Glenn
@ntkramer
Elder Millennial | 💼 Cybersecurity | I ask 'why?' a lot | Pro Oxford Comma | Fix it! | He/Him | #BLM | Views are my own.
It seems that CISA is, in fact, shortening the time-to-fix for vulns added to the KEV of late. (Casual reminder that the KEV should not be used as "what we should patch" but it is a signal worth watching for awareness). #threatintel
When the signal gets lost in the noise, you learn to tune into a new frequency. Sometimes change doesn’t ask; it hums beneath the static. #TheSignalShift
🍩 & #threatintel - 95% of exploitation attempts targeting CVE-2026-20045, a critical vulnerability in Cisco Unified Communications Manager, have used a distinctive user-agent: Mozilla/5.0 (compatible; CiscoExploit/1.0) and are heavily targeting our Cisco Unified Communications Manager sensors. 1/2
☕ & #threatintel: CISA has moved the due date for mitigating CVE-2025-55182 (Meta React Server Components Remote Code Execution Vulnerability) up by two weeks. It was initially set for December 26, but it is now due on December 12. 1/2
Ron (@iagox86.bsky.social) and I are presenting at #Suricon (Montreal) next month! If you're around, you'll definitely want to find us for some sweet swag (oh, and our talk is pretty cool too!). suricon.net/agenda-m...
🥤& #threat-intel: CISA added Langflow Code Injection CVE-2025-3248 to the KEV on May 5. Recently, it has garnered considerable attention, with South Korea leading the pack. This vuln enables unauthenticated attackers to execute arbitrary code via /api/v1/validate/code viz.greynoise.io/tag...
This change legitimately pisses me off. TL;DR—They appear to be removing RSS for KEV alerts and moving them to email or X. They gave orgs 0 days to prepare. RSS is already a thing. The emails arrive many hours later. X is NOT a gov website(!); it even warns you when you click their link! 1/2
Absolutely disgusting. The Trump admin (DHS) has repurposed opt-in email signups to spread their propaganda. Years ago (4+) I signed up for Homeland Security emails; I don't recall doing this but based on the ones in my email it was related to something cyber -- not surprising. 1/4
🍵 & #threatintel: @greynoise.io is observing a massive spike in exploitation attempts for CVE-2017-18368, Zyxel Command Injection Vulnerability. The source countries for this spike are pretty diverse; perhaps added to a botnet? viz.greynoise.io/tag...
Regarding the Murdoc botnet delivering Mirai malware (www.darkreading.com/...) GreyNoise has 👀 1) viz.greynoise.io/tag... 2) viz.greynoise.io/tag...
Censys released an advisory regarding Kerio CVE-2024-52875. We at GreyNoise began observing exploit attempts on December 28. Although the IP addresses involved are currently quite noisy, it's notable that they predominantly trace from Singapore to Lithuania. #threatintel viz.greynoise.io/tag...
Amplifying this from our /noiseletter/. Today marks a significant milestone for GreyNoise as we (essentially) launch GreyNoise v2. 1/5
We, @greynoise.bsky.social, are seeing a massive uptick in IPs attempting to authenticate via telnet using one of several known backdoor accounts in FiberHome routers. viz.greynoise.io/tag...
🎃 & #threatintel: We/GreyNoise have observed a significant increase in Fortinet SSL brute force attempts recently. This is the highest level in the past two months and the third highest of 2024. viz.greynoise.io/tag...
🗞️ & #threatintel: Increased interest in IPs attempting to exploit CVE-2023-4966, an unauthenticated information disclosure vulnerability in Citrix ADC & NetScaler platforms. viz.greynoise.io/tag...
☕️ & #threatintel: GreyNoise is observing a sizable increase in IPs attempting to brute-force credentials against Fortinet SSL VPNs. This is the most activity we've observed since mid January 2024. viz.greynoise.io/tag...
🎰 & #threatintel: GreyNoise has observed an increase in the exploitation of CVE-2021-28799 over the past few days. This vulnerability affects QNAP NAS devices and allows unauthorized remote access. viz.greynoise.io/tag...
I'll be around the hackery summery campy things this week starting late Tues; looking forward to all the things except the germs and exhaustion. See you around! #blackhat #BHUSA #DEFCON #defcon32 #brathacker #bsideslv #HackerSummercamp #didimissone
🌭 & #threatintel: Not loving the bump in interest of Cisco CVE-2019-1935 right before #blackhat #defcon week. viz.greynoise.io/tag...
🥪 & #threatintel: something suspicious a-bot this spike in IP addresses attempting to exploit Mikrotik CVE-2018-14847... new botnet/addition? viz.greynoise.io/tag... 1/2
🥪 & #threatintel: We're seeing a significant uptick (the most in the last 6+ months) in the inventorying of Outlook Web Access (OWA) instances; I can't imagine why... [Narrator: Microsoft’s June 2024 Patch Tuesday] viz.greynoise.io/tag...
⛱️ and #threatintel: GreyNoise has observed exploitation for CVE-2024-4577, a remote code execution vulnerability in Windows-based PHP installations. viz.greynoise.io/tag...