greynoise.io/blog/filtering-no

    #GreyNoise #Cybersecurity

  11. GreyNoise analyzed activity targeting exposed Ollama and LLM infrastructure, identifying SSRF abuse attempts and large-scale probing of LLM model endpoints.
    Analysis: greynoise.io/blog/threat-actor
    #GreyNoise #ThreatIntelligence #LLMSecurity

  12. Ransomware starts with reconnaissance: we observed a recent large-scale scanning campaign validating exploitable systems, data that feeds the initial access market and shows up later in real attacks. 🕵️‍♀️

    greynoise.io/blog/christmas-sc

    #GreyNoise #Ransomware #InitialAccess #IAB #Recon

  13. Ransomware starts with reconnaissance: we observed a recent large-scale scanning campaign validating exploitable systems, data that feeds the initial access market and shows up later in real attacks. 🕵️‍♀️

    greynoise.io/blog/christmas-sc

    #GreyNoise #Ransomware #InitialAccess #IAB #Recon

  14. Ransomware starts with reconnaissance: we observed a recent large-scale scanning campaign validating exploitable systems, data that feeds the initial access market and shows up later in real attacks. 🕵️‍♀️

    greynoise.io/blog/christmas-sc

    #GreyNoise #Ransomware #InitialAccess #IAB #Recon

  15. Ransomware starts with reconnaissance: we observed a recent large-scale scanning campaign validating exploitable systems, data that feeds the initial access market and shows up later in real attacks. 🕵️‍♀️

    greynoise.io/blog/christmas-sc

    #GreyNoise #Ransomware #InitialAccess #IAB #Recon

  16. Ransomware starts with reconnaissance: we observed a recent large-scale scanning campaign validating exploitable systems, data that feeds the initial access market and shows up later in real attacks. 🕵️‍♀️

    greynoise.io/blog/christmas-sc

    #GreyNoise #Ransomware #InitialAccess #IAB #Recon

  17. @briankrebs Hi Sir sorry for the disturb. A swift question is it possible to detect such activity via check.labs.greynoise.io/ #greynoise #botnet

    Or does one have to use dedicated scans via wireshark and #shodan and the likes?

  18. GreyNoise IP Check – narzędzie pozwalające sprawdzić adres IP

    Firma GreyNoise, zajmująca się zbieraniem informacji o trwających skanach sieci i próbach wykorzystania podatności, stworzyła narzędzie, które może przydać się każdemu. TLDR: GreyNoise IP Check, bo o nim mowa, pozwala sprawdzić, czy adres IP, którym aktualnie wychodzimy do Internetu, jest widziany jako bezpieczny, czy może zauważono jakieś jego powiązania ze skanowaniem...

    #WBiegu #Awareness #Greynoise #Internet #Ip

    sekurak.pl/greynoise-ip-check-

  19. Just in: Watch #React2Shell exploitation unfold over time in the map below (geo of source IPs attempting to exploit CVE-2025-55182).

    #GreyNoise #ThreatIntel #CVE202555182 #Nextjs #Cybersecurity

  20. Warto tym narzędziem sprawdzić swoją sieć lokalną pod kątem podejrzanych aktywności (botnety, malware, wirusy, itp) a potem dodać do zakładek ✅

    check.labs.greynoise.io/

    #GreyNoise

  21. Headed to BlackHat EU? 🇬🇧
    Swing by the @corelight + GreyNoise booth for a chat and then grab drinks with the team after the con on Wednesday, Dec 10th. Sign up today to reserve your spot!

    🔗 info.greynoise.io/events/black

    #BHEU #Corelight #GreyNoise

  22. Headed to BlackHat EU? 🇬🇧
    Swing by the @corelight + GreyNoise booth for a chat and then grab drinks with the team after the con on Wednesday, Dec 10th. Sign up today to reserve your spot!

    🔗 info.greynoise.io/events/black

    #BHEU #Corelight #GreyNoise

  23. Headed to BlackHat EU? 🇬🇧
    Swing by the @corelight + GreyNoise booth for a chat and then grab drinks with the team after the con on Wednesday, Dec 10th. Sign up today to reserve your spot!

    🔗 info.greynoise.io/events/black

    #BHEU #Corelight #GreyNoise

  24. Headed to BlackHat EU? 🇬🇧
    Swing by the @corelight + GreyNoise booth for a chat and then grab drinks with the team after the con on Wednesday, Dec 10th. Sign up today to reserve your spot!

    🔗 info.greynoise.io/events/black

    #BHEU #Corelight #GreyNoise

  25. Headed to BlackHat EU? 🇬🇧
    Swing by the @corelight + GreyNoise booth for a chat and then grab drinks with the team after the con on Wednesday, Dec 10th. Sign up today to reserve your spot!

    🔗 info.greynoise.io/events/black

    #BHEU #Corelight #GreyNoise

  26. 📢 GreyNoise lance un scanner gratuit pour vérifier si votre IP participe à un botnet
    📝 Source: BleepingComputer — GreyNoise Labs a annoncé « GreyNoise IP Check », un outil gratuit...
    📖 cyberveille : cyberveille.ch/posts/2025-11-2
    🌐 source : bleepingcomputer.com/news/secu
    #GreyNoise #botnet #Cyberveille

  27. We’ve launched At The Edge, a weekly brief for GreyNoise customers highlighting shifts in attacker behavior seen across the Global Observation Grid (GOG).

    Human-led analysis that turns internet noise into insight defenders can act on.

    #ThreatIntel #GreyNoise

  28. We deployed MCP honeypots to understand how threat actors engage with AI middleware exposed to the internet. What we observed was unexpected. Full analysis: greynoise.io/blog/deploying-mc

    #GreyNoise #AI #AISecurity #MCP #MCPSecurity #Cybersecurity #ThreatIntel

  29. GreyNoise has observed a surge in PHP exploitation activity since late summer — now peaking as attackers deploy cryptominers at scale.
    Full analysis → greynoise.io/blog/php-cryptomi
    #GreyNoise #PHP #ThreatIntel

  30. GreyNoise observed a ~500% surge in IPs scanning Palo Alto Networks login portals on October 3, 2025 — the highest level we’ve seen in 90 days. Read our full analysis here 👉 greynoise.io/blog/palo-alto-sc
    #PaloAltoNetworks #PaloAlto #GreyNoise #ThreatIntel #PANOS

  31. 🚨GreyNoise has published a new Situation Report on Cisco ASA reconnaissance activity we observed before the new zero-days were disclosed.

    Read the full report: info.greynoise.io/hubfs/Situat

    #Cisco #ASA #CiscoASA #GreyNoise #ThreatIntel #CVE202520333 #CVE202520362

  32. 🚨GreyNoise has published a new Situation Report on Cisco ASA reconnaissance activity we observed before the new zero-days were disclosed.

    Read the full report: info.greynoise.io/hubfs/Situat

    #Cisco #ASA #CiscoASA #GreyNoise #ThreatIntel #CVE202520333 #CVE202520362

  33. 🚨GreyNoise has published a new Situation Report on Cisco ASA reconnaissance activity we observed before the new zero-days were disclosed.

    Read the full report: info.greynoise.io/hubfs/Situat

    #Cisco #ASA #CiscoASA #GreyNoise #ThreatIntel #CVE202520333 #CVE202520362

  34. 🚨GreyNoise has published a new Situation Report on Cisco ASA reconnaissance activity we observed before the new zero-days were disclosed.

    Read the full report: info.greynoise.io/hubfs/Situat

    #Cisco #ASA #CiscoASA #GreyNoise #ThreatIntel #CVE202520333 #CVE202520362