GreyNoise's Avatar

GreyNoise

@greynoise.infosec.exchange.ap.brid.gy

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats […] [bridged from https://infosec.exchange/@greynoise on the fediverse by https://fed.brid.gy/ ]

59 Followers  |  0 Following  |  157 Posts  |  Joined: 06.05.2024  |  1.3157

Latest posts by greynoise.infosec.exchange.ap.brid.gy on Bluesky

Surge in Brute-Force Attempts Against Fortinet SSL VPNs

Surge in Brute-Force Attempts Against Fortinet SSL VPNs

On August 3, we observed the largest single-day spike in brute-force activity against Fortinet SSL VPNs in recent months. Full breakdown of the campaign and how we traced it: https://www.greynoise.io/blog/vulnerability-fortinet-vpn-bruteforce-spike […]

[Original post on infosec.exchange]

12.08.2025 13:16 — 👍 0    🔁 0    💬 0    📌 0
Preview
NoiseLetter July 2025 Get GreyNoise updates! Read the July 2025 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.

This month's NoiseLetter will make the perfect light reading for a trip to say...Vegas? Make sure to check it out (even if you're not headed to BlackHat/DEF CON there is something in it for you). 🤘https://www.greynoise.io/resources/noiseletter-july-2025

01.08.2025 20:46 — 👍 1    🔁 0    💬 0    📌 0
Post image

Yesterday, we published new research revealing an early warning system for CVE disclosure. 📌 Full report: https://www.greynoise.io/resources/early-warning-signals-attacker-behavior-precedes-new-vulnerabilities

#Cybersecurity #ThreatIntel #VulnerabilityManagement #GreyNoise #InfoSec #CISO

01.08.2025 13:32 — 👍 3    🔁 0    💬 0    📌 0
Preview
GreyNoise University LIVE

GN University LIVE is headed your way tomorrow @ 12pm ET, don't miss it! 🔥
https://www.greynoise.io/events/greynoise-university-live

30.07.2025 16:31 — 👍 0    🔁 1    💬 0    📌 0
Original post on infosec.exchange

🚨 New Research: GreyNoise identifies an early warning signal, spikes in attacker activity tend to precede new CVE disclosures within six weeks. Which vendors show the strongest signal and more, all in our latest report ⬇️ […]

31.07.2025 13:17 — 👍 0    🔁 0    💬 0    📌 0
Preview
GreyNoise University LIVE

GN University LIVE is headed your way tomorrow @ 12pm ET, don't miss it! 🔥
https://www.greynoise.io/events/greynoise-university-live

30.07.2025 16:31 — 👍 0    🔁 1    💬 0    📌 0
Preview
A Spike in the Desert: How GreyNoise Uncovered a Global Pattern of VOIP-Based Telnet Attacks A spike in botnet traffic from a single utility in a rural part of New Mexico led to the discovery of a global botnet. Explore how human-led, AI-powered analysis exposed compromised devices, uncovered attack patterns, and why defenders should take note.

An unexpected cluster of malicious IPs in a remote U.S. town led GreyNoise researchers to uncover a 500+ device botnet. Full analysis: https://www.greynoise.io/blog/how-greynoise-uncovered-global-pattern-voip-based-telnet-attacks

#Cybersecurity #ThreatIntel #Botnet #VoIP #GreyNoise #Cyber #Tech

24.07.2025 13:04 — 👍 0    🔁 1    💬 1    📌 0
Original post on infosec.exchange

A vulnerability in a Signal-based enterprise messaging app could expose plaintext usernames and passwords via an unauthenticated memory dump. We're seeing exploit attempts in real time.

Full analysis: https://www.greynoise.io/blog/active-exploit-attempts-signal-based-messaging-app […]

17.07.2025 13:05 — 👍 0    🔁 0    💬 0    📌 0
Preview
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept was released on July 4.

GreyNoise observed exploitation of CitrixBleed 2 (CVE-2025-5777) nearly two weeks before a public PoC was released. Full breakdown: https://www.greynoise.io/blog/exploitation-citrixbleed-2-cve-2025-5777-before-public-poc #GreyNoise #ThreatIntel #CitrixBleed #Citrix #NetScaler

16.07.2025 20:45 — 👍 0    🔁 0    💬 0    📌 0
Preview
GreyNoise Identifies New Scraper Botnet Concentrated in Taiwan GreyNoise has identified a previously untracked variant of a scraper botnet, detectable through a globally unique network fingerprint. To detect it, GreyNoise analysts created a signature using JA4+, the suite of JA4 signatures used to fingerprint network traffic.

🚨 GreyNoise uncovered a previously untracked botnet, mostly based in Taiwan. Detected using JA4H + JA4T behavioral fingerprinting. Full analysis and list of IPs: https://www.greynoise.io/blog/new-scraper-botnet-concentrated-in-taiwan

#GreyNoise #ThreatIntel #Cybersecurity

09.07.2025 13:06 — 👍 1    🔁 0    💬 0    📌 0
Preview
NoiseLetter June 2025 Get GreyNoise updates! Read the June 2025 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.

For the 5th year, we’re on summer break✈️Mandatory PTO starts TODAY! Services will stay up, with a skeleton crew on call for emergencies. Miss us? Check out this month’s NoiseLetter. See ya July 7! ✌️

💌 https://www.greynoise.io/resources/noiseletter-june-2025

27.06.2025 15:32 — 👍 0    🔁 1    💬 0    📌 0
Preview
GreyNoise University LIVE

See ya'll tomorrow at 12pm ET, for June's GreyNoise University LIVE! 🔥

https://www.greynoise.io/events/greynoise-university-live

25.06.2025 18:16 — 👍 0    🔁 1    💬 0    📌 0
Preview
GreyNoise University LIVE

See ya'll tomorrow at 12pm ET, for June's GreyNoise University LIVE! 🔥

https://www.greynoise.io/events/greynoise-university-live

25.06.2025 18:16 — 👍 0    🔁 1    💬 0    📌 0
Preview
Surge in MOVEit Transfer Scanning Activity Could Signal Emerging Threat Activity GreyNoise has identified a notable surge in scanning activity targeting MOVEit Transfer systems, beginning on May 27, 2025. Prior to this date, scanning was minimal — typically fewer than 10 IPs observed per day.

🚨 GreyNoise has observed a surge in scanning activity against MOVEit Transfer. Read the blog & see suspicious and malicious IPs: https://www.greynoise.io/blog/surge-moveit-transfer-scanning-activity

#GreyNoise #ThreatIntel #Cybersecurity

25.06.2025 13:04 — 👍 1    🔁 1    💬 0    📌 0

@runZeroInc we are stoked to have you back this year! 🔥

20.06.2025 16:08 — 👍 0    🔁 0    💬 0    📌 0
Preview
GreyNoise - NoiseFest at BlackHat 2025 Join us for NoiseFest at BlackHat/DEFCON on Thursday, August 7th. Enjoy drinks, snacks, and engaging conversations with your peers. RSVP now!

VEGAS, WE ARE SO BACK! 🤘

https://info.greynoise.io/events/noisefest-blackhat-2025

18.06.2025 19:17 — 👍 1    🔁 0    💬 1    📌 0
Original post on infosec.exchange

New GreyNoise Labs research: CVE-2025-4748

Our team demonstrates how path traversal via zip archives can be used to achieve file write and code execution against Erlang OTP environments, exploiting CVE-2025-4748. This technique leverages the zip:unzip function when untrusted zip files are […]

17.06.2025 17:16 — 👍 0    🔁 3    💬 0    📌 0
Preview
GreyNoise Observes Exploit Attempts Targeting Zyxel CVE-2023-28771 ‍On June 16, GreyNoise observed exploit attempts targeting CVE-2023-28771 — a remote code execution vulnerability affecting Zyxel Internet Key Exchange (IKE) packet decoders over UDP port 500.

GreyNoise has observed exploit attempts targeting CVE-2023-28771 — an RCE vuln affecting Zyxel devices. Full analysis + malicious IPs

🔗https://www.greynoise.io/blog/exploit-attempts-targeting-zyxel-cve-2023-28771

#Cybersecurity #ThreatIntel #Vulnerabilities #GreyNoise

16.06.2025 21:03 — 👍 2    🔁 2    💬 0    📌 0
Preview
Cribl Pit Stop - Toronto Learn how to supercharge your telemetry management strategy from the world’s leader in telemetry management infrastructure. Cribl is coming to Toronto to address your data challenges.

Hey Toronto 🇨🇦! We are headed your way next week with our friends @cribl_io for their #CriblPitStop. Say hi to our team and get the inside scoop about all things GreyNoise! 🍁

https://info.cribl.io/RM-FEV-FY26-Q2-06-17-PitStop-Toronto_LP-Registration.html

13.06.2025 19:04 — 👍 0    🔁 0    💬 0    📌 0
Preview
Coordinated Brute Force Activity Targeting Apache Tomcat Manager Indicates Possible Upcoming Threats GreyNoise recently observed a coordinated spike in malicious activity against Apache Tomcat Manager interfaces. On June 5, 2025, two GreyNoise tags — Tomcat Manager Brute Force Attempt and Tomcat Manager Login Attempt — registered well above baseline volumes, indicating a deliberate attempt to identify and access exposed Tomcat services at scale.

🚨 Brute force activity against Apache Tomcat Manager just spiked, indicating possible upcoming threats. 🔗 Full analysis & malicious IPs: https://www.greynoise.io/blog/coordinated-brute-force-activity-targeting-apache-tomcat-manager
#GreyNoise #Apache #ThreatIntel #Tomcat

10.06.2025 13:15 — 👍 1    🔁 1    💬 0    📌 0

Technical Blog Drop 🔥 GreyNoise Labs explains why encoded payloads may go unnoticed:
🔗 https://labs.greynoise.io/grimoire/2025-06-05-suricata-url-decoding/

#Suricata #Cybersecurity

06.06.2025 16:59 — 👍 0    🔁 0    💬 0    📌 0
Preview
GreyNoise Webinar - How Resurgent Vulnerabilities Jeopardize Organizational Security Join GreyNoise Founder & Chief Architect Andrew Morris and VP of Data Science Bob Rudis as they break down key insights from our latest 2025 report, A Blindspot in Cyber Defense: How Resurgent Vulnerabilities Jeopardize Organizational Security.

ICYMI 👀 @hrbrmstr + Noah gave an epic talk on all things resurgent vulns, check it out 🔥

https://info.greynoise.io/webinar/how-resurgent-vulnerabilities-jeopardize-organizational-security

05.06.2025 17:29 — 👍 0    🔁 1    💬 0    📌 0
Original post on infosec.exchange

🧟‍♂️ Old CVEs are back from the dead + they’re coming for your edge tech.

Join @morris + @hrbrmstr TOMORROW as they unpack the weird world of resurgent vulns and what they mean for your security strategy.

🎟️ Register now […]

02.06.2025 17:39 — 👍 0    🔁 0    💬 0    📌 0
Preview
NoiseLetter May 2025 Get GreyNoise updates! Read the May 2025 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.

It's may almost be summer, but not before you check out this month's NoiseLetter! 🌊 https://www.greynoise.io/resources/noiseletter-may-2025

29.05.2025 15:37 — 👍 0    🔁 0    💬 0    📌 0
Post image

We are back this Thursday for another GreyNoise University LIVE, tune in for demos, news + what to expect this month! 🔗https://www.greynoise.io/events/greynoise-university-live

27.05.2025 22:26 — 👍 0    🔁 2    💬 0    📌 0
Post image

GreyNoise Discovers Stealthy Backdoor Campaign Targeting ASUS Routers. Attacker tradecraft reflects APT-like behavior: quiet, durable, and designed for long-term access. Full blog […]

[Original post on infosec.exchange]

28.05.2025 13:32 — 👍 0    🔁 1    💬 0    📌 0
Post image

We are back this Thursday for another GreyNoise University LIVE, tune in for demos, news + what to expect this month! 🔗https://www.greynoise.io/events/greynoise-university-live

27.05.2025 22:26 — 👍 0    🔁 2    💬 0    📌 0
Original post on infosec.exchange

🚨 On May 8, GreyNoise observed a coordinated scanning operation launched by 251 malicious IPs, all hosted by Amazon and geolocated in Japan. ColdFusion, Apache Struts, Tomcat targeted. Full analysis […]

27.05.2025 16:50 — 👍 1    🔁 1    💬 0    📌 0
Post image

GreyNoise observed a major spike in scanning against Ivanti products weeks before two zero-days were disclosed in Ivanti EPMM. Full update: https://www.greynoise.io/blog/surge-ivanti-connect-secure-scanning-activity
#Ivanti #GreyNoise #Cybersecurity #ZeroDays

20.05.2025 19:54 — 👍 0    🔁 1    💬 0    📌 0
Preview
GreyNoise Webinar - How Resurgent Vulnerabilities Jeopardize Organizational Security Join GreyNoise Founder & Chief Architect Andrew Morris and VP of Data Science Bob Rudis as they break down key insights from our latest 2025 report, A Blindspot in Cyber Defense: How Resurgent Vulnerabilities Jeopardize Organizational Security.

Old CVEs, new nightmares 😱 Resurgent vulns are rewriting the risk equation..are you prepared? Join @morris + @hrbrmstr next week as they unpack key insights from our latest 2025 report.

https://info.greynoise.io/webinar/how-resurgent-vulnerabilities-jeopardize-organizational-security

20.05.2025 17:15 — 👍 0    🔁 0    💬 0    📌 0