Glenn's Avatar

Glenn

@ntkramer.bsky.social

Experienced InfoSec | Elder Millennial | ๐Ÿ’ผ @GreyNoiseIO | I ask 'why?' a lot | Pro Oxford Comma | Fix it! | He/Him | #BLM | Views are my own. https://linktr.ee/glennthorpe

2,568 Followers  |  259 Following  |  137 Posts  |  Joined: 26.04.2023  |  2.3533

Latest posts by ntkramer.bsky.social on Bluesky

Post image Post image

Itโ€™s time for many folksโ€™ annual cultural learning session. ๐Ÿคฃ

03.10.2025 12:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Coordinated Grafana Exploitation Attempts on 28 September GreyNoise observed a sharp one-day surge of exploitation attempts targeting CVE-2021-43798 โ€” a Grafana path traversal vulnerability that enables arbitrary file reads. All observed IPs are classified a...

On 28 September, GreyNoise observed a sharp one-day surge in attempts to exploit Grafana CVE-2021-43798. Full analysis & malicious IPs โฌ‡๏ธ
#Grafana #GreyNoise #ThreatIntel

02.10.2025 21:32 โ€” ๐Ÿ‘ 6    ๐Ÿ” 4    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

We all know that @hrbrmstr.dev is a mad scientist, and when you give him the amazing telemetry our new fleet has been collecting lately, you get knowledge drops like this! Super proud of our @greynoise.io teamโ€™s work on the deception capabilities we now have! hashtag#threatintel

01.08.2025 15:24 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
A Spike in the Desert: How GreyNoise Uncovered a Global Pattern of VOIP-Based Telnet Attacks A spike in botnet traffic from a single utility in a rural part of New Mexico led to the discovery of a global botnet. Explore how human-led, AI-powered analysis exposed compromised devices, uncovered...

An unexpected cluster of malicious IPs in a remote U.S. town led GreyNoise researchers to uncover a 500+ device botnet. Full analysis โฌ‡๏ธ
#Cybersecurity #ThreatIntel #Botnet #VoIP #GreyNoise #Cyber #Tech

24.07.2025 13:05 โ€” ๐Ÿ‘ 12    ๐Ÿ” 8    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GreyNoise Visualizer | GreyNoise Visualizer At GreyNoise, we collect and analyze untargeted, widespread, and opportunistic scan and attack activity that reaches every server directly connected to the Internet.

๐Ÿ“ CVE-2017-18370 (Zyxel P660HN)

Oldie but goodie.

viz.greynoise.io/tag...
4/4

16.07.2025 21:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GreyNoise Visualizer | GreyNoise Visualizer At GreyNoise, we collect and analyze untargeted, widespread, and opportunistic scan and attack activity that reaches every server directly connected to the Internet.

โšก CVE-2024-20439 (Cisco Smart Licensing Utility) (9.8/10, KEV)

Hardcoded credentials have been known since late last year.

viz.greynoise.io/tag...
3/4

16.07.2025 21:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
GreyNoise Visualizer | GreyNoise Visualizer At GreyNoise, we collect and analyze untargeted, widespread, and opportunistic scan and attack activity that reaches every server directly connected to the Internet.

๐Ÿ”ฅ CVE-2025-49132 (Pterodactyl Panel RCE) (10/10 RCE)

Active exploitation observed within days of disclosure.

viz.greynoise.io/tag...
2/4

16.07.2025 21:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

๐Ÿซ– & #threatintel - noticing a few other spikes orgs should be mindful of:
๐Ÿ”ฅ CVE-2025-49132 (Pterodactyl Panel RCE) (10/10 RCE)
โšก CVE-2024-20439 (Cisco Smart Licensing Utility) (9.8/10, KEV)
๐Ÿ“ CVE-2017-18370 (Zyxel P660HN)
1/4

16.07.2025 21:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

The main takeaway is we, first hand, observed exploitation almost two weeks before the POC was released, so ensure all retro threat hunting goes back at LEAST a month, but ideally further.
2/2

16.07.2025 21:05 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 โ€” nearly two weeks before a public proof-of-concept was released on July 4.

๐Ÿฉธ& #threatintel | We (GreyNoise) just published a quick note (www.greynoise.io/blo...) regarding CVE-2025-5777 - CitrixBleed 2
1/2

16.07.2025 21:05 โ€” ๐Ÿ‘ 12    ๐Ÿ” 9    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
GreyNoise Visualizer | GreyNoise Visualizer At GreyNoise, we collect and analyze untargeted, widespread, and opportunistic scan and attack activity that reaches every server directly connected to the Internet.

...here: viz.greynoise.io/tag...
2/2

07.07.2025 21:56 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿฅœ & #threatintel - Thanks to @horizon3ai.bsky.social, we pushed a tag out today for CitrixBleed 2 CVE-2025-5777 and are backfilling. Currently, we see 233 hits starting on July 1 from:
64.176.50[.]109
38.154.237[.]100
102.129.235[.]108
121.237.80[.]241
45.135.232[.]2
Follow along...

1/2

07.07.2025 21:56 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Just a totally normal trip home from the airport last nightโ€ฆ passing the national guard rolling down the highway as they prepare for NO KINGS DAY protests. F this administration. About 3 more months before they start trying to censor social media via tech controls.

12.06.2025 14:37 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Paleoproteomic profiling recovers diverse proteins from 200-year-old human brains A new method developed by researchers at the Nuffield Department of Medicine, University of Oxford, could soon unlock the vast repository of biological information held in the proteins of ancient soft ...

Seems like a lot of work when you could have found 200 year old brain proteins in the US Congress rn.

phys.org/news/2025-0...

29.05.2025 11:45 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

It's hard to beat good deception. :)

28.05.2025 15:38 โ€” ๐Ÿ‘ 7    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

If you're ever feeling lonely, just close Zoom.
This works because a funny thing always happens: a random last-minute Zoom will appear if you close it completely.

27.05.2025 21:21 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿฅค& #threat-intel: CISA added Langflow Code Injection CVE-2025-3248 to the KEV on May 5. Recently, it has garnered considerable attention, with South Korea leading the pack. This vuln enables unauthenticated attackers to execute arbitrary code via /api/v1/validate/code

viz.greynoise.io/tag...

15.05.2025 22:06 โ€” ๐Ÿ‘ 5    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The number of times I've murmured, "This wouldn't have happened with a PM," is too damn high.

15.05.2025 15:14 โ€” ๐Ÿ‘ 6    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Update to How CISA Shares Cyber-Related Alerts and Notifications | CISA CISA is changing how we announce cybersecurity updates and the release of new guidance.

Good news everyone! www.cisa.gov/news-events/...

"Update May 13: (...) As such, we have paused immediate changes while we re-assess the best approach to sharing with our stakeholders."

13.05.2025 21:10 โ€” ๐Ÿ‘ 5    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Update to How CISA Shares Cyber-Related Alerts and Notifications | CISA CISA is changing how we announce cybersecurity updates and the release of new guidance

www.cisa.gov/news-ev...

The only beneficiary here is, checks notes, X.
2/2

12.05.2025 21:04 โ€” ๐Ÿ‘ 26    ๐Ÿ” 6    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

This change legitimately pisses me off.

TL;DRโ€”They appear to be removing RSS for KEV alerts and moving them to email or X.
They gave orgs 0 days to prepare. RSS is already a thing. The emails arrive many hours later. X is NOT a gov website(!); it even warns you when you click their link!
1/2

12.05.2025 21:04 โ€” ๐Ÿ‘ 57    ๐Ÿ” 20    ๐Ÿ’ฌ 4    ๐Ÿ“Œ 4

Join us live! Or later? Looking forward to chatting with Tracy!

15.04.2025 13:37 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Hi yes. Help your local cybersecurity researchers. If you blog a thing, please date the blog. kthx.

07.04.2025 15:26 โ€” ๐Ÿ‘ 13    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

๐Ÿšจ New GreyNoise Tag Alert: We've added a fresh tag tracking CrushFTP Authentication Bypass (CVE-2025-2825) exploitation attempts. Thanks to @horizon3ai.bsky.social for the intel! Dive into the details: viz.greynoise.io/tags/crushft...

27.03.2025 21:31 โ€” ๐Ÿ‘ 3    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ”ฎ clearly! ๐Ÿ™ƒ

27.03.2025 11:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Today is Opening Day for baseball season in the US. At least now I have my fav sport to put on when I want to watch something but avoid TV news.

27.03.2025 11:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Dammit

27.03.2025 02:40 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
GreyNoise - NoiseFest at RSAC 2025 Join us for NoiseFest at RSAC 2025 on April 30th, At the House of Shields. Enjoy drinks, snacks, and engaging conversations with your peers. RSVP now!

Headed to RSAC next month? ๐Ÿ‘€ NoiseFest will be just a few blocks away...no nonsense (well maybe a little ๐Ÿ˜ˆ), just drinks, good people, and real security talk.

House of Shields | April 30 | 7โ€“10PM

Spots are limited. RSVP now.
info.greynoise.io/events/noise...

26.03.2025 19:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

this morning was quite the haul

26.03.2025 14:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

And another one. Two in one day.

22.03.2025 03:04 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@ntkramer is following 20 prominent accounts