Ron Bowes's Avatar

Ron Bowes

@iagox86.bsky.social

Principal Security Researcher at GreyNoise. https://skullsecurity.org Mostly post about work stuff, maybe some improv stuff and maybe even magic some day. Seattle-based (originally Canadian), queer, cybersecurity nerd. (He/him)

3,169 Followers  |  703 Following  |  1,094 Posts  |  Joined: 23.05.2023  |  2.1322

Latest posts by iagox86.bsky.social on Bluesky

Preview
Palo Alto Scanning Surges ~500% in 48 Hours, Marking 90-Day High On October 3, 2025, GreyNoise observed a ~500% increase in IPs scanning Palo Alto Networks login portals, the highest level recorded in the past 90 days.Β The activity was highly targeted and involved ...

GreyNoise has linked three concurrent campaigns targeting remote-access technologies β€” Palo Alto login attempts, Fortinet SSL VPN brute-forcing, and Cisco ASA scanning β€” all partially driven by the same threat actor(s) [High Confidence]. Full analysis πŸ‘‡ #Palo #Cisco #Fortinet #ThreatIntel

08.10.2025 22:00 β€” πŸ‘ 7    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Pretty sure that's fake

09.10.2025 03:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Palo login attempts are escalating, potentially driven by iteration through a large credential dataset. GreyNoise is sharing observed usernames/passwords for defender review.

πŸ”— Latest: www.greynoise.io/blog/palo-al...

#PaloAltoNetworks #ThreatIntel

07.10.2025 21:03 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0

Also outright malicious repos.. I report them all the time and they only rarely get removed

06.10.2025 18:41 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
NoiseLetter September 2025 Get GreyNoise updates! Read the September 2025 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.

NoiseLetter, but make it fashionably late... πŸ’… We were at our company offsite, but we're back with our new GreyNoise MCP Server launch, Cisco ASA zero-day and VPN brute force insights, plus upcoming events, let's get into it!

06.10.2025 17:19 β€” πŸ‘ 7    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Preview
Palo Alto Scanning Surges ~500% in 48 Hours, Marking 90-Day High On October 3, 2025, GreyNoise observed a ~500% increase in IPs scanning Palo Alto Networks login portals, the highest level recorded in the past 90 days.Β The activity was highly targeted and involved ...

GreyNoise observed a ~500% surge in IPs scanning Palo Alto Networks login portals on October 3, 2025 β€” the highest level we’ve seen in 90 days. Read our full analysis here πŸ‘‡ #PaloAltoNetworks #PaloAlto #GreyNoise #ThreatIntel #PANOS

03.10.2025 21:01 β€” πŸ‘ 4    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Preview
Coordinated Grafana Exploitation Attempts on 28 September GreyNoise observed a sharp one-day surge of exploitation attempts targeting CVE-2021-43798 β€” a Grafana path traversal vulnerability that enables arbitrary file reads. All observed IPs are classified a...

On 28 September, GreyNoise observed a sharp one-day surge in attempts to exploit Grafana CVE-2021-43798. Full analysis & malicious IPs ⬇️
#Grafana #GreyNoise #ThreatIntel

02.10.2025 21:32 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0

Calling it "World War I" was just asking for trouble

01.10.2025 22:59 β€” πŸ‘ 8    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

GreyNoise now has coverage for Cisco zero-days CVE-2025-20333 and CVE-2025-20362. Watch for exploit attempts in real-time:

CVE-2025-20333 (Net new): viz.greynoise.io/tags/cisco-a...

CVE-2025-20362 (Updated tag): viz.greynoise.io/tags/cisco-a...

#CiscoASA #ZeroDay #CVE202520333 #CVE202520362

01.10.2025 22:24 β€” πŸ‘ 5    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

They're trying so hard to brand it as "democrat shutdown" that it just comes off as whiny and pathetic

But they've also bought all the media so it might even work :(

01.10.2025 21:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Everything I know about that movie is from the book Box Office Poison, but it made me want to watch it!

01.10.2025 16:48 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Creating a password requires entropy, and entropy is slowly killing the universe. Why do you want me to kill the universe??

01.10.2025 16:46 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

At least they didn't say "some experts believe ..."? Low bar, I know..

01.10.2025 15:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I was getting my (second shot of 3) Hepatitis B vaccine yesterday, and the nurse administering it asked if I knew where/how to get the COVID booster

Was it REALLY necessary to throw a ton of confusion into the vaccine situation??

30.09.2025 20:39 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I've learned never to underestimate them

29.09.2025 20:00 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

My thoughts exactly!

29.09.2025 17:11 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
How Ruby Went Off the Rails What happened to RubyGems, Bundler, and the Open Source drama that controls the internet infrastructure.

How Ruby went off the rails: A deep dive into the ownership and governance drama of some of the most important open source projects in the world

www.404media.co/how-ruby-wen...

29.09.2025 13:23 β€” πŸ‘ 72    πŸ” 19    πŸ’¬ 4    πŸ“Œ 6
Preview
First Malicious MCP in the Wild: The Postmark Backdoor That's Stealing Your Emails | Koi Blog

www.koi.security/blog/postmar...

28.09.2025 07:10 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Gabriella Lester and her volunteer

Gabriella Lester and her volunteer

"It's my fault, I asked if you could read, not if you could count" "if I could count I wouldn't have had four children"

--Gabriella Lester and her volunteer at Scoopfest

@heyscoops.bsky.social

27.09.2025 04:41 β€” πŸ‘ 11    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

"Some have criticized the officer who dropped the weapon for not handling it properly" can our media please give up this passive language bullshit? He clearly different handle it properly, you're allowed to take an editorial stand

27.09.2025 02:55 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0
Michael Goudeau eating a tomato while juggling

Michael Goudeau eating a tomato while juggling

Michael Goudeau getting into a trashbag

Michael Goudeau getting into a trashbag

Couple more

26.09.2025 22:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Michael Goudeau juggling tomatoes

Michael Goudeau juggling tomatoes

Michael Goudeau wondering how tall the room is

Michael Goudeau wondering how tall the room is

Michael Goudeau with a rubber band in his hair

Michael Goudeau with a rubber band in his hair

Michael Goudeau passing clubs

Michael Goudeau passing clubs

Wow, Michael Goudeau performed at Scoopfest! I didn't think I'd ever get to see him perform!

@heyscoops.bsky.social

26.09.2025 22:05 β€” πŸ‘ 15    πŸ” 3    πŸ’¬ 2    πŸ“Œ 0
Preview
25,000 IPs Scanned Cisco ASA Devices β€” New Vulnerability Potentially Incoming GreyNoise observed two scanning surges against Cisco Adaptive Security Appliance (ASA) devices in late August including more than 25,000 unique IPs in a single burst. This activity represents a signif...

Sept 25: Cisco disclosed two ASA/FTD zero-days (#CVE-2025-20333, #CVE-2025-20362).

Weeks earlier, GreyNoise saw 25k IPs scanning ASA β€” another case of recon surges preceding disclosures.

Read the update: www.greynoise.io/blog/scannin...

#CiscoASA #ZeroDay #Cisco

26.09.2025 20:51 β€” πŸ‘ 5    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

My feed this week is a mix of Scoopfest (improv/magic/podcast stuff) and security.. makes me miss the old days before the world turned into.. this

26.09.2025 18:28 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Matt shrink-wrapped

Matt shrink-wrapped

Matt and Nick Paul on stage

Matt and Nick Paul on stage

Nick Paul with his duplicating wine bottles

Nick Paul with his duplicating wine bottles

Nick Paul and @mindnoodler.bsky.social performing magic at Scoopfest!

@heyscoops.bsky.social

26.09.2025 18:26 β€” πŸ‘ 7    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Lindsay Benner juggling knives

Lindsay Benner juggling knives

Lindsay Benner balancing cups on her head

Lindsay Benner balancing cups on her head

Lindsay Benner with a ball in her mouth

Lindsay Benner with a ball in her mouth

Gary doing a book trick to introduce Lindsay Benner

Gary doing a book trick to introduce Lindsay Benner

Lindsay Benner and Gary @ Scoopfest! What a cool show!

@heyscoops.bsky.social

26.09.2025 18:22 β€” πŸ‘ 7    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

My strategy is to connect my phone to the hotel and my devices to my phone's mobile hotspot (assuming it can bridge)

We recently got a travel router to help solve this as well

26.09.2025 16:34 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I thought for sure that'd be X and it was why Musk was getting so cozy with the administration

26.09.2025 16:32 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2 We’re back, just over 24 hours later, to share our evolving understanding of CVE-2025-10035. Thanks to everyone who reached out after Part 1, and especially to the individual who shared credible inte...

Pretty unfortunate update on Fortra GoAnywhere MFT CVE-2025-10035 from the folks at watchTowr labs.watchtowr.com/it-is-bad-ex...

25.09.2025 20:08 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

@iagox86 is following 20 prominent accounts