This week in GreyNoise data, rented crawlers probed for credentials and configuration secrets across widely deployed web software. Customers get the full weekly brief. Our public At The Edge Clear one-pager: www.greynoise.io/resources/at...
GreyNoise
@greynoise.io
GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats.
New in the GreyNoise Visualizer: the Intelligence Dashboard. Build one saved view of the threats you actually track, then watch it stay current on its own. Read the launch blog: greynoise.io/blog/intelli...
The June NoiseLetter is live! In this edition, we're diving into GreyNoise use cases, sharing the latest product releases, and getting ready for our biggest event of the year, NoiseFest.
NoiseLetter June 2026
In this edition, we're diving into GreyNoise use cases, sharing the latest product releases, and getting ready for our biggest event of the year, NoiseFest.
greynoise.io
The Threat Brief Library is now live in the GreyNoise Visualizer! Browse, search, filter, and download weekly At The Edge briefs, Executive Situation Reports, and more. All built on primary-source data from our global sensor network. Check it out: www.greynoise.io/blog/threat-...
NoiseFest is just a few weeks away!🎉 If you're in Las Vegas for #BlackHat or #DEFCON, come join us for a night of cold drinks, good company, and 60s and 70s vibes. 🏵️ 📅Thursday, August 6th | 6–9 PM PT | Las Vegas 🔗RSVP: info.greynoise.io/events/black... #NoiseFest #GreyNoise #cybersecurity
GreyNoise - NoiseFest at BlackHat 2026
Join us for NoiseFest at BlackHat/DEFCON on Thursday, August 6th. Enjoy drinks, snacks, and engaging conversations with your peers. RSVP now!
info.greynoise.io
This week a long-dormant Palo Alto flaw came back to life in GreyNoise data. Separately, two coordinated hosting fleets ran the week's highest-volume web exploitation, roughly 7.5M connection attempts. 🔗https://www.greynoise.io/resources/at-the-edge-clear-070626
Three things that caught our eye at the edge this week: - One host mapped the enterprise edge. - A pair ran a Hikvision camera RCE (CISA KEV) on shared tooling. - VPN logins stayed under steady pressure. This week's At The Edge Clear 👉 www.greynoise.io/resources/at...
We're in London tomorrow for CrowdStrike #CrowdTour2026. If you're attending our team would love to connect! Schedule some time to meet with us: info.greynoise.io/crowdtour-20... #CyberSecurity #GreyNoise #ThreatIntel
GreyNoise At The Edge Intel Brief (June 1-8, 2026) This week attackers went after the front door of remote access — RDP, SSL VPN, router management — not new CVEs. 🔗 www.greynoise.io/resources/at...
NoiseFest is BACK 🎉 We're throwing our 4th annual party during Black Hat / DEF CON 2026 with a 60s and 70s theme 🏵️🎸✌️. Cold drinks, new connections, and stories from the front lines of cybersecurity at House of Blues B-Side in Las Vegas. #BlackHat #DEFCON #NoiseFest #GreyNoise #cybersecurity
GreyNoise - NoiseFest at BlackHat 2025
Join us for NoiseFest at BlackHat/DEFCON on Thursday, August 6th. Enjoy drinks, snacks, and engaging conversations with your peers. RSVP now!
info.greynoise.io
Less noise. Better signal. Faster response. New blog breaks down 4 ways GreyNoise helps SOC teams cut through internet background noise and focus on what actually matters: www.greynoise.io/blog/ways-gr... #CyberSecurity #ThreatIntel #SOC #GreyNoise
4 Ways GreyNoise Improves SOC Outcomes
Learn four practical ways GreyNoise improves SOC outcomes—from reducing alert volume and surfacing targeted threats to identifying compromised hosts.
greynoise.io
The May NoiseLetter is live! Early warning signals, blocklist gaps, and a SonicWall spike that echoes the pattern that preceded a CVE: www.greynoise.io/resources/no...
NoiseLetter May 2026
Get GreyNoise updates! Read the May 2026 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.
greynoise.io
The week's signal: a long-running MikroTik RouterOS brute-force operation (VPSVAULT, AS215925) reversed a multi-week decline — adding a second node and climbing back to ~1.9M sessions against the management API. Rented infrastructure, inventorying the edge. 🔗 www.greynoise.io/resources/at...
We're in Toronto for CrowdStrike #CrowdTour2026 tomorrow, May 28th! Attending the event or local to the area? We'd love to connect. Book time with our team: info.greynoise.io/crowdtour-20...
Got questions? We've got answers. Tune in tomorrow at 12 ET for GreyNoise University LIVE! 📺
GreyNoise University LIVE
greynoise.io
We measured 11 major IP blocklists against 119,842 malicious IPs we observed on one day. The best feed covered less than 5%. Most were under 2%. Your blocklist isn't broken. It was built for a slower threat landscape. Full breakdown ⬇️
The Coverage Gap: Why Your Blocklist Is Missing 119,000 Malicious IPs Today
GreyNoise compared 119,842 malicious IPs against 11 major threat feeds. The average coverage: just 2%, exposing the limits of static blocklists.
greynoise.io
A scanning pattern similar to the one preceding CVE-2026-0400 in February is active again. May 12 saw the largest single-day session volume on this SonicWall tag in 90 days. #GreyNoise #ThreatIntel #SonicWall
A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400
A new SonicWall scanning surge mirrors the pattern that preceded CVE-2026-0400. GreyNoise details the activity and what defenders should watch.
greynoise.io
GreyNoise enrichment is now built into #IOC Insight Cards so you get behavioral signals, classification data, and validated #OSINT from 10,000+ #CTI sources, in one place. feedly.com/new-features...
The mission: make sure no attack works twice. 🚀 We're hiring a Detection Engineer and a Federal Customer Success Manager to help us get there. Remote-friendly, high-impact, great benefits. Sound like you? 👇 www.greynoise.io/careers
May the 4th be with you + so be the signal. 🚀 The April Noiseletter is live: Project Swarm is open to the global security community, new research drops, and a packed events calendar. Let's get into it. 👇
NoiseLetter April 2026
Get GreyNoise updates! Read the April 2026 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.
greynoise.io
Today's the perfect day for a matinee double feature: GreyNoise University LIVE: www.greynoise.io/events/greyn... The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse Webinar: info.greynoise.io/webinar/invi...
We're so back, after taking last month off, we are refreshed + ready for April's GreyNoise University LIVE!! 📺 Tune in TOMORROW at 12 ET! www.greynoise.io/events/greyn...
GreyNoise University LIVE
greynoise.io
Introducing Project Swarm: a research initiative to defend the network edge and we're inviting you to join. Deploy a sensor on your infrastructure, capture real attacker traffic + compare what's hitting you to the GreyNoise global baseline. Join today! 🐝
Residential proxies, sleep cycles, and 4 BILLION sessions 👀 Join us Thursday, April 30th at 2pm ET to see why IP reputation is broken against home traffic + what actually works instead. Save your spot now 👇
Webinar - The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse
This webinar presents the full findings of the latest report on residential proxy abuse — why IP reputation is structurally broken against this traffic, behavioral patterns consistent with compromised...
info.greynoise.io
GN At The Edge: 4 themes dominated activity on our sensor network: recon, exploitation, brute-force, + botnet recruitment. Top story: a broad credential and configuration discovery campaign with ~6.2M sessions across hundreds of IPs hunting exposed .env, .git, AWS metadata, + path traversal.
At The Edge Clear: April 13 - 20, 2026
This week's report covers credential discovery, VNC exposure, and a new multi-cloud scanning framework.
greynoise.io
11 hosting ASNs appeared in pre-disclosure surges across 3+ vendor families. When targeting concentrates, lead time drops from 21 days to 7.5. The infrastructure behind these surges is recognizable.
Ten Days Before Zero: How Activity Surges in GreyNoise Data Precede Vulnerability Disclosure
Attackers are moving before disclosures. GreyNoise shows how surge activity can signal vulnerabilities days before CVEs are published.
greynoise.io
My team at @greynoise.io is hiring a Junior Detection Engineer - somebody who understands network traffic and can write detection rules. Hit me up if you have any questions! job-boards.greenhouse.io/greynoiseint...
Detection Engineer
United States (Remote)
job-boards.greenhouse.io
See you in Glasgow for #CyberUK! 🇬🇧 Find GreyNoise at Booth D2 + catch our talks: 🗓 Apr 22, 12:20 – Nishawn Smagh 🗓 Apr 23, 14:30 – Glenn Thorpe III Happy Hour @ Golf Fang on Apr 22 ⛳️ Book 1:1 time: info.greynoise.io/cyberuk-meet... #CyberSecurity #ThreatIntelligence #GreyNoise
CyberUK| Meet With Us | GreyNoise Intelligence
GreyNoise is proud to be a sponsor and speaker at this years CyberUK conference. Here are all the different ways you can engage with GreyNoise during the event.
info.greynoise.io
Atlanta!!! 🍑 We will be in town for the CrowdStrike #CrowdTour this week + we're kicking things off early with a Happy Hour TOMORROW! Come hang out with us from 4-6 at the Blue Moon Brewery & Grill. 🍻
GreyNoise | Happy Hour Atlanta
We’re leaving the slide decks and sales pitches at the office in favor of cold beers and genuine conversation. Join us to unwind, talk shop (or not), and enjoy a relaxed evening with your Atlanta peer...
info.greynoise.io