.png)
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
Analysis Period: August 30 – September 8, 2026
Credential collection was the highest-volume malicious activity this period, and almost none of it required a vulnerability. Environment files, cloud configuration and repository configuration hold credentials for other systems, and a correctly functioning web server returns them to anyone who asks for the right path. A patch queue never sees any of this.
Adversaries attempted CVE-2026-0257 in Palo Alto Networks PAN-OS from 64 sources on 02 September. The flaw is rated CVSS 9.1, has been in CISA KEV since May 2026, and CISA records known ransomware use. One source or none arrived on every other day of the window, and all 65 sources GreyNoise observed classified malicious.
Rented hosts on one network presented themselves as Googlebot while requesting environment files and cloud configuration. Those nine hosts produced roughly two thirds of all forged search engine crawler traffic GreyNoise observed, and the forged identity covered 63% of everything they sent. Relax rate limiting or logging by user agent, and this traffic gets the same treatment.
A single cloud-hosted source paired Oracle WebLogic remote code execution attempts with enumeration of an unauthenticated Cisco switch provisioning service. It supplied 36% of all attempts GreyNoise observed against CVE-2018-2628 and 35% of all switch provisioning enumeration. Four unrelated target classes sat within 337 connection attempts of one another, consistent with one scheduled pass.
A source that appeared on 01 September requested repository configuration files from web roots across a seven-day span. It contributed 24% of all such activity in the corpus before going quiet. This class of collection, alongside environment file crawling, is the largest malicious-intent volume of the period and maps to no CISA KEV entry.
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
Request a demo to learn more about GreyNoise's data and intelligence.
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
Analysis Period: August 30 – September 8, 2026
Credential collection was the highest-volume malicious activity this period, and almost none of it required a vulnerability. Environment files, cloud configuration and repository configuration hold credentials for other systems, and a correctly functioning web server returns them to anyone who asks for the right path. A patch queue never sees any of this.
Adversaries attempted CVE-2026-0257 in Palo Alto Networks PAN-OS from 64 sources on 02 September. The flaw is rated CVSS 9.1, has been in CISA KEV since May 2026, and CISA records known ransomware use. One source or none arrived on every other day of the window, and all 65 sources GreyNoise observed classified malicious.
Rented hosts on one network presented themselves as Googlebot while requesting environment files and cloud configuration. Those nine hosts produced roughly two thirds of all forged search engine crawler traffic GreyNoise observed, and the forged identity covered 63% of everything they sent. Relax rate limiting or logging by user agent, and this traffic gets the same treatment.
A single cloud-hosted source paired Oracle WebLogic remote code execution attempts with enumeration of an unauthenticated Cisco switch provisioning service. It supplied 36% of all attempts GreyNoise observed against CVE-2018-2628 and 35% of all switch provisioning enumeration. Four unrelated target classes sat within 337 connection attempts of one another, consistent with one scheduled pass.
A source that appeared on 01 September requested repository configuration files from web roots across a seven-day span. It contributed 24% of all such activity in the corpus before going quiet. This class of collection, alongside environment file crawling, is the largest malicious-intent volume of the period and maps to no CISA KEV entry.
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
Request a demo to learn more about GreyNoise's data and intelligence.