Itโs time for many folksโ annual cultural learning session. ๐คฃ
03.10.2025 12:22 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0@ntkramer.bsky.social
Experienced InfoSec | Elder Millennial | ๐ผ @GreyNoiseIO | I ask 'why?' a lot | Pro Oxford Comma | Fix it! | He/Him | #BLM | Views are my own. https://linktr.ee/glennthorpe
Itโs time for many folksโ annual cultural learning session. ๐คฃ
03.10.2025 12:22 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0On 28 September, GreyNoise observed a sharp one-day surge in attempts to exploit Grafana CVE-2021-43798. Full analysis & malicious IPs โฌ๏ธ
#Grafana #GreyNoise #ThreatIntel
We all know that @hrbrmstr.dev is a mad scientist, and when you give him the amazing telemetry our new fleet has been collecting lately, you get knowledge drops like this! Super proud of our @greynoise.io teamโs work on the deception capabilities we now have! hashtag#threatintel
01.08.2025 15:24 โ ๐ 1 ๐ 2 ๐ฌ 0 ๐ 0An unexpected cluster of malicious IPs in a remote U.S. town led GreyNoise researchers to uncover a 500+ device botnet. Full analysis โฌ๏ธ
#Cybersecurity #ThreatIntel #Botnet #VoIP #GreyNoise #Cyber #Tech
๐ CVE-2017-18370 (Zyxel P660HN)
Oldie but goodie.
viz.greynoise.io/tag...
4/4
โก CVE-2024-20439 (Cisco Smart Licensing Utility) (9.8/10, KEV)
Hardcoded credentials have been known since late last year.
viz.greynoise.io/tag...
3/4
๐ฅ CVE-2025-49132 (Pterodactyl Panel RCE) (10/10 RCE)
Active exploitation observed within days of disclosure.
viz.greynoise.io/tag...
2/4
๐ซ & #threatintel - noticing a few other spikes orgs should be mindful of:
๐ฅ CVE-2025-49132 (Pterodactyl Panel RCE) (10/10 RCE)
โก CVE-2024-20439 (Cisco Smart Licensing Utility) (9.8/10, KEV)
๐ CVE-2017-18370 (Zyxel P660HN)
1/4
The main takeaway is we, first hand, observed exploitation almost two weeks before the POC was released, so ensure all retro threat hunting goes back at LEAST a month, but ideally further.
2/2
๐ฉธ& #threatintel | We (GreyNoise) just published a quick note (www.greynoise.io/blo...) regarding CVE-2025-5777 - CitrixBleed 2
1/2
...here: viz.greynoise.io/tag...
2/2
๐ฅ & #threatintel - Thanks to @horizon3ai.bsky.social, we pushed a tag out today for CitrixBleed 2 CVE-2025-5777 and are backfilling. Currently, we see 233 hits starting on July 1 from:
64.176.50[.]109
38.154.237[.]100
102.129.235[.]108
121.237.80[.]241
45.135.232[.]2
Follow along...
1/2
Just a totally normal trip home from the airport last nightโฆ passing the national guard rolling down the highway as they prepare for NO KINGS DAY protests. F this administration. About 3 more months before they start trying to censor social media via tech controls.
Seems like a lot of work when you could have found 200 year old brain proteins in the US Congress rn.
phys.org/news/2025-0...
It's hard to beat good deception. :)
28.05.2025 15:38 โ ๐ 7 ๐ 0 ๐ฌ 0 ๐ 0If you're ever feeling lonely, just close Zoom.
This works because a funny thing always happens: a random last-minute Zoom will appear if you close it completely.
๐ฅค& #threat-intel: CISA added Langflow Code Injection CVE-2025-3248 to the KEV on May 5. Recently, it has garnered considerable attention, with South Korea leading the pack. This vuln enables unauthenticated attackers to execute arbitrary code via /api/v1/validate/code
viz.greynoise.io/tag...
The number of times I've murmured, "This wouldn't have happened with a PM," is too damn high.
15.05.2025 15:14 โ ๐ 6 ๐ 2 ๐ฌ 0 ๐ 0Good news everyone! www.cisa.gov/news-events/...
"Update May 13: (...) As such, we have paused immediate changes while we re-assess the best approach to sharing with our stakeholders."
www.cisa.gov/news-ev...
The only beneficiary here is, checks notes, X.
2/2
This change legitimately pisses me off.
TL;DRโThey appear to be removing RSS for KEV alerts and moving them to email or X.
They gave orgs 0 days to prepare. RSS is already a thing. The emails arrive many hours later. X is NOT a gov website(!); it even warns you when you click their link!
1/2
Join us live! Or later? Looking forward to chatting with Tracy!
15.04.2025 13:37 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Hi yes. Help your local cybersecurity researchers. If you blog a thing, please date the blog. kthx.
07.04.2025 15:26 โ ๐ 13 ๐ 1 ๐ฌ 0 ๐ 1๐จ New GreyNoise Tag Alert: We've added a fresh tag tracking CrushFTP Authentication Bypass (CVE-2025-2825) exploitation attempts. Thanks to @horizon3ai.bsky.social for the intel! Dive into the details: viz.greynoise.io/tags/crushft...
27.03.2025 21:31 โ ๐ 3 ๐ 3 ๐ฌ 0 ๐ 0๐ฎ clearly! ๐
27.03.2025 11:31 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Today is Opening Day for baseball season in the US. At least now I have my fav sport to put on when I want to watch something but avoid TV news.
27.03.2025 11:30 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Dammit
27.03.2025 02:40 โ ๐ 5 ๐ 0 ๐ฌ 1 ๐ 0Headed to RSAC next month? ๐ NoiseFest will be just a few blocks away...no nonsense (well maybe a little ๐), just drinks, good people, and real security talk.
House of Shields | April 30 | 7โ10PM
Spots are limited. RSVP now.
info.greynoise.io/events/noise...
this morning was quite the haul
26.03.2025 14:39 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0And another one. Two in one day.
22.03.2025 03:04 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0