posting my ass off on linkedin is sick but there's like mad gay dudes coming out woodwork. sick but, you know, dawg
Andrew Morris
@andrewmorr.is
🔳 founder of @greynoise.io. computers, networks, technology enthusiast. big goober.
We had the good fortune of having @andrewmorr.is in the SOC for most of the day learning up the kids!
I am absolutely POSTING on linkedin now btw. It's like bluesky but nobody is funny and I can write like five million characters per post.
We're aware of the regrettably easy-to-exploit telnetd auth bypass and are preparing a tag for it in @greynoise.io
wiring my house up with fiber and I'm insanely humbled by my complete lack of even the most basic concepts. LC??? OM3???? multi mode???
asked claude to fix a VM that doesn't have internet or network access and its screenshotting and reading the terminal and using qm sendkeys to the proxmox host via SSH to fix it. that goes kinda hard.
waking up at 4am and hitting Bitchat #dj (all of america) with a "gm" text. three users active. no response.
All internet traffic from Iran ceased in @greynoise.io one hour ago. Tier 1 dropped off two hours ago.
between the ~1,400 networks we've seen exploiting React2Shell (CVE-2025-55182) we've captured about 100 different distinct malware payloads. Lots of vibe coded slop, coin miners, chinese comments, mirai variants, etc. hit us up if you're tracking this and want deets research@greynoise.io
TL;DR a couple hundred IPs suddenly started exploiting Cisco devices today - Entire exploitation cluster is originating from OVH (@ovhcloudus.bsky.social). - Payloads are interesting- attacker is even checking hardware temperatures most likely to ensure they are not honeypots
Also please be aware if your org runs a lot of Cisco gear we're seeing a very large spike in exploitation against Cisco devices right now.
Also please be aware if your org runs a lot of Cisco gear we're seeing a very large spike in exploitation against Cisco devices right now.
Lots of React4Shell in @greynoise.io. Visualization a la @hrbrmstr.dev
The @hrbrmstr.dev himself has an entire web page of these stats he's keeping up to date if you want to keep an eye on them btw: rud.is/r2s/r2s.html
r2s
rud.is
React2Shell exploitation frequency in GreyNoise dec 5-dec 6
React Server CVE-2025-55182 popping off in @greynoise.io right now. Blog from @hrbrmstr.dev up: www.greynoise.io/blog/cve-202...
one thing about me is that I love windows. the building fixture. not the operating system.
Shamlessly reposting from elsewhere- you can easily communicate between Linux VMs and guests using VSOCK (man7.org/linux/man-pa...). Here's some silly examples of bidirectional chat btwn host & guest using Socat. Or connecting via SSH to my home router from the VM without TCP/IP. No code required.
on the surface this appears to be a massive credential stuffing campaign against Palo Alto's. please audit your successful logins and enable MFA. good catch @remyhax.bsky.social www.greynoise.io/blog/palo-al...
Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High
GreyNoise has identified a significant escalation in malicious activity targeting Palo Alto Networks GlobalProtect portals. Beginning on 14 November 2025, activity rapidly intensified, culminating in ...
greynoise.io
People always make fun of me for being polite to LLMs and I like to joke that I want to be on the good side of the robots when they take over the world. But really it just feels like a nasty habit to reinforce being an asshole on the computer. Unless we're playing Modern Warfare and you're 12.
POV you're my new 42U server rack in the garage and I just turned the lights off and saw your lights blinking in the dark for the first time
did you know you can quickly figure out if an ethernet port/cable supports PoE by putting it on your lips and feeling whether it electrocutes you or not
We've hired Colonel Shawn Smagh to up our @greynoise.io intel reporting game and we've started producing weekly intelligence briefs. This week's is a banger.