#greynoise
React2Shell exploitation frequency in GreyNoise dec 5-dec 6
December 7, 2025 at 4:14 PM
little GreyNoise (@greynoise.bsky.social) pipeline update
January 31, 2025 at 8:04 PM
GreyNoise Discovers Stealthy Backdoor Campaign Targeting ASUS Routers. Attacker tradecraft reflects APT-like behavior: quiet, durable, and designed for long-term access. Full blog ⬇️

#Cybersecurity #ThreatIntel #GreyNoise #ASUS
GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers
GreyNoise uncovers a stealth campaign exploiting ASUS routers, enabling persistent backdoor access via CVE-2023-39780 and unpatched techniques. Learn how attackers evade detection, how GreyNoise disco...
www.greynoise.io
May 28, 2025 at 1:33 PM
Check out viz.greynoise.io/query/last_s.... Collecting, labeling, and decimating this data is literally our mission.
GreyNoise Visualizer
At GreyNoise, we collect and analyze untargeted, widespread, and opportunistic scan and attack activity that reaches every server directly connected to the Internet.
viz.greynoise.io
December 6, 2024 at 9:41 AM
Greynoise, Zagreb.
September 4, 2026 at 7:46 PM
🚨 GreyNoise uncovered a previously untracked botnet, mostly based in Taiwan. Detected using JA4H + JA4T behavioral fingerprinting. Full analysis and list of IPs ⬇️ #GreyNoise #ThreatIntel #Cybersecurity
GreyNoise Identifies New Scraper Botnet Concentrated in Taiwan
GreyNoise has identified a previously untracked variant of a scraper botnet, detectable through a globally unique network fingerprint. To detect it, GreyNoise analysts created a signature using JA4+, ...
www.greynoise.io
July 9, 2025 at 1:05 PM
Yall are beyond not ready about the shit we're cooking up with @censys.bsky.social and @greynoise.io powers combined

censys.com/blog/hunting...
Hunting Botnets With CursorAI, GreyNoise, Censys, and Censeye
Threat hunting is made easier and simpler by combining the power of Censys, GreyNoise, CursorAI, and Censeye.
censys.com
April 21, 2025 at 7:12 PM
We deployed MCP honeypots to understand how threat actors engage with AI middleware exposed to the internet. What we observed was unexpected. Full analysis ⬇️
#GreyNoise #AI #AISecurity #MCP #MCPSecurity #Cybersecurity #ThreatIntel
What GreyNoise Learned from Deploying MCP Honeypots
GreyNoise deployed MCP honeypots to see what happens when AI middleware meets the open internet — revealing how attackers interact with this new layer of AI infrastructure.
www.greynoise.io
November 5, 2025 at 7:15 PM
GreyNoise has observed exploit attempts targeting CVE-2023-28771 — an RCE vuln affecting Zyxel devices. Full analysis + malicious IPs ⬇️

#Cybersecurity #ThreatIntel #Vulnerabilities #GreyNoise
GreyNoise Observes Exploit Attempts Targeting Zyxel CVE-2023-28771
‍On June 16, GreyNoise observed exploit attempts targeting CVE-2023-28771 — a remote code execution vulnerability affecting Zyxel Internet Key Exchange (IKE) packet decoders over UDP port 500.
www.greynoise.io
June 16, 2025 at 9:04 PM
Bob's GreyNoise Labs QBR is an interactive super mario video game I am VERKLEMPT @hrbrmstr.dev
February 14, 2025 at 6:10 PM
We have a serious problem with vulnerable gateway/edge devices. Andrew Morris from Greynoise says exploitation of these types of vulns is at crisis levels. Get this stuff off your network boundary!

Full show: www.youtube.com/watch?v=Rxye...
November 22, 2024 at 12:32 AM
GreyNoise 🤝 You
Explore our open roles + see if your next opportunity is with us!
🔗 www.greynoise.io/careers
December 3, 2024 at 8:02 PM
👀 React2Shell attacker profiles fresh from GreyNoise telemetry: info.greynoise.io/hubfs/PDFs-S..., don't miss the latest contribution from GreyNoise Labs on React2Shell: www.labs.greynoise.io/grimoire/202...

#React2Shell #Nextjs #CVE202555182 #CVE #GreyNoise
December 9, 2025 at 6:59 PM
psychic.labs.greynoise.io - Offline, in-memory bitmaps of GreyNoise data. Available now.
August 21, 2025 at 6:10 PM
🚨 GreyNoise has observed a surge in scanning activity against MOVEit Transfer. Read the blog & see suspicious and malicious IPs ⬇️

#GreyNoise #ThreatIntel #Cybersecurity
Surge in MOVEit Transfer Scanning Activity Could Signal Emerging Threat Activity
GreyNoise has identified a notable surge in scanning activity targeting MOVEit Transfer systems, beginning on May 27, 2025. Prior to this date, scanning was minimal — typically fewer than 10 IPs obser...
www.greynoise.io
June 25, 2025 at 1:07 PM
This is cool @feedly.com. Thanks for working with us on it.

It's true- Feedly uplevels our detection game in a big way @ GreyNoise.

feedly.com/customers/po...
Case Study: GreyNoise Doubles Detection Output with Feedly | Feedly
Discover how GreyNoise used Feedly Threat Intelligence to automate OSINT workflows, double detection output, and save hours of manual effort daily.
feedly.com
January 30, 2025 at 9:16 PM
The new GreyNoise Visualizer just dropped 💥
We redesigned the GreyNoise Visualizer to match how defenders actually work.

Log in and hit "Try the New Visualizer" to explore it today.

🔗https://www.greynoise.io/blog/new-way-to-navigate-greynoise
August 17, 2026 at 6:16 PM
I posted a quick/fun little blog about the dangers of invisible bytes, particularly when everybody copies/pastes exploits without understanding them:

#vulnerability #exploit #greynoise #null #byte
GreyNoise Labs - Null problem! Or: the dangers of an invisible byte
A quick and silly post about a weird exploit situation
www.labs.greynoise.io
November 25, 2024 at 5:53 PM
Amplifying this from our /noiseletter/. Today marks a significant milestone for GreyNoise as we (essentially) launch GreyNoise v2.
1/5
December 4, 2024 at 10:56 PM
GreyNoise observed a major spike in scanning against Ivanti products weeks before two zero-days were disclosed in Ivanti EPMM. Full update: www.greynoise.io/blog/surge-i...
#Ivanti #GreyNoise #Cybersecurity #ZeroDays
May 20, 2025 at 7:54 PM
A single malicious cyber actor. One IP address. GreyNoise tracked a suspected Chinese-speaking actor across months of activity, from UniFi to WordPress to ZyXEL, including a novel CVE exploit hitting 996 switches across 48 countries.

Here's what we saw ⬇️
Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We detail a few of the more notable int...
www.greynoise.io
September 21, 2026 at 2:14 PM
🚨Active Exploitation Alert: Critical Apache Tomcat RCE (CVE-2025-24813). Majority of traffic targeting U.S.-based systems. Full analysis & attacker IPs⬇️
#ApacheTomcat #Apache #GreyNoise #Vulnerability #CVE202524813
GreyNoise Observes Active Exploitation of Critical Apache Tomcat RCE Vulnerability (CVE-2025-24813)
Attackers are actively exploiting Apache Tomcat servers by leveraging CVE-2025-24813. If successfully exploited it could enable remote code execution. GreyNoise has identified multiple IPs engaging in...
greynoise.io
March 20, 2025 at 7:31 PM