GreyNoise
greynoise.io
Imported from official source
GreyNoise — publications from its own official source.
- Type
- Company
- Scope
- US · national
- Website
- greynoise.io
- Feed
- Atom
Publications 27
-
Swarming Against Citrix 0-Day Exploitation
On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for t...
-
Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We detail a few of the more notable ...
-
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
11 organizations compromised in 26 seconds. GreyNoise breaks down the AI-enabled campaign against PaperCut that hit 440 instances across 48 countries.
-
GreyNoise + CrowdStrike: Real-Time Edge Intelligence in Falcon Next-Gen SIEM and Charlotte Agentic SOAR
Today we’re announcing an expanded integration between GreyNoise and the CrowdStrike Falcon® platform, with new content for CrowdStrike Falcon® Next-Gen SIEM and CrowdStrike Charlotte Agentic SOAR....
-
Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets
GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies, using forged user agents while requesting the files where misconfigur...
-
A New Way to Navigate GreyNoise
Today, we’re introducing a redesigned GreyNoise Visualizer that makes it easier to navigate those capabilities and brings related workflows together in one place.
-
GreyNoise Welcomes New SVP of Adversary Operations
Former Google Threat Intelligence leader joins GreyNoise as SVP of Adversary Operations to advance proactive discovery and disruption of cyber threats.
-
Introducing Tactics: See What Adversaries Do After They’re Inside
GreyNoise Tactics gives anyone running a Deception Sensor visibility into what adversaries do after initial compromise, automatically mapping qualifying sessions to the MITRE ATT&CK framework.
-
Enhanced Detection Engineering at Scale in the Agentic Era
Check out GreyNoise's new Head of Adversary Engagement, Mark Mager, on why traditional detection engineering can't keep pace with CVE growth — and the agentic pipeline replacing it.
-
Now Available: Intelligence Dashboard in the GreyNoise Platform
With the new Intelligence Dashboard, pin any combination of CVEs, tags, countries, IPs, and GNQL queries into one persistent, always-current view.
-
Now Available: The Threat Brief Library in the GreyNoise Platform
GreyNoise's Threat Brief Library is now live in the Visualizer — browse, search, filter, and download weekly At The Edge briefs, Executive Situation Reports, and more, all built on primary-source s...
-
5 Things I Show Every SOC Team When We Wire GreyNoise Into Their SOAR
Your playbooks move fast, but GreyNoise helps them move smarter. Here are five ways GreyNoise drives better decisions in SOAR.
-
4 Ways GreyNoise Improves SOC Outcomes
Learn four practical ways GreyNoise improves SOC outcomes—from reducing alert volume and surfacing targeted threats to identifying compromised hosts.
-
The Coverage Gap: Why Your Blocklist Is Missing 119,000 Malicious IPs Today
GreyNoise compared 119,842 malicious IPs against 11 major threat feeds. The average coverage: just 2%, exposing the limits of static blocklists.
-
A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400
A new SonicWall scanning surge mirrors the pattern that preceded CVE-2026-0400. GreyNoise details the activity and what defenders should watch.
-
Project Swarm: Join the Collective. Defend the Edge
Today, we're launching Project Swarm — a research initiative that opens the GreyNoise deception platform to the global security community. Project Swarm transforms GreyNoise from a proprietary sens...
-
The Internet Changes Before the Advisory Drops
Before Cisco disclosed a CVSS 10.0 zero-day, GreyNoise sensors had already observed eight surges of targeting activity compressing from 39 days to 2 days. A new study finds this pattern repeated ac...
-
Just 21 IP Addresses Are Now Behind Nearly Half of All RDP Scanning on the Internet
GreyNoise uncovers a concentrated RDP scanning campaign, revealing infrastructure patterns, rapid traffic shifts that impact detection, and recommendations for defenders.
-
Introducing C2 Detection: Know When Your Edge Devices Are Calling Home to Attackers
We're launching C2 Detection — a new GreyNoise intelligence module that gives you two distinct, high-confidence signals that a device in your environment has been compromised.
-
The Invisible Army: Why IP Reputation Fails Against the Rotation Economy
Attackers route malicious traffic through ordinary home internet connections — and to a reputation feed, the source IP is indistinguishable from a legitimate user's connection. GreyNoise analyzed 4...
-
Ghost Fleet: Half of All New Scanning IPs Last Week Geolocated to Hong Kong — Nearly None Completed a Connection
Last week, the GreyNoise Observation Grid observed something unusual: 242,666 new scanning IPs geolocating to Hong Kong appeared in seven days and 99.7% of them never completed a single TCP connect...
-
GreyNoise Integrates with Google Security Operations to Enhance Detection and Response Capabilities
GreyNoise's integration with Google Security Operations delivers standardized indicator ingestion, pre-built dashboards, YARA-L detection rules, saved searches, response actions, webhook support, a...
-
GreyNoise Intelligence Is Available Across the CrowdStrike Falcon Platform
GreyNoise intelligence is now available across the CrowdStrike Falcon platform, bringing internet-wide scanning context to SIEM queries, SOAR workflows, and AI-driven triage.
-
Active Reconnaissance Campaign Targets SonicWall Firewalls Through Commercial Proxy Infrastructure
84,000+ scanning sessions targeting SonicWall SonicOS infrastructure in four days. GreyNoise details a coordinated reconnaissance campaign using rotating proxy infrastructure.
-
2026 GreyNoise State of the Edge Report: Where Attacks Concentrate and Defenses Fall Short
GreyNoise analyzed 2.97 billion malicious sessions over 162 days — and the patterns challenge assumptions about where edge defenses are strongest. From VPN targeting to infrastructure concentration...
-
Reconnaissance Has Begun for the New BeyondTrust RCE (CVE-2026-1731): Here's What We See So Far
A PoC for CVE-2026-1731 hit GitHub on Feb 10. Within 24 hours, GreyNoise observed reconnaissance probing for vulnerable BeyondTrust instances.
-
Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere
The GreyNoise Global Observation Grid observed active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, and 83% of that exploitation traces to a single IP address on bull...