Skip to content

company

GreyNoise

GreyNoise is a cybersecurity firm that monitors internet-wide scanning and attack traffic, providing threat intelligence on mass exploitation activity.

Known aliases

  • GreyNoise Intelligence
  • GreyNoise Research

Relationships

No evidence-backed relationships are recorded.

Current stories

security21 publishers

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

Perspective Coverage

21 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence88
Adoption82
Hype gap−8
Incentives60
Confidence86
security6 publishers

Hundreds of AI agents drove one IP into 440 PaperCut servers across 48 countries

GreyNoise and Blackpoint Cyber trace the new PaperCut auth-bypass chain to one scanning address running AI agents against schools, which turns an unpatched print server from a maintenance ticket into a credential incident.

Perspective Coverage

6 publishers
Builder
Builder 31%
Operator
Operator 57%
Investor
Investor 12%

Reality

Evidence62
Adoption38
Hype gap+20
Incentives40
Confidence66
build1 publisher

Exploit development for PaperCut took under four hours from an empty workspace

GreyNoise says a likely Russian-speaking actor built and tested PaperCut exploits in a lab, then ran hundreds of agents on a Codex harness with a DeepSeek model against 440 servers in 48 countries. The sending infrastructure was already on its watchlist.

Publishers:greynoise.io

Reality

Evidence58
Adoption70
Hype gap+12
Incentives68
Confidence55