GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats. (Yes, it's really us. - Love, GreyNoise )
Public Key
npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 Profile Code
nprofile1qqs0ak5y0mdrjgdvl2zvrrpk9p7yng2jma6pnt4g6lg56p35v7vxdjsprpmhxue69uhhyetvv9ujumt0d4hhxarj9ecxjmntqy28wumn8ghj7un9d3shjtnyv9kh2uewd9hsrkqn7v
Show more details
Published at
2026-06-26T03:03:22Z Event JSON
{
"id": "9b4af5950669cf26535cbfc8348ba3625a13701feb7bd7e8824b5dfab8f4cb0a" ,
"pubkey": "feda847eda3921acfa84c18c36287c49a152df7419aea8d7d14d0634679866ca" ,
"created_at": 1782443002 ,
"kind": 0 ,
"tags": [
[
"proxy",
"https://infosec.exchange/users/greynoise",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://infosec.exchange/users/greynoise",
"pink.momostr"
],
[
"-"
]
],
"content": "{\"name\":\"GreyNoise\",\"about\":\"GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats.\\n\\n(Yes, it's really us. - Love, GreyNoise )\",\"website\":\"https://infosec.exchange/@greynoise\",\"picture\":\"https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/287/162/176/762/744/original/03f75c5756bc3459.png\",\"banner\":\"https://media.infosec.exchange/infosec.exchange/accounts/headers/109/287/162/176/762/744/original/ca6d970047e54339.png\",\"nip05\":\"[email protected] \"}" ,
"sig": "b20ed55d83d29e334a6d14eef085f63d7f6bfaab2ed31fac2076f4fc61310bbdee8bfca23c8e98fa1ddea417c5ed7544f17d2e80989df790388a0949f1d6517e"
}
Last Notes npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise Three things that caught our eye at the edge this week: - One host mapped the enterprise edge. - A pair ran a Hikvision camera RCE (CISA KEV) on shared tooling. - VPN logins stayed under steady pressure. Defend on behavior, not IPs. This week's At The Edge Clear👉 https://www.greynoise.io/resources/at-the-edge-clear-061526 #ThreatIntelligence #CyberSecurity #GreyNoise #InfoSec https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/772/482/527/828/079/original/98d44790fe96a3d7.png npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise NoiseFest is BACK 🎉 We're throwing our 4th annual party during Black Hat / DEF CON 2026 with a 60s and 70s theme 🏵️🎸✌️. Cold drinks, new connections, and stories from the front lines of cybersecurity at House of Blues B-Side in Las Vegas. 🔗RSVP: https://info.greynoise.io/events/blackhat-noisefest-2026 #BlackHat #DEFCON #NoiseFest #GreyNoise #cybersecurity https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/727/202/199/020/312/original/a74fe8e3fac6043d.png npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise The mission: make sure no attack works twice. 🚀 We're hiring a Detection Engineer and a Federal Customer Success Manager to help us get there. Remote-friendly, high-impact, great benefits. Sound like you? 👇 https://www.greynoise.io/careers https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/602/388/278/511/170/original/553dfb9ac64b1573.png npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise We observed a 65% drop in global telnet traffic in a single hour on Jan 14, settling into a sustained 59% reduction. 18 ASNs went silent, 5 countries disappeared, but cloud providers were unaffected. Our analysis of 51.2M sessions points to backbone-level port 23 filtering by a North American Tier 1 transit provider. 🔗 https://www.labs.greynoise.io/grimoire/2026-02-10-telnet-falls-silent/ #GreyNoise #ThreatIntel #CyberSecurity #InfoSec npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise 🚨 Palo Alto GlobalProtect scanning surged 40X in 24hrs...a 90-day high. 2.3M login attempts from concentrated infrastructure (AS200373/AS208885). Block these IPs now: https://www.greynoise.io/blog/palo-alto-scanning-surges-90-day-high npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise EU sanctioned Stark Industries in May. Leaked docs gave them 12 days warning. Result: ASN shuffle, rebrand to THE.Hosting. Corporate shells changed, network behavior didn't. We tracked it: AS44477→AS209847. Packets don't lie. 🔗 https://www.greynoise.io/blog/stark-industries-shell-game npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise GreyNoise now has coverage for Cisco zero-days CVE-2025-20333 and CVE-2025-20362. Watch for exploit attempts in real-time:CVE-2025-20333 (Net-new): https://viz.greynoise.io/tags/cisco-asa-vpn-input-validation-cve-2025-20333-rce-attempt?days=1CVE-2025-20362 (Updated tag): https://viz.greynoise.io/tags/cisco-asa-directory-traversal-cve-2018-0296-and-cve-2025-20362-attempt #CiscoASA #Cisco #ZeroDay #CiscoZeroDays #CVE202520333 #CVE202520362 #GreyNoise #ThreatIntel npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise On August 21, GreyNoise observed nearly 2,000 malicious IPs probing Microsoft Remote Desktop (RDP) services in a single day — a sharp deviation from baseline activity. Full blog: https://www.greynoise.io/blog/surge-malicious-ips-probe-microsoft-remote-desktop #ThreatIntel #RDP #Cybersecurity #GreyNoise #Analysis #RemoteDesktop https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/090/941/432/782/395/original/a498b25dbf6f7c24.png npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise Two critical Ivanti zero-days (CVE-2025-4427 + CVE-2025-4428) are now being actively exploited after a surge in scanning activity last month. Immediate patching is required. Get more details here ⬇️ https://www.greynoise.io/blog/ivanti-epmm-zero-days-reconnaissance-exploitation #ZeroDay #CyberSecurity #threatintel https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/518/471/220/723/020/original/c3b5c5b4674c1b28.png npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise 🚨 9X Surge in Scanning for Ivanti Connect Secure. No CVEs are tied to this yet, but patterns like this often precede exploitation. Full analysis + suspicious IPs: https://www.greynoise.io/blog/surge-ivanti-connect-secure-scanning-activity #Ivanti #Cybersecurity #Scanning npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise 🚨 New GreyNoise Tag Alert: We've added a fresh tag tracking CrushFTP Authentication Bypass (CVE-2025-2825) exploitation attempts. Thanks to @npub13ar…p2f4 for the intel! Dive into the details: https://viz.greynoise.io/tags/crushftp-authentication-bypass-cve-2025-2825-attempt npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise 🚨Active Exploitation Alert: Critical Apache Tomcat RCE (CVE-2025-24813). Majority of traffic targeting U.S.-based systems. Full analysis & attacker IPs: https://greynoise.io/blog/active-exploitation-critical-apache-tomcat-rce-vulnerability-cve-2025-24813 #ApacheTomcat #Apache #GreyNoise #Vulnerability #CVE202524813 https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/196/407/729/558/204/original/bd5acbbb497fb86e.png npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise 🚨 March 12 UPDATE: Grafana Exploitation May Signal Multi-Phase SSRF Attacks. Update + original analysis: https://www.greynoise.io/blog/new-ssrf-exploitation-surge #Cybersecurity #GreyNoise #Vulnerability npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise Where do you get the most actionable threat intel? 🧐 npub1lmdgglk68ys6e75ycxxrv2rufxs49hm5rxh23473f5rrgeucvm9qaum9t8 GreyNoise 🚨 Hackers Are Exploiting Fortinet Firewalls 🚨 15k+ FortiGate firewalls were breached via CVE-2022-40684. GreyNoise has spotted 366 compromised devices behaving abnormally. Defenders: Patch now, secure your systems, and check your IPs. https://www.greynoise.io/blog/hackers-actively-exploiting-fortinet-firewalls-real-time-insights-from-greynoise https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/907/770/149/546/063/original/3d85b319fc4d6966.png