At The Edge Clear: March 9-16, 2026

Table of Contents
Loading nav...

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

The Scanning Landscape Is Reorganizing

Analysis Period: March 9-16, 2026

A single Hong Kong cloud provider surged nearly sevenfold to become the dominant source of internet scanning. RDP operators rotate faster than blocklists. Edge device exploitation enters its fourth month — and it's re-accelerating.

By The Numbers:

  • 301.8M Sessions Observed
  • 439K Unique Source IPs
  • +578% UCLOUD Surge
  • +90.5% Sophos WK 4

Preview Findings:

UCLOUD Surges 578% to #1 Scanning Source

A single Hong Kong cloud provider surged nearly sevenfold, deploying a new tunneled fingerprint at 29.3M sessions. Western providers declined simultaneously.


Edge Device Siege: Month 4, Re-Accelerating

Sophos CVE-2022-1040 nearly doubled for the 4th consecutive week. SonicWall VPN doubled. Dell NetExtender appeared for the first time. Two Cisco CVSS 10.0 CVEs on CISA KEV. State-aligned and financially motivated actors converging on the same attack surface.


RDP Operators Rotate Faster Than Blocklists

MEVSPACE collapsed. Its replacement disappeared. RDP scanning surged 157%. The criminal ecosystem treats infrastructure as disposable.

React2Shell Reverses Decline

After weeks of contraction, CVE-2025-55182 surged 56.2%. New proxy infrastructure linked to known operators suggests campaign refresh.

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

Request a demo to learn more about GreyNoise's data and intelligence.

Read the transcript

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

The Scanning Landscape Is Reorganizing

Analysis Period: March 9-16, 2026

A single Hong Kong cloud provider surged nearly sevenfold to become the dominant source of internet scanning. RDP operators rotate faster than blocklists. Edge device exploitation enters its fourth month — and it's re-accelerating.

By The Numbers:

  • 301.8M Sessions Observed
  • 439K Unique Source IPs
  • +578% UCLOUD Surge
  • +90.5% Sophos WK 4

Preview Findings:

UCLOUD Surges 578% to #1 Scanning Source

A single Hong Kong cloud provider surged nearly sevenfold, deploying a new tunneled fingerprint at 29.3M sessions. Western providers declined simultaneously.


Edge Device Siege: Month 4, Re-Accelerating

Sophos CVE-2022-1040 nearly doubled for the 4th consecutive week. SonicWall VPN doubled. Dell NetExtender appeared for the first time. Two Cisco CVSS 10.0 CVEs on CISA KEV. State-aligned and financially motivated actors converging on the same attack surface.


RDP Operators Rotate Faster Than Blocklists

MEVSPACE collapsed. Its replacement disappeared. RDP scanning surged 157%. The criminal ecosystem treats infrastructure as disposable.

React2Shell Reverses Decline

After weeks of contraction, CVE-2025-55182 surged 56.2%. New proxy infrastructure linked to known operators suggests campaign refresh.

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

Request a demo to learn more about GreyNoise's data and intelligence.