2K Followers
31 Following
533 Posts

GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats.

(Yes, it's really us. - Love, GreyNoise )

May the 4th be with you + so be the signal. πŸš€
The April Noiseletter is live: Project Swarm is open to the global security community, new research drops, and a packed events calendar. Let's get into it. πŸ‘‡
https://www.greynoise.io/resources/noiseletter-april-2026
NoiseLetter April 2026

Get GreyNoise updates! Read the April 2026 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.

Today's the perfect day for a matinee double feature:

GreyNoise University LIVE: https://www.greynoise.io/events/greynoise-university-live

The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse Webinar: https://info.greynoise.io/webinar/invisible-army?_ga=2.231440415.1063083880.1777487534-981227823.1753375781

We're so back, after taking last month off, we are refreshed + ready for April's GreyNoise University LIVE!!

πŸ“Ί Tune in TOMORROW at 12 ET! https://www.greynoise.io/events/greynoise-university-live

Check out Project Swarm today: https://www.greynoise.io/project-swarm
Project Swarm | GreyNoise Intelligence

Project Swarm is a research initiative that opens the GreyNoise deception platform to the global security community. When you deploy a GreyNoise sensor through Project Swarm, you get visibility into all the traffic hitting that sensor, and everything your sensor captures is yours to work with.

Introducing Project Swarm: a research initiative to defend the network edge and we're inviting you to join. Deploy a sensor on your infrastructure, capture real attacker traffic + compare what's hitting you to the GreyNoise global baseline. Join today! 🐝

Residential proxies, sleep cycles, and 4 BILLION sessions πŸ‘€

Join us Thursday, April 30th at 2pm ET to see why IP reputation is broken against home traffic + what actually works instead.

Save your spot now πŸ‘‡https://info.greynoise.io/webinar/invisible-army

Webinar - The Invisible Army: What 4 Billion Sessions Reveal About Residential Proxy Abuse

This webinar presents the full findings of the latest report on residential proxy abuse β€” why IP reputation is structurally broken against this traffic, behavioral patterns consistent with compromised home PCs following the human sleep cycle, and what four separate threats hiding behind one label mean for detection strategy.

GreyNoise At The Edge β€” April 13–20, 2026. Four themes dominated activity on the GreyNoise sensor network this week β€” spanning reconnaissance, exploitation attempts, credential brute-forcing, and botnet recruitment.

1. A broad credential and configuration discovery campaign ran at ~6.2M sessions across hundreds of IPs β€” ENV files, .git/config, AWS metadata, path traversal, sensitive file access. The biggest real story, distributed rather than concentrated.

2. VNC scanning surged to the third-most-targeted port on the internet β€” port 5900 at 17.4M sessions. Not in prior briefs.

3. A new multi-cloud Masscan framework activated this week. Shared JA3 across a new Poland IP and an existing DigitalOcean Singapore cluster.

4. VPSVAULT IoT worm weaponized CVE-2025-54322 (Xspeeder SXZOS, CVSS 10.0). CVE-2026-24061 (GNU telnetd, CVSS 9.8, CISA KEV) also in payload.

Full Report: https://www.greynoise.io/resources/at-the-edge-clear-042026

#ThreatIntel #CyberSecurity #InfoSec #GreyNoise

At The Edge Clear: April 13 - 20, 2026

This week's report covers credential discovery, VNC exposure, and a new multi-cloud scanning framework.

11 hosting ASNs appeared in pre-disclosure surges across 3+ vendor families. When targeting concentrates, lead time drops from 21 days to 7.5. The infrastructure behind these surges is recognizable. https://www.greynoise.io/resources/ten-days-before-zero
Ten Days Before Zero: How Activity Surges in GreyNoise Data Precede Vulnerability Disclosure

Attackers are moving before disclosures. GreyNoise shows how surge activity can signal vulnerabilities days before CVEs are published.

See you in Glasgow for #CyberUK! πŸ‡¬πŸ‡§

Find GreyNoise at Booth D2 + catch our talks:
πŸ—“ Apr 22, 12:20 – Nishawn Smagh
πŸ—“ Apr 23, 14:30 – Glenn Thorpe III

Happy Hour @ Golf Fang on Apr 22 ⛳️

Book 1:1 time: https://info.greynoise.io/cyberuk-meet-with-us

#CyberSecurity #ThreatIntelligence #GreyNoise

CyberUK| Meet With Us | GreyNoise Intelligence

GreyNoise is proud to be a sponsor and speaker at this years CyberUK conference. Here are all the different ways you can engage with GreyNoise during the event.

Atlanta!!! πŸ‘

We will be in town for the CrowdStrike #CrowdTour this week + we're kicking things off early with a Happy Hour TOMORROW! Come hang out with us from 4-6 at the Blue Moon Brewery & Grill. 🍻

https://info.greynoise.io/event/happy-hour-atlanta

GreyNoise | Happy Hour Atlanta

We’re leaving the slide decks and sales pitches at the office in favor of cold beers and genuine conversation. Join us to unwind, talk shop (or not), and enjoy a relaxed evening with your Atlanta peers.