Glenn

@ntkramer.bsky.social

Elder Millennial | 💼 Cybersecurity | I ask 'why?' a lot | Pro Oxford Comma | Fix it! | He/Him | #BLM | Views are my own.

I’ll be at Black Hat / DEF CON next month, so DM me if you want to meet up! I’ve lost count of how many I’ve been to now (actually it'd be depressing to know). As logistically chaotic as the week is, it’s always worth it to catch up with old friends and make new ones. 1/2

It seems that CISA is, in fact, shortening the time-to-fix for vulns added to the KEV of late. (Casual reminder that the KEV should not be used as "what we should patch" but it is a signal worth watching for awareness). #threatintel

BildBild

Big day! Today I start at Censys leading Applied AI, Intelligence (A²I²?). Threat hunting is getting a major upgrade with what we’re scheming. Stay tuned…

Bittersweet yet exciting transition ahead. This week marks my last at GreyNoise. Lately I've spent a lot of time thinking about what I value most in this field: research and findings grounded in clarity, integrity, actionability, and truth that drives outcomes. #TheSignalShift

Excited to share that I've been asked to speak at the Minorities in Cybersecurity Conference this March! I’ll be on a panel “How Do You Define Cybersecurity Experience? A Change in Perspective” where we’ll dig into what really counts as cybersecurity experience

🍩 & #threatintel - 95% of exploitation attempts targeting CVE-2026-20045, a critical vulnerability in Cisco Unified Communications Manager, have used a distinctive user-agent: Mozilla/5.0 (compatible; CiscoExploit/1.0) and are heavily targeting our Cisco Unified Communications Manager sensors. 1/2

Bild

CISA's KEV hit 1,500 yesterday. I'm working on a cool #threatintel blog (yes, I'm biased) about additional hidden intel in KEV that should be published soon, along with a helpful tool hosted by GreyNoise! :)

☕ & #threatintel: CISA has moved the due date for mitigating CVE-2025-55182 (Meta React Server Components Remote Code Execution Vulnerability) up by two weeks. It was initially set for December 26, but it is now due on December 12. 1/2

Bild

We all know that @hrbrmstr.dev is a mad scientist, and when you give him the amazing telemetry our new fleet has been collecting lately, you get knowledge drops like this! Super proud of our @greynoise.io team’s work on the deception capabilities we now have! hashtag#threatintel

GreyNoise@greynoise.io · last yr.

🚨 New Research: GreyNoise identifies an early warning signal, spikes in attacker activity tend to precede new CVE disclosures within six weeks. Which vendors show the strongest signal and more, all in our latest report ⬇️

🫖 & #threatintel - noticing a few other spikes orgs should be mindful of: 🔥 CVE-2025-49132 (Pterodactyl Panel RCE) (10/10 RCE) ⚡ CVE-2024-20439 (Cisco Smart Licensing Utility) (9.8/10, KEV) 📝 CVE-2017-18370 (Zyxel P660HN) 1/4

Just a totally normal trip home from the airport last night… passing the national guard rolling down the highway as they prepare for NO KINGS DAY protests. F this administration. About 3 more months before they start trying to censor social media via tech controls.

If you're ever feeling lonely, just close Zoom. This works because a funny thing always happens: a random last-minute Zoom will appear if you close it completely.

This change legitimately pisses me off. TL;DR—They appear to be removing RSS for KEV alerts and moving them to email or X. They gave orgs 0 days to prepare. RSS is already a thing. The emails arrive many hours later. X is NOT a gov website(!); it even warns you when you click their link! 1/2

Bild