.png)
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
Analysis Period: January 26–30, 2026
A single JA4T signature linked React, Fortinet, Palo Alto, and ENV campaigns across 3.3 million sessions. Combined with a 20M-session VNC reconnaissance surge and two-week RouterOS persistence, this week confirms coordinated operations targeting enterprise infrastructure at scale.
Netherlands-based infrastructure systematically enumerated VNC ports 5900-5920 with uniform distribution across ~100IPs. Reconnaissance at this scale typically precedes credential attacks.
MikroTik RouterOS brute force IPs from last week's brief continued without pause. 1.1 million authentication attempts. One IP dropped; new one emerged. Deliberate infrastructure management.
1 million CVE-2025-55182 attempts from the same top IPs. Three scanners rotate through 11 identical user agents spanning 6 platforms — a pattern consistent with LLM generated evasion lists.
585,000 combined sessions targeting Palo Alto GlobalProtect and Fortinet SSL VPN. Same IP ranges observed last week —persistent scanning infrastructure.
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
Request a demo to learn more about GreyNoise's data and intelligence.
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
Analysis Period: January 26–30, 2026
A single JA4T signature linked React, Fortinet, Palo Alto, and ENV campaigns across 3.3 million sessions. Combined with a 20M-session VNC reconnaissance surge and two-week RouterOS persistence, this week confirms coordinated operations targeting enterprise infrastructure at scale.
Netherlands-based infrastructure systematically enumerated VNC ports 5900-5920 with uniform distribution across ~100IPs. Reconnaissance at this scale typically precedes credential attacks.
MikroTik RouterOS brute force IPs from last week's brief continued without pause. 1.1 million authentication attempts. One IP dropped; new one emerged. Deliberate infrastructure management.
1 million CVE-2025-55182 attempts from the same top IPs. Three scanners rotate through 11 identical user agents spanning 6 platforms — a pattern consistent with LLM generated evasion lists.
585,000 combined sessions targeting Palo Alto GlobalProtect and Fortinet SSL VPN. Same IP ranges observed last week —persistent scanning infrastructure.
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
Request a demo to learn more about GreyNoise's data and intelligence.