GreyNoise identified an increase in scanning and exploitation attempts targeting Digital Video Recorders (DVR) in Ukraine between 21 September and 1 October 2026. The activity coincides with an ...
On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the ...
WASHINGTON, Sept. 23, 2026 -- GreyNoise Intelligence, the cybersecurity company that empowers defenders with real-time threat data about attacks at the network edge, today announced four senior hires ...
Source: GreyNoise Global Observation Grid and adversary infrastructure. Times are UTC. Jul 22 times come from preserved file timestamps and may differ from a forensic investigation.
GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies. These forged automated scanners have been observed requesting files ...
GreyNoise has spent years observing the earliest stages of an attack. Our Global Observation Grid sees adversaries as they scan the internet, probe exposed systems, and attempt to exploit ...
The internet changes before the advisory drops. GreyNoise found that activity surges in sensor data precede vulnerability disclosures by a median of 11 days — a pattern that held across 33 CVEs and 16 ...
Every enterprise firewall processes traffic from residential IP space. Traditional reputation feeds fail to flag IPs that rotate before they can be cataloged. GreyNoise analyzed 4 billion sessions ...
GreyNoise measured 212 exploitation attempts per second across H2 2025 — and the patterns inside that volume expose specific, measurable gaps in common edge defense strategies. The 2026 GreyNoise ...
GreyNoise analyzed 2.97 billion sessions over 162 days in H2 2025, and the patterns reveal where edge defenses hold up — and where they fall short. The data exposes specific concentration points in ...
Oops! Something went wrong while submitting the form. Be part of the conversation in our Community Slack group.
For GreyNoise Customers: A comprehensive IOC package with extended infrastructure, network fingerprints, and connected domains was sent directly to customers via email. Two months after CVE-2025-55182 ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results