Our latest analysis identified that attack activity typically spikes before a vulnerability is publicly disclosed. This report breaks down the patterns, infrastructure shifts, and attack progressions that signal what's coming.
On April 7, 2026 a fleet of 21 IP addresses produced 1,856,167 RDP Crawler sessions — 67.4% of global RDP Crawler activity that day.
Today, we're launching C2 Detection, a new GreyNoise intelligence module that gives you two distinct, high-confidence signals that a device in your environment has been compromised.
GreyNoise releases new report The Invisible Army: Residential Proxy Abuse in Internet-Scale Attack Traffic. An analysis of 4 billion malicious sessions reveals a disturbing pattern of attackers using compromised internet connections as a disguise to route malicious traffic.
The GreyNoise Observation Grid observed 242,666 new scanning IPs geolocating to Hong Kong in seven days and 99.7% of them never completed a single TCP connection.
GreyNoise's new and improved integration with Google SecOps delivers improved dashboards, detection rules, playbooks, and webhook support.
GreyNoise intelligence is now available across the CrowdStrike Falcon platform , bringing internet-wide scanning context to SIEM queries, SOAR workflows, and AI-driven triage.
84,000+ scanning sessions targeting SonicWall SonicOS infrastructure in four days. GreyNoise details a coordinated reconnaissance campaign using rotating proxy infrastructure.
GreyNoise Releases 2026 State of the Edge Report. Analysis of Nearly 3 Billion Malicious Sessions Quantifies Sustained Exploitation of VPN Appliances, Routers, and Remote Access Services.
A PoC for CVE-2026-1731 hit GitHub on Feb 10. Within 24 hours, GreyNoise observed reconnaissance probing for vulnerable BeyondTrust instances.
The GreyNoise Global Observation Grid observed active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities .
Two months after CVE-2025-55182 was disclosed on December 3, 2025, exploitation activity targeting React Server Components has consolidated significantly.
In 2025, 59 KEV entries silently flipped to “known ransomware use.” GreyNoise uncovers the hidden flips, why they matter, and a new feed to track them.
GreyNoise launches Recall , a time-series capability that enables customers to query GreyNoise data over specific historical ranges.
Dive into the scientific methods GreyNoise uses to separate internet noise from real threats, providing defenders a clearer, more accurate view of malicious activity.
Over four days in December, one operator scanned the internet for vulnerable systems, testing 240+ exploits and logging confirmed vulnerabilities that could power targeted intrusions in 2026.
GreyNoise is tracking a coordinated, automated credential-based campaign targeting enterprise VPN authentication infrastructure , with activity observed against Cisco SSL VPN and Palo Alto Networks GlobalProtect services.
Analyzing the payload size distribution across React2Shell attacks reveals a clear fingerprint of modern cybercrime, and a landscape dominated by automated scanners with a handful of sophisticated outliers.
GreyNoise is already seeing opportunistic, largely automated exploitation attempts consistent with the newly disclosed React Server Components “Flight” protocol RC E —often referred to publicly as “React2Shell” and tracked as CVE-2025-55182.
GreyNoise detected a surge of 7,000+ IPs attempting to log into GlobalProtect , sharing fingerprints with a surge in SonicWall API scanning and earlier Palo Alto campaigns, exposing a persistent credential-based attack pattern.
GreyNoise has identified a significant escalation in malicious activity targeting Palo Alto Networks GlobalProtect portals, reaching a 40x spike within just 24 hours.
GreyNoise has begun seeing active exploitation of CVE‑2025‑64446 , the critical path‑traversal flaw that lets an unauthenticated actor run administrative commands on Fortinet FortiWeb appliances.
GreyNoise releases query-based blocklists enabling customers to turn any GreyNoise query directly into a real-time blocklist for their firewall, SOAR, or other enforcement points.
EU sanctions hit Stark Industries in May 2025. GreyNoise data shows how the group quietly rebranded to THE.Hosting and kept its malicious infrastructure running.
GreyNoise deployed MCP honeypots to see what happens when AI middleware meets the open internet — revealing how attackers interact with this new layer of AI infrastructure.
From August through October 2025, GreyNoise observed a clear ramp-up in exploitation attempts against PHP and PHP-based frameworks as actors push to deploy cryptominers.
GreyNoise Welcomes New Director of Intelligence , Nishawn Smagh.
GreyNoise has observed steady deployments of previously unseen IPs attacking Microsoft RDP services through timing-based vulnerabilities.
Amid the security incident involving F5 BIG-IP announced on 15 October 2025, GreyNoise is sharing recent insights into activity targeting BIG-IP to aid in defensive posturing.
Since October 8, 2025, GreyNoise has tracked a coordinated botnet operation involving over 100,000 unique IP addresses from more than 100 countries targeting RDP services in the United States.
GreyNoise launches Feeds to enable real-time, event-driven threat intelligence that eliminates polling delays — helping defenders react instantly to new exploits, IP threats, and zero-day activity.
GreyNoise observed a ~500% increase in IPs scanning Palo Alto Networks login portals , the highest level recorded in the past 90 days.
On 28 September 2025, GreyNoise observed a sharp one-day surge of exploitation attempts targeting CVE-2021-43798 — a Grafana path traversal vulnerability that enables arbitrary file reads.
GreyNoise Intelligence launches model context protocol (MCP) server to power the future of agentic SOC.
GreyNoise observed two scanning surges against Cisco ASA devices in late August including more than 25,000 unique IPs in a single burst.
On August 21, GreyNoise observed a sharp surge in scanning against Microsoft Remote Desktop (RDP) services. The wave’s aim was clear: test for timing flaws that reveal valid usernames, laying the groundwork for credential-based intrusions.
On August 3, GreyNoise observed a significant spike in brute-force traffic targeting Fortinet SSL VPNs. Over 780 unique IPs in a single day — the highest single-day volume we’ve seen on this tag in recent months.
GreyNoise’s latest research reveals that spikes in attacker activity often precede the disclosure of new CVEs — typically within six weeks.
GreyNoise launches Block , a blocklist designed to be highly configurable, grounded in primary-sourced intelligence, and updated in real-time as attacker behavior changes.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
