On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the ...
When a new CVE hits critical perimeter systems, it can trigger emergency response and disruption. Early warnings from GreyNoise let teams prepare in advance and minimize impact ...
Actionable intelligence on real-world threats as they unfold. Get insights into attacker behavior, infrastructure, exploitation of zero-days and n-days, temporal pattern, and geographic hotspots — all ...
GreyNoise measured 212 exploitation attempts per second across H2 2025 — and the patterns inside that volume expose specific, measurable gaps in common edge defense strategies. The 2026 GreyNoise ...
GreyNoise’s new research reveals a recurring pattern: spikes in malicious activity often precede the disclosure of new CVEs — especially in enterprise edge technologies like VPNs and firewalls. In 80 ...
In a significant escalation, the botnet has grown to ~300,000 IPs — more than tripling in size. The threat actor(s) continues its focus on RDP infrastructure in the United States, leveraging IPs from ...
The internet changes before the advisory drops. GreyNoise found that activity surges in sensor data precede vulnerability disclosures by a median of 11 days — a pattern that held across 33 CVEs and 16 ...
Coordinated Brute Force Activity Targeting Apache Tomcat Manager Indicates Possible Upcoming Threats
Roughly 400 unique IPs were involved in the activity observed across both tags during this period of elevated activity. Most of the activity originating from these IPs exhibited a narrow focus on ...
Mass exploitation is faster and broader than ever. 40% of exploited CVEs in 2024 were at least four years old — some dating back to the 1990s. Attackers are targeting zero-days within hours of ...
GreyNoise has identified a notable surge in scanning activity targeting MOVEit Transfer systems, beginning on May 27, 2025. Prior to this date, scanning was minimal — typically fewer than 10 IPs ...
Exploitation of the CVE-2024-3273 command injection vulnerability requires the two valid `user=` and `passwd=` parameters. There is a companion vulnerability tracked as CVE-2024-3272 and describes the ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results