GreyNoise

greynoise.io

Imported from official source

GreyNoise — publications from its own official source.

Type
Company
Scope
US · national
Website
greynoise.io
Feed
Atom

Publications 27

  1. Swarming Against Citrix 0-Day Exploitation

    On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for t...

  2. Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation

    GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We detail a few of the more notable ...

  3. Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

    11 organizations compromised in 26 seconds. GreyNoise breaks down the AI-enabled campaign against PaperCut that hit 440 instances across 48 countries.

  4. GreyNoise + CrowdStrike: Real-Time Edge Intelligence in Falcon Next-Gen SIEM and Charlotte Agentic SOAR

    Today we’re announcing an expanded integration between GreyNoise and the CrowdStrike Falcon® platform, with new content for CrowdStrike Falcon® Next-Gen SIEM and CrowdStrike Charlotte Agentic SOAR....

  5. Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets

    GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies, using forged user agents while requesting the files where misconfigur...

  6. A New Way to Navigate GreyNoise

    Today, we’re introducing a redesigned GreyNoise Visualizer that makes it easier to navigate those capabilities and brings related workflows together in one place.

  7. GreyNoise Welcomes New SVP of Adversary Operations

    Former Google Threat Intelligence leader joins GreyNoise as SVP of Adversary Operations to advance proactive discovery and disruption of cyber threats.

  8. Introducing Tactics: See What Adversaries Do After They’re Inside

    GreyNoise Tactics gives anyone running a Deception Sensor visibility into what adversaries do after initial compromise, automatically mapping qualifying sessions to the MITRE ATT&CK framework.

  9. Enhanced Detection Engineering at Scale in the Agentic Era

    Check out GreyNoise's new Head of Adversary Engagement, Mark Mager, on why traditional detection engineering can't keep pace with CVE growth — and the agentic pipeline replacing it.

  10. Now Available: Intelligence Dashboard in the GreyNoise Platform

    With the new Intelligence Dashboard, pin any combination of CVEs, tags, countries, IPs, and GNQL queries into one persistent, always-current view.

  11. Now Available: The Threat Brief Library in the GreyNoise Platform

    GreyNoise's Threat Brief Library is now live in the Visualizer — browse, search, filter, and download weekly At The Edge briefs, Executive Situation Reports, and more, all built on primary-source s...

  12. 5 Things I Show Every SOC Team When We Wire GreyNoise Into Their SOAR

    Your playbooks move fast, but GreyNoise helps them move smarter. Here are five ways GreyNoise drives better decisions in SOAR.

  13. 4 Ways GreyNoise Improves SOC Outcomes

    Learn four practical ways GreyNoise improves SOC outcomes—from reducing alert volume and surfacing targeted threats to identifying compromised hosts.

  14. The Coverage Gap: Why Your Blocklist Is Missing 119,000 Malicious IPs Today

    GreyNoise compared 119,842 malicious IPs against 11 major threat feeds. The average coverage: just 2%, exposing the limits of static blocklists.

  15. A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400

    A new SonicWall scanning surge mirrors the pattern that preceded CVE-2026-0400. GreyNoise details the activity and what defenders should watch.

  16. Project Swarm: Join the Collective. Defend the Edge

    Today, we're launching Project Swarm — a research initiative that opens the GreyNoise deception platform to the global security community. Project Swarm transforms GreyNoise from a proprietary sens...

  17. The Internet Changes Before the Advisory Drops

    Before Cisco disclosed a CVSS 10.0 zero-day, GreyNoise sensors had already observed eight surges of targeting activity compressing from 39 days to 2 days. A new study finds this pattern repeated ac...

  18. Just 21 IP Addresses Are Now Behind Nearly Half of All RDP Scanning on the Internet

    GreyNoise uncovers a concentrated RDP scanning campaign, revealing infrastructure patterns, rapid traffic shifts that impact detection, and recommendations for defenders.

  19. Introducing C2 Detection: Know When Your Edge Devices Are Calling Home to Attackers

    We're launching C2 Detection — a new GreyNoise intelligence module that gives you two distinct, high-confidence signals that a device in your environment has been compromised.

  20. The Invisible Army: Why IP Reputation Fails Against the Rotation Economy

    Attackers route malicious traffic through ordinary home internet connections — and to a reputation feed, the source IP is indistinguishable from a legitimate user's connection. GreyNoise analyzed 4...

  21. Ghost Fleet: Half of All New Scanning IPs Last Week Geolocated to Hong Kong — Nearly None Completed a Connection

    Last week, the GreyNoise Observation Grid observed something unusual: 242,666 new scanning IPs geolocating to Hong Kong appeared in seven days and 99.7% of them never completed a single TCP connect...

  22. GreyNoise Integrates with Google Security Operations to Enhance Detection and Response Capabilities

    GreyNoise's integration with Google Security Operations delivers standardized indicator ingestion, pre-built dashboards, YARA-L detection rules, saved searches, response actions, webhook support, a...

  23. GreyNoise Intelligence Is Available Across the CrowdStrike Falcon Platform

    GreyNoise intelligence is now available across the CrowdStrike Falcon platform, bringing internet-wide scanning context to SIEM queries, SOAR workflows, and AI-driven triage.

  24. Active Reconnaissance Campaign Targets SonicWall Firewalls Through Commercial Proxy Infrastructure

    84,000+ scanning sessions targeting SonicWall SonicOS infrastructure in four days. GreyNoise details a coordinated reconnaissance campaign using rotating proxy infrastructure.

  25. 2026 GreyNoise State of the Edge Report: Where Attacks Concentrate and Defenses Fall Short

    GreyNoise analyzed 2.97 billion malicious sessions over 162 days — and the patterns challenge assumptions about where edge defenses are strongest. From VPN targeting to infrastructure concentration...

  26. Reconnaissance Has Begun for the New BeyondTrust RCE (CVE-2026-1731): Here's What We See So Far

    A PoC for CVE-2026-1731 hit GitHub on Feb 10. Within 24 hours, GreyNoise observed reconnaissance probing for vulnerable BeyondTrust instances.

  27. Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere

    The GreyNoise Global Observation Grid observed active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, and 83% of that exploitation traces to a single IP address on bull...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.