Check out this month's NoiseLetter for the latest on Ghostie + all things GreyNoise!
ποΈhttps://www.greynoise.io/resources/noiseletter-january-2026
GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats.
(Yes, it's really us. - Love, GreyNoise )
Check out this month's NoiseLetter for the latest on Ghostie + all things GreyNoise!
ποΈhttps://www.greynoise.io/resources/noiseletter-january-2026
Two IPs now generate 56% of all CVE-2025-55182 exploitation traffic.
One deploys cryptominers. The other opens reverse shells.
We dug into the infrastructure. What we found goes back to 2020.
https://www.greynoise.io/blog/react2shell-exploitation-consolidates
In 2025, 59 CVEs quietly flipped to βknown ransomware useβ in CISAβs KEV...no alerts, no fanfare. π§
We dug through a year of JSON to catch every silent flip and built an RSS feed so you donβt miss the next one.
Read the blog + grab the feed ποΈ
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
π Seeing whoβs poking Ivanti Connect Secure?
GreyNoise just caught a ~100x spike in recon on CVE-2025-0282 featuring one loud AS213790 campaign and one sneaky botnet spread across 6K IPs.
We broke down the infra + what defenders should do next. π
https://www.labs.greynoise.io/grimoire/2026-01-29-inside-the-infrastructure-whos-scanning-for-ivanti-connect-secure/
Join us tomorrow at 12 ET for 2026's first GreyNoise University LIVE! With a new co-host, David! Looking forward to seeing you there. πͺ©https://www.greynoise.io/events/greynoise-university-live
Most attacker behavior only makes sense over time. π°οΈ
Recall brings time-series analysis to GNQL so you can see how scanning and exploitation evolved.
See the timeline. Find the pattern. https://www.greynoise.io/blog/recall-time-series-intelligence
Three campaigns. One fingerprint.
React RCE, VPN brute forcing, and router scanningβall linked to the same infrastructure.β 1.7M React attacks
β 506K VPN targets
β 3 IPs behind 1.8M router attempts
This week's At The Edge preview: http://greynoise.io/contact
The first runZero Hour of 2026 is almost here! π
Join hosts Rob King and @todb on January 21 as they talk all things OT security with guest Brianna Cluck from @greynoise.
π οΈ Brianna will provide the blueprint to set up your own ICS home lab.
π Rob will share his insights from the freshest OT research.
π¨ And of course, no episode would be complete without a Rapid Response Roundup, dissecting this month's notable vulnerabilities.
π Register now: https://www.runzero.com/research/runzero-hour/
Check out @hrbrmstr today on @huntress's Tradecraft Tuesday at 1pm ET to chat about all things #React2Shell. π€
Later today the epic @huntress team lets me crash the party to talk all things React2Shell.
Still time to reg!
Rly looking fwd to it. Tis not often one gets to meet ones heroes!
New on the GreyNoise blog: We borrow from some unexpected fields, enzyme kinetics, species biodiversity models, astrophotography, to understand internet-wide scanning activity and measure what we might be missing.
π¨ We are hiring across sales, alliances, and customer experience for our US + EMEA teams π
See a role you'd crush? We would love to hear from you!
π Apply now: greynoise.io/careers
GreyNoise analyzed activity targeting exposed Ollama and LLM infrastructure, identifying SSRF abuse attempts and large-scale probing of LLM model endpoints.
Analysis: https://www.greynoise.io/blog/threat-actors-actively-targeting-llms
#GreyNoise #ThreatIntelligence #LLMSecurity
Ransomware starts with reconnaissance: we observed a recent large-scale scanning campaign validating exploitable systems, data that feeds the initial access market and shows up later in real attacks. π΅οΈββοΈ
https://www.greynoise.io/blog/christmas-scanning-campaign-fuel-2026-attacks
Back from the holidays and afraid to open your inbox? Same. Open the latest NoiseLetter instead.
https://www.greynoise.io/resources/noiseletter-december-2025
React2Shell Update β 7 January 2026
Full update & analysis: https://www.greynoise.io/blog/cve-2025-55182-react2shell-opportunistic-exploitation-in-the-wild-what-the-greynoise-observation-grid-is-seeing-so-far
#React2Shell slingers had a party goin' on since the 25th and are still doing more with less.
Ginormous session counts from a fraction of the IPs.
New year, new opportunities? Check out our current openings for a new start in the new year! πͺ©π
π greynoise.io/careers
RE: https://infosec.exchange/@greynoise/115736358685164517
See ya'll in 10 β³
GreyNoise is tracking a coordinated credential-based campaign targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect.
π https://www.greynoise.io/blog/credential-based-campaign-cisco-palo-alto-networks-vpn-gateways
#Cisco #PaloAltoNetworks #GreyNoise #VPN #CiscoSSLVPN #GlobalProtect #ThreatIntel