GreyNoise identified an increase in scanning and exploitation attempts targeting Digital Video Recorders (DVR) in Ukraine between 21 September and 1 October 2026. The activity coincides with an ...
On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the ...
We use cookies to ensure you get the best experience on our website. Learn more ...
Actionable intelligence on real-world threats as they unfold. Get insights into attacker behavior, infrastructure, exploitation of zero-days and n-days, temporal pattern, and geographic hotspots — all ...
Oops! Something went wrong while submitting the form. Be part of the conversation in our Community Slack group.
GreyNoise’s new research reveals a recurring pattern: spikes in malicious activity often precede the disclosure of new CVEs — especially in enterprise edge technologies like VPNs and firewalls. In 80 ...
Mass exploitation is faster and broader than ever. 40% of exploited CVEs in 2024 were at least four years old — some dating back to the 1990s. Attackers are targeting zero-days within hours of ...
GreyNoise has identified a notable surge in scanning activity targeting MOVEit Transfer systems, beginning on May 27, 2025. Prior to this date, scanning was minimal — typically fewer than 10 IPs ...
GreyNoise measured 212 exploitation attempts per second across H2 2025 — and the patterns inside that volume expose specific, measurable gaps in common edge defense strategies. The 2026 GreyNoise ...
GreyNoise analyzed 2.97 billion sessions over 162 days in H2 2025, and the patterns reveal where edge defenses hold up — and where they fall short. The data exposes specific concentration points in ...
Coordinated Brute Force Activity Targeting Apache Tomcat Manager Indicates Possible Upcoming Threats
Roughly 400 unique IPs were involved in the activity observed across both tags during this period of elevated activity. Most of the activity originating from these IPs exhibited a narrow focus on ...
SnakeYAML has slithered its way into a deserialization vulnerability, with versions before 2.0 allowing remote code execution when used to parse untrusted input. In this GreyNoise Labs post, Lead ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results