The Coverage Gap: Why Your Blocklist Is Missing 119,000 Malicious IPs Today

Imported from official source

Cybersecurity Classified by Officially

If you defend an enterprise network, you almost certainly trust an IP blocklist somewhere in your stack. That blocklist was almost certainly built for a different threat landscape than the one you are defending against today.

We measured it. On a single day, May 14, 2026, the GreyNoise Global Observation Grid recorded 119,842 malicious, non-spoofable IPs targeting edge infrastructure. We compared that set against eleven of the most widely deployed OSINT and commercial IP feeds in the industry. The average coverage was 2.0%. The strongest individual feed closed less than five percent of the gap.

That is not a flaw in any single feed. It is the cost of static curation in 2026.

Eleven feeds tested. None broke five percent. The list with the largest absolute size (Avastel, half a million IPs) caught fewer than two percent of the malicious traffic we observed in the same window. The vendor-curated EDLs that ship by default in many enterprise firewalls came in under half a percent.

This is not because those feeds are bad. They are doing the job they were designed to do, which is to flag IPs that meet a high bar for confidence. The problem is that "high bar" is often the result of a manual and slow review process.

The pace of attacker infrastructure has changed. Three forces are compressing the useful life of an indicator faster than any curated list can keep up.

‍Automated reconnaissance no longer requires a human in the loop. Threat actors can spin up scanners at a scale and speed that was operationally impractical even two years ago, then rotate the source infrastructure once it gets noisy.

‍A growing share of malicious traffic now originates from compromised consumer devices and rented residential IP pools. These IPs do not look like traditional badness. They sit inside ISP ranges that you cannot blanket-block without breaking legitimate traffic, and they recycle constantly.

3. Ephemeral cloud and hosting infrastructure

This is an extract. The publication continues at the source.

Read the original at the source: https://www.greynoise.io/blog/why-your-blocklist-missing-malicious-ips

Officially imported this from GreyNoise’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
GreyNoise — imported from official source
Official source
https://www.greynoise.io/blog/rss.xml RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://www.greynoise.io/blog/why-your-blocklist-missing-malicious-ips

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.