Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

GreyNoise

@greynoise@infosec.exchange
  • Open on infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats.

(Yes, it's really us. - Love, GreyNoise )

2034 Followers
30 Following
50 Posts
Joined November 04, 2022

Posts

Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jul 22, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange
This week in GreyNoise data, rented crawlers probed for credentials and configuration secrets across widely deployed web software. A matched pair of crawlers sharing one client fingerprint probed NGINX UI (CVE-2026-27944) and LiteSpeed Cache (CVE-2024-44000), two CVSS 9.8 flaws that leak credentials, private keys, or session material, from two different hosting providers. Alongside them, an RDP brute force cohort spread across three networks under one transport fingerprint. WordPress core SQL injection CVE-2026-60137 also entered the CISA KEV catalog this week. The rented hosts rotate; the fingerprints persist. Customers get the full weekly brief. Our public At The Edge one-pager 👉https://www.greynoise.io/resources/at-the-edge-clear-072026
0
0
0
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jul 14, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange
The June NoiseLetter is live! In this edition, we're diving into GreyNoise use cases, sharing the latest product releases, and getting ready for our biggest event of the year, NoiseFest. 🔗 https://www.greynoise.io/resources/noiseletter-june-2026
0
0
0
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jul 13, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

The Threat Brief Library is now live in the GreyNoise Visualizer! Browse, search, filter, and download weekly At The Edge briefs, Executive Situation Reports, and more. All built on primary-source data from our global sensor network.

Check it out: https://www.greynoise.io/blog/threat-brief-library

0
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jul 13, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

NoiseFest is just a few weeks away!🎉 If you're in Las Vegas for #BlackHat or #DEFCON, come join us for a night of cold drinks, good company, and 60s and 70s vibes. 🏵️

📅Thursday, August 6th | 6–9 PM PT | Las Vegas
🔗RSVP: https://info.greynoise.io/events/blackhat-noisefest-2026

#NoiseFest #GreyNoise #cybersecurity

0
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jul 08, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange
This week a long-dormant Palo Alto flaw came back to life in GreyNoise data. GlobalProtect CVE-2019-1579 (unauth RCE, CISA KEV) drew only isolated activity through late June, then more than 120 malicious hosts probed it on 06 July, almost all from a single hosting network. Separately, two coordinated hosting fleets ran the week's highest-volume web exploitation, roughly 7.5M connection attempts. Access our public preview At The Edge Clear: https://www.greynoise.io/resources/at-the-edge-clear-070626 GreyNoise customers get the full weekly brief.
3
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jun 24, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Four things that caught our eye at the edge this week:

Following the FortiBleed reporting, GreyNoise is providing telemetry on the same Fortinet surfaces, without attributing the activity; the SSL VPN brute-force we track stood down in early June. Cisco SSL VPN brute-force sources surged to 3,645 in a day. A German source kept harvesting Laravel and TeleMessage secrets. Hikvision targeting broadened.

MFA on every VPN edge. Defend on behavior, not IPs.

This week's At The Edge 👉 https://www.greynoise.io/resources/at-the-edge-clear-062226

1
0
3
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jun 18, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Three things that caught our eye at the edge this week:

- One host mapped the enterprise edge.
- A pair ran a Hikvision camera RCE (CISA KEV) on shared tooling.
- VPN logins stayed under steady pressure.

Defend on behavior, not IPs. This week's At The Edge Clear👉 https://www.greynoise.io/resources/at-the-edge-clear-061526

#ThreatIntelligence #CyberSecurity #GreyNoise #InfoSec

3
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jun 16, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

We're in London tomorrow for @crowdstrike@infosec.exchange #CrowdTour2026. If you're attending our team would love to connect! Schedule some time to meet with us: https://info.greynoise.io/crowdtour-2026-meet

#CyberSecurity #GreyNoise #ThreatIntel

1
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jun 12, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

GreyNoise At The Edge Intel Brief | June 1-8, 2026

This week's story: credential attacks on the front door of remote access, not new vulnerabilities.
🔗 https://www.greynoise.io/resources/at-the-edge-clear-060826

1. A single Netherlands host (94.102.49.82, malicious) produced more than a quarter of all RDP crawling we observed — a 48-hour burst across a wide port range, then silence.

2. Every major SSL VPN vendor — Fortinet, Cisco, SonicWall, and Palo Alto — drew sustained credential brute-forcing and login scanning.

3. A two-node MikroTik RouterOS brute-force campaign (NL + BR) continued for a third week on TCP/8728.

4. Nine of the top ten source IPs trace to rented hosting — apply GreyNoise dynamic blocklists for the relevant tags — the IPs rotate, the tag-based coverage does not.

The actionable intelligence is the specific IPs, ASNs, and GreyNoise tags — not generic hardening advice.

#ThreatIntel #CyberSecurity #InfoSec #GreyNoise

1
0
0
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jun 10, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

NoiseFest is BACK 🎉
We're throwing our 4th annual party during Black Hat / DEF CON 2026 with a 60s and 70s theme 🏵️🎸✌️. Cold drinks, new connections, and stories from the front lines of cybersecurity at House of Blues B-Side in Las Vegas.

🔗RSVP: https://info.greynoise.io/events/blackhat-noisefest-2026

#BlackHat #DEFCON #NoiseFest #GreyNoise #cybersecurity

9
0
9
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jun 04, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Less noise. Better signal. Faster response.
We break down 4 ways GreyNoise helps SOC teams cut through internet background noise and focus on what actually matters:
https://www.greynoise.io/blog/ways-greynoise-improves-soc-outcomes

0
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Jun 04, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

The May NoiseLetter is live! Early warning signals, blocklist gaps, and a SonicWall spike that echoes the pattern that preceded a CVE: https://www.greynoise.io/resources/noiseletter-may-2026

0
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · May 29, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

GreyNoise At The Edge (May 19–26, 2026): a week of rented-infrastructure reconnaissance against the internet's edge — routers, VPN gateways, container planes, and embedded devices, probed in parallel.

1. A long-running MikroTik RouterOS brute-force operation (VPSVAULT, AS215925) reversed a multi-week decline, adding a second node and climbing back to ~1.9M sessions against TCP/8728.

2. A fingerprinted Netherlands cluster cataloged Fortinet, Ivanti, Pulse Secure, Sophos, and F5 appliances, running auth-bypass checks including Palo Alto PAN-OS GlobalProtect (CVE-2020-2034).

3. Telnet dominated volume; low-level probing continued for the tracked GNU telnetd out-of-bounds write watch item CVE-2026-32746 (CVSS 9.8).

4. Kubernetes and Docker control-plane recon now runs from a compromised consumer broadband host.

The infrastructure rotates constantly — detect on behavior, not addresses.

https://www.greynoise.io/resources/at-the-edge-clear-052526

#ThreatIntel #CyberSecurity #InfoSec #GreyNoise

2
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · May 27, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Got questions? We've got answers. Tune in tomorrow at 12 ET for GreyNoise University LIVE! 📺 https://www.greynoise.io/events/greynoise-university-live

0
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · May 22, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Your blocklist is probably missing 98% of what's actively hitting your edge right now. We tested 11 major feeds against 119,842 malicious IPs GreyNoise observed on a single day. The best feed covered less than 5%. Most were under 2%.

The feeds aren't broken. Attacker infrastructure just rotates faster than static curation can keep up with.

Read the full breakdown: https://www.greynoise.io/blog/why-your-blocklist-missing-malicious-ips

3
0
1
1
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · May 21, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

A scanning pattern similar to the one preceding CVE-2026-0400 in February is active again. May 12 saw the largest single-day session volume on this SonicWall tag in 90 days.

🔗 https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400

#GreyNoise #ThreatIntel #SonicWall

2
0
4
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · May 19, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

The mission: make sure no attack works twice. 🚀

We're hiring a Detection Engineer and a Federal Customer Success Manager to help us get there. Remote-friendly, high-impact, great benefits.

Sound like you? 👇
https://www.greynoise.io/careers

4
0
3
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · May 04, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

May the 4th be with you + so be the signal. 🚀
The April Noiseletter is live: Project Swarm is open to the global security community, new research drops, and a packed events calendar. Let's get into it. 👇
https://www.greynoise.io/resources/noiseletter-april-2026

4
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Apr 30, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Today's the perfect day for a matinee double feature:

GreyNoise University LIVE: https://www.greynoise.io/events/greynoise-university-live

The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse Webinar: https://info.greynoise.io/webinar/invisible-army?_ga=2.231440415.1063083880.1777487534-981227823.1753375781

1
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Apr 29, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

We're so back, after taking last month off, we are refreshed + ready for April's GreyNoise University LIVE!!

📺 Tune in TOMORROW at 12 ET! https://www.greynoise.io/events/greynoise-university-live

1
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Apr 29, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Introducing Project Swarm: a research initiative to defend the network edge and we're inviting you to join. Deploy a sensor on your infrastructure, capture real attacker traffic + compare what's hitting you to the GreyNoise global baseline. Join today! 🐝

Your browser does not support the video tag.
1
1
2
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Apr 10, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

21 IPs generated nearly half of all RDP scanning on the internet in 48 hours. Then vanished — for the second time in 30 days.

🔗 https://www.greynoise.io/blog/ip-addresses-behind-nearly-half-rdp-internet-scanning

#ThreatIntel #RDP #CyberSecurity #InfoSec #ThreatHunting

www.greynoise.io

Just 21 IP Addresses Are Now Behind Nearly Half of All RDP Scanning on the Internet

5
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Apr 07, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange
Replying to @greynoise@infosec.exchange
Press Release: https://www.prweb.com/releases/greynoise-intelligence-introduces-c2-detection-to-close-the-visibility-gap-at-the-edge-of-the-network-302734388.html
1
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Apr 07, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

🚨We just shipped C2 Detection.

Compromised edge devices call home to attacker infrastructure. The evidence is in your outbound logs...most teams just can’t see it.

Now they can. 👀

Learn more >> https://www.greynoise.io/blog/introducing-c2-detection

5
2
2
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Apr 03, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

GreyNoise is on the move 🌍
Next up: CrowdTours (8 cities), Glasgow + Tampa

It’s all in the March Noiseletter 🗞️ + fresh research (more coming soon 👀)

https://www.greynoise.io/resources/noiseletter-march-2026

1
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Apr 02, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

New GreyNoise Report: 39% of unique IPs targeting the edge come from home internet connections. They are everywhere, briefly — 78% appear at most twice before rotating. The rotation rate makes feed-based IP reputation structurally ineffective against this traffic.

🔗 https://www.greynoise.io/resources/invisible-army-residential-proxy-abuse-report

4
0
2
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 31, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

NEW: GreyNoise At The Edge Intel Brief (March 23-30)

187,998,900 sessions from 100 top source IPs observed by GreyNoise sensors between March 23-30, 2026. Daily volumes surged 4x mid-week — from 8.5M to 36.6M in 72 hours.

1. VPSVAULT IoT botnet recruitment across 22 CVEs — 3,347,443 sessions from 4 Brazilian IPs targeting Hikvision, MikroTik, TP-Link, D-Link devices. Includes CVE-2026-24061, now on CISA KEV.

2. VisionHeight fleet of 6 AWS IPs generated 5,892,055 sessions mapping enterprise perimeters across Palo Alto, Sophos, Ivanti, Citrix, F5, and ConnectWise — probing CVE-2024-1709 (CVSS 10.0).

3. React/Next.js exploit chaining (CVE-2025-55182 + CVE-2025-29927) produced 1,338,336 sessions, with attackers spoofing GoogleBot user-agents to bypass detection.

4. At least 4 new scanning operations activated simultaneously mid-week, driving the sharp volume surge across the observation period.

Here's what we found: 🔗 https://www.greynoise.io/resources/at-the-edge-clear-033026

#ThreatIntel #CyberSecurity #InfoSec #GreyNoise

2
0
2
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 26, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

GreyNoise is proud to be sponsoring the CrowdStrike CrowdTour across 8 cities! We’re excited to highlight how our integration with Falcon Next-Gen SIEM helps SOC teams stop chasing ghosts and start catching real threats.

If you’re attending a tour stop or local to the area, let’s connect to chat about:
- Validating your perimeter in real time.
- Protecting the identity layer from brute-force scanners.
- Filtering out background noise to focus on high-fidelity alerts.

👇Book a meeting with us here:
https://info.greynoise.io/crowdtour-2026-meet

0
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 25, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Last week, half of all new scanning IPs observed by GreyNoise geolocated to Hong Kong.

A quarter-million of them never completed a TCP handshake.

The ones that did were scanning MySQL, SSH, SMB, and RDP across 20+ countries.

One of these is the signal. The other is noise.
🔗 https://www.greynoise.io/blog/ghost-fleet-half-new-scanning-ips-geolocated-to-hong-kong

6
0
4
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 24, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

200,886,675 sessions. 101 unique source IPs. March 16–23, 2026.

GreyNoise At The Edge intelligence brief highlights:

1. The MEVSPACE RDP brute-force operator returned after a 99.8% infrastructure collapse — single IP generated 7,975,241 sessions before deliberately withdrawing after 4 days. GreyNoise has tracked a surge-withdraw-reconstitute cycle since January 2026, reinforcing that well-resourced operators can reconstitute capacity within days.

2. Two coordinated campaigns emerged: VPSVAULT.HOST (IoT worm weaponizing 21+ CVEs against 12+ manufacturers) and Omegatech (TLS fingerprint randomization with 5,854 unique JA3s per node).

3. Sophos CVE-2022-1040 exploitation stabilized at 638,654 sessions in its fifth consecutive week. Enterprise VPN credential pressure reached week 9 across five vendors with 2.9M+ combined sessions.

4. n8n CVE-2026-21858 (CVSS 10.0) reached 118,086 sessions with links to MuddyWater and ZeroBot. ICS/SCADA reconnaissance expanded with new HMI and PLC vulnerabilities trending.

🔗 https://www.greynoise.io/resources/at-the-edge-clear-032326

#ThreatIntel #CyberSecurity #InfoSec #GreyNoise

2
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 19, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

New GreyNoise At The Edge brief: The internet's scanning infrastructure is reorganizing.

UCLOUD (HK) surged +578% to become the #1 scanning ASN — now 15.6% of all observed traffic. Western providers declining simultaneously.

301.8M sessions. 439K IPs. Here's what we found.

🔗 https://www.greynoise.io/resources/at-the-edge-clear-031626

2
0
2
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 17, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Starting at the top of the hour! 🚨

Hope to see you there to break down all things State of the Edge with @morris@infosec.exchange @hrbrmstr@infosec.exchange + Nishawn!

There's still time to register 👉 https://info.greynoise.io/webinar/state-of-the-edge-2026

0
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 16, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

TOMORROW! 🚨 Join us for a fast-paced dive into the 2026 GreyNoise State of the Edge Report...from rogue residential botnets to 26-year-old CVEs still getting hammered. Save your spot and see what’s actually hitting the edge.
🔗 https://info.greynoise.io/webinar/state-of-the-edge-2026

1
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 11, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

🚀 New GreyNoise + Google SecOps integrations are live. See which IPs scan everyone vs just you, now directly inside Google SecOps.

🧩 SIEM: Standardized ingestion, dashboards, YARA-L rules, and saved searches
⚡️ SOAR: v7.0 actions, webhooks, and playbooks to automate triage

https://www.greynoise.io/blog/greynoise-google-secops-integration

3
0
3
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 11, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Hey London! We are closing down day 1 at #ecrimecongress today + cant wait to see you tomorrow! If you're around, say hi to the team, watch a demo, and grab some great swag! 🔥

3
0
2
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 10, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Edge attacks are evolving faster than your playbook. Join @morris@infosec.exchange, @hrbrmstr@infosec.exchange + Shawn Smagh next Tuesday for a live breakdown of where edge targeting is concentrating, where defenses are failing, + what 162 days of internet-scale data says about your real exposure.

https://info.greynoise.io/webinar/state-of-the-edge-2026

2
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 05, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

February was anything but quiet at GreyNoise, from our 2026 State of the Edge Report to new edge attack research, Ivanti + BeyondTrust deep dives, and a packed March of events, check it all out in this month's Noiseletter! 🚀

https://www.greynoise.io/resources/noiseletter-february-2026

3
0
3
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 04, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

GreyNoise is now integrated across CrowdStrike Falcon. 🚀

Falcon users can bring GreyNoise IP classification into Next-Gen SIEM searches, Fusion SOAR playbooks, and Charlotte AI workflows to triage faster, cut background noise + prioritize real threats.

https://www.greynoise.io/blog/greynoise-intelligence-available-across-crowdstrike-falcon-platform

4
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 04, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Here's a taste of what GreyNoise customers got in this week's At The Edge intelligence brief.

268M sessions. 540K unique IPs. Four findings that matter.

→ Sophos CVE-2022-1040 surged 435% — second consecutive week
→ 9.1M RDP sessions from two IPs, one JA4T fingerprint
→ VPN siege Week 6 — vendors rotating after our published analysis
→ Scanning landscape collapsed. Enterprise campaigns didn't.

Full brief: IOCs, attribution, recommendations.

🔗 https://www.greynoise.io/resources/at-the-edge-clear-030226

greynoise.io/contact

3
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Mar 02, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Noise: analyzed.
Security: certified.

GreyNoise is now ISO 27001 certified 🔐
We spend our days tracking internet background noise and we hold ourselves to the same high security standards we expect from the ecosystem.

9
0
2
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Feb 27, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

GreyNoise observed a coordinated campaign probing SonicWall firewalls to identify which devices have SSL VPN enabled — the prerequisite step before credential attacks. Four infrastructure clusters, a commercial proxy service rotating thousands of IPs, and near-zero exploitation. This is target mapping.

🔗 https://www.greynoise.io/blog/active-reconnaissance-campaign-targets-sonicwall-firewalls-through-commercial-proxy-infrastructure

4
0
5
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Feb 26, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Join us today at 12pm ET for February’s GreyNoise University LIVE session, where you’ll get an overview of what’s new at GreyNoise, plus a live demo of our tools and latest product releases.

🔗 https://www.greynoise.io/events/greynoise-university-live

2
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Feb 24, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

52% of RCE attempts came from IPs with no prior GreyNoise history. New research on where edge defenses fall short + what to do about it: https://www.greynoise.io/resources/2026-state-of-the-edge-report

#ThreatIntel #Cybersecurity #GreyNoise

10
0
6
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Feb 18, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

This week's At the Edge: CLEAR is out — a preview of the intel brief GreyNoise customers get every week.

🔗 https://www.greynoise.io/resources/at-the-edge-clear-021626

That's just the preview. greynoise.io/contact

#ThreatIntel #CyberSecurity #GreyNoise

1
0
2
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Feb 12, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

It took less than a day. A PoC for BeyondTrust CVE-2026-1731 hit GitHub, and GreyNoise immediately started seeing reconnaissance from multi-exploit actors hiding behind VPNs + custom tooling. See what our data reveals about who’s mapping targets + how.

🔗 https://www.greynoise.io/blog/reconnaissance-beyondtrust-rce-cve-2026-1731

10
0
3
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Feb 11, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Three campaigns. One has Cobalt Strike ready.

RDP nearly quadrupled. A botnet picked up a new CVE. And someone built a Kubernetes cluster just to exploit n8n.

A preview of what GreyNoise customers get every week. Full brief has the IOCs, attribution, and analysis.

#ThreatIntelligence #InfoSec #GreyNoise #CyberSecurity

1
0
2
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Feb 10, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

We observed a 65% drop in global telnet traffic in a single hour on Jan 14, settling into a sustained 59% reduction. 18 ASNs went silent, 5 countries disappeared, but cloud providers were unaffected.

Our analysis of 51.2M sessions points to backbone-level port 23 filtering by a North American Tier 1 transit provider.

🔗 https://www.labs.greynoise.io/grimoire/2026-02-10-telnet-falls-silent/

#GreyNoise #ThreatIntel #CyberSecurity #InfoSec

2026-01-14: The Day the telnet Died – GreyNoise Labs
GreyNoise Labs

2026-01-14: The Day the telnet Died – GreyNoise Labs

On January 14, 2026, global telnet traffic observed by GreyNoise sensors fell off a cliff. A 59% sustained reduction, eighteen ASNs going completely silent, five countries vanishing from our data enti

44
8
53
1
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Feb 10, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

83% of observed Ivanti EPMM exploitation (CVE-2026-1281) traces to one bulletproof IP that isn't on any published IOC list. The IPs that are? VPN exits with zero Ivanti activity. We broke down who's actually doing this ⬇️ https://www.greynoise.io/blog/active-ivanti-exploitation

#Ivanti #ThreatIntel #CVE20261281 #InfoSec

4
0
3
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Feb 10, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Attackers are operating at machine speed + so should defenders. 🤖

Check out the Government Technology Insider article, where our Principal Intelligence Liaison, Shawn Smagh, shares what we’re seeing in the data and 4️⃣ steps to get to active defense at machine speed.
https://governmenttechnologyinsider.com/the-ai-accelerated-threat-landscape-four-steps-toward-active-defense-at-machine-speed/

3
0
1
0
Open post
greynoise
GreyNoise @greynoise@infosec.exchange · Feb 04, 2026
GreyNoise
@greynoise@infosec.exchange

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )

infosec.exchange

Check out this month's NoiseLetter for the latest on Ghostie + all things GreyNoise!
🗞️https://www.greynoise.io/resources/noiseletter-january-2026

Your browser does not support the video tag.
2
0
3
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:20:29 UTC