Four findings this period, one shared exposure pattern: each involves a system that holds credentials or files for a secondary environment, so a successful attempt against one would likely open the next without a second exploit. In GreyNoise data this […] [Original post on infosec.exchange]
GreyNoise
@greynoise.infosec.exchange.ap.brid.gy
GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats […] [bridged from https://infosec.exchange/@greynoise on the fediverse by https://fed.brid.gy/ ]
This week in GreyNoise data, rented crawlers probed for credentials and configuration secrets across widely deployed web software. A matched pair of crawlers sharing one client fingerprint probed NGINX UI (CVE-2026-27944) and LiteSpeed Cache […] [Original post on infosec.exchange]
New in the GreyNoise Visualizer: the Intelligence Dashboard. Most mornings start the same way, rerunning the same CVE, tag, and country searches to see what moved overnight. The Intelligence Dashboard replaces that routine. Build one saved view of the […] [Original post on infosec.exchange]
The June NoiseLetter is live! In this edition, we're diving into GreyNoise use cases, sharing the latest product releases, and getting ready for our biggest event of the year, NoiseFest. 🔗 https://www.greynoise.io/resources/noiseletter-june-2026
The Threat Brief Library is now live in the GreyNoise Visualizer! Browse, search, filter, and download weekly At The Edge briefs, Executive Situation Reports, and more. All built on primary-source data from our global sensor network. Check it out: https://www.greynoise.io/blog/threat-brief-library
NoiseFest is just a few weeks away!🎉 If you're in Las Vegas for #BlackHat or #DEFCON, come join us for a night of cold drinks, good company, and 60s and 70s vibes. 🏵️ 📅Thursday, August 6th | 6–9 PM PT | Las Vegas 🔗RSVP […] [Original post on infosec.exchange]
This week a long-dormant Palo Alto flaw came back to life in GreyNoise data. GlobalProtect CVE-2019-1579 (unauth RCE, CISA KEV) drew only isolated activity through late June, then more than 120 malicious hosts probed it on 06 July, almost all from a single […] [Original post on infosec.exchange]
Four things that caught our eye at the edge this week: Following the FortiBleed reporting, GreyNoise is providing telemetry on the same Fortinet surfaces, without attributing the activity; the SSL VPN brute-force we track stood down in early June. Cisco SSL […] [Original post on infosec.exchange]
Three things that caught our eye at the edge this week: - One host mapped the enterprise edge. - A pair ran a Hikvision camera RCE (CISA KEV) on shared tooling. - VPN logins stayed under steady pressure. Defend on behavior, not IPs. This week's At The Edge […] [Original post on infosec.exchange]
We're in London tomorrow for @crowdstrike #CrowdTour2026. If you're attending our team would love to connect! Schedule some time to meet with us: https://info.greynoise.io/crowdtour-2026-meet #CyberSecurity #GreyNoise #ThreatIntel
GreyNoise At The Edge Intel Brief | June 1-8, 2026 This week's story: credential attacks on the front door of remote access, not new vulnerabilities. 🔗 https://www.greynoise.io/resources/at-the-edge-clear-060826 1. A single Netherlands host (94.102.49.82 […] [Original post on infosec.exchange]
NoiseFest is BACK 🎉 We're throwing our 4th annual party during Black Hat / DEF CON 2026 with a 60s and 70s theme 🏵️🎸✌️. Cold drinks, new connections, and stories from the front lines of cybersecurity at House of Blues B-Side in Las Vegas. 🔗RSVP […] [Original post on infosec.exchange]
Less noise. Better signal. Faster response. We break down 4 ways GreyNoise helps SOC teams cut through internet background noise and focus on what actually matters: https://www.greynoise.io/blog/ways-greynoise-improves-soc-outcomes
The May NoiseLetter is live! Early warning signals, blocklist gaps, and a SonicWall spike that echoes the pattern that preceded a CVE: https://www.greynoise.io/resources/noiseletter-may-2026
GreyNoise At The Edge (May 19–26, 2026): a week of rented-infrastructure reconnaissance against the internet's edge — routers, VPN gateways, container planes, and embedded devices, probed in parallel. 1. A long-running MikroTik RouterOS brute-force […] [Original post on infosec.exchange]
Got questions? We've got answers. Tune in tomorrow at 12 ET for GreyNoise University LIVE! 📺 https://www.greynoise.io/events/greynoise-university-live
Your blocklist is probably missing 98% of what's actively hitting your edge right now. We tested 11 major feeds against 119,842 malicious IPs GreyNoise observed on a single day. The best feed covered less than 5%. Most were under 2%. The feeds aren't broken […] [Original post on infosec.exchange]
A scanning pattern similar to the one preceding CVE-2026-0400 in February is active again. May 12 saw the largest single-day session volume on this SonicWall tag in 90 days. 🔗 […] [Original post on infosec.exchange]
The mission: make sure no attack works twice. 🚀 We're hiring a Detection Engineer and a Federal Customer Success Manager to help us get there. Remote-friendly, high-impact, great benefits. Sound like you? 👇 https://www.greynoise.io/careers
May the 4th be with you + so be the signal. 🚀 The April Noiseletter is live: Project Swarm is open to the global security community, new research drops, and a packed events calendar. Let's get into it. 👇 https://www.greynoise.io/resources/noiseletter-april-2026
NoiseLetter April 2026
Get GreyNoise updates! Read the April 2026 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.
greynoise.io
GreyNoise University LIVE: https://www.greynoise.io/events/greynoise-university-live The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse Webinar: https://info.greynoise.io/webinar/invisible-army?_ga=2.231440415.1063083880.1777487534-981227823.1753375781
We're so back, after taking last month off, we are refreshed + ready for April's GreyNoise University LIVE!! 📺 Tune in TOMORROW at 12 ET! https://www.greynoise.io/events/greynoise-university-live
Introducing Project Swarm: a research initiative to defend the network edge and we're inviting you to join. Deploy a sensor on your infrastructure, capture real attacker traffic + compare what's hitting you to the GreyNoise global baseline. Join today! 🐝
Residential proxies, sleep cycles, and 4 BILLION sessions 👀 Join us Thursday, April 30th at 2pm ET to see why IP reputation is broken against home traffic + what actually works instead. Save your spot now 👇https://info.greynoise.io/webinar/invisible-army
Webinar - The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse
This webinar presents the full findings of the latest report on residential proxy abuse — why IP reputation is structurally broken against this traffic, behavioral patterns consistent with compromised home PCs following the human sleep cycle, and what four separate threats hiding behind one label mean for detection strategy.
info.greynoise.io
GreyNoise At The Edge — April 13–20, 2026. Four themes dominated activity on the GreyNoise sensor network this week — spanning reconnaissance, exploitation attempts, credential brute-forcing, and botnet recruitment. 1. A broad credential and configuration discovery campaign ran at ~6.2M […]
Original post on infosec.exchange
infosec.exchange
11 hosting ASNs appeared in pre-disclosure surges across 3+ vendor families. When targeting concentrates, lead time drops from 21 days to 7.5. The infrastructure behind these surges is recognizable. https://www.greynoise.io/resources/ten-days-before-zero
Ten Days Before Zero: How Activity Surges in GreyNoise Data Precede Vulnerability Disclosure
Attackers are moving before disclosures. GreyNoise shows how surge activity can signal vulnerabilities days before CVEs are published.
greynoise.io
See you in Glasgow for #CyberUK! 🇬🇧 Find GreyNoise at Booth D2 + catch our talks: 🗓 Apr 22, 12:20 – Nishawn Smagh 🗓 Apr 23, 14:30 – Glenn Thorpe III Happy Hour @ Golf Fang on Apr 22 ⛳️ Book 1:1 time: https://info.greynoise.io/cyberuk-meet-with-us #CyberSecurity #ThreatIntelligence #GreyNoise
CyberUK| Meet With Us | GreyNoise Intelligence
GreyNoise is proud to be a sponsor and speaker at this years CyberUK conference. Here are all the different ways you can engage with GreyNoise during the event.
info.greynoise.io
Atlanta!!! 🍑 We will be in town for the CrowdStrike #CrowdTour this week + we're kicking things off early with a Happy Hour TOMORROW! Come hang out with us from 4-6 at the Blue Moon Brewery & Grill. 🍻 https://info.greynoise.io/event/happy-hour-atlanta
GreyNoise | Happy Hour Atlanta
We’re leaving the slide decks and sales pitches at the office in favor of cold beers and genuine conversation. Join us to unwind, talk shop (or not), and enjoy a relaxed evening with your Atlanta peers.
info.greynoise.io
The internet changes before the advisory drops. New from GreyNoise: activity surges preceded 33 CVEs across 16 vendor families with a median 11-day lead. The pattern holds up to rigorous testing. https://www.greynoise.io/resources/ten-days-before-zero
Ten Days Before Zero: How Activity Surges in GreyNoise Data Precede Vulnerability Disclosure
Attackers are moving before disclosures. GreyNoise shows how surge activity can signal vulnerabilities days before CVEs are published.
greynoise.io
39% of IPs targeting the edge are residential. Geolocation catches 0% of them. We analyzed 4 billion sessions and the findings break A LOT of assumptions. Join us April 30 at 2 PM ET as we unpack what's really hiding in your traffic. 👉 https://info.greynoise.io/webinar/invisible-army
Webinar - The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse
This webinar presents the full findings of the latest report on residential proxy abuse — why IP reputation is structurally broken against this traffic, behavioral patterns consistent with compromised home PCs following the human sleep cycle, and what four separate threats hiding behind one label mean for detection strategy.
info.greynoise.io