At The Edge Clear: April 06 - 13, 2026

Table of Contents
Loading nav...

‍

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

‍

From Reconnaissance to Execution. Adversaries Operationalize at Scale.

Analysis Period: April 06 -13, 2026

This week's intelligence highlights a shift from opportunistic scanning to coordinated, targeted exploitation of enterprise perimeter devices and IoT infrastructure, with adversaries operationalizing prior reconnaissance at scale.

‍

By The Numbers:

  • 6,180,111 Sessions from VisionHeight scanning cluster
  • 1,652,443 Combined Fortinet exploitation sessions
  • +76.9% Mirai activity increase week-over-week
  • 13x Ollama AI scanning growth over three weeks

‍

Preview Findings:

VisionHeight Cluster Targets Enterprise Perimeters

Six AWS-hosted nodes sharing a single JA3 fingerprint systematically probed Fortinet, Palo Alto, Sophos, Ivanti, Citrix, ConnectWise, and F5 appliances β€” covering the full enterprise perimeter stack in one coordinated operation active since January. Fortinet FortiClient EMS API Auth Bypass Check >

‍

Fortinet Multi-Vector Exploitation Intensifies

FortiClient EMS authentication bypass (CVE-2026-35616, CVSS 9.1, CISA KEV) generated 1,535,690 sessions while SSL VPN brute-forcing trended upward β€” creating a dual-vector attack posture against the most targeted perimeter vendor. Fortinet SSL VPN Bruteforcer >

‍

IoT Botnet Recruitment Expands Against Volume Decline

Mirai activity increased 76.9% while overall volume fell 28.3%. The VPSVAULT cluster weaponized 16+ CVEs across cameras, routers, DVRs, and NAS devices with 2,732,814 combined sessions. Mirai >

‍

AI Infrastructure Under Systematic Reconnaissance

Ollama API endpoint scanning grew 93.6% for the second consecutive week β€” a thirteenfold increase over three weeks β€” as threat actors build inventories of exposed AI inference infrastructure. Ollama API Endpoint Crawler >

‍

‍

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

‍Request a demo to learn more about GreyNoise's data and intelligence.

‍

Read the transcript

‍

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

‍

From Reconnaissance to Execution. Adversaries Operationalize at Scale.

Analysis Period: April 06 -13, 2026

This week's intelligence highlights a shift from opportunistic scanning to coordinated, targeted exploitation of enterprise perimeter devices and IoT infrastructure, with adversaries operationalizing prior reconnaissance at scale.

‍

By The Numbers:

  • 6,180,111 Sessions from VisionHeight scanning cluster
  • 1,652,443 Combined Fortinet exploitation sessions
  • +76.9% Mirai activity increase week-over-week
  • 13x Ollama AI scanning growth over three weeks

‍

Preview Findings:

VisionHeight Cluster Targets Enterprise Perimeters

Six AWS-hosted nodes sharing a single JA3 fingerprint systematically probed Fortinet, Palo Alto, Sophos, Ivanti, Citrix, ConnectWise, and F5 appliances β€” covering the full enterprise perimeter stack in one coordinated operation active since January. Fortinet FortiClient EMS API Auth Bypass Check >

‍

Fortinet Multi-Vector Exploitation Intensifies

FortiClient EMS authentication bypass (CVE-2026-35616, CVSS 9.1, CISA KEV) generated 1,535,690 sessions while SSL VPN brute-forcing trended upward β€” creating a dual-vector attack posture against the most targeted perimeter vendor. Fortinet SSL VPN Bruteforcer >

‍

IoT Botnet Recruitment Expands Against Volume Decline

Mirai activity increased 76.9% while overall volume fell 28.3%. The VPSVAULT cluster weaponized 16+ CVEs across cameras, routers, DVRs, and NAS devices with 2,732,814 combined sessions. Mirai >

‍

AI Infrastructure Under Systematic Reconnaissance

Ollama API endpoint scanning grew 93.6% for the second consecutive week β€” a thirteenfold increase over three weeks β€” as threat actors build inventories of exposed AI inference infrastructure. Ollama API Endpoint Crawler >

‍

‍

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

‍Request a demo to learn more about GreyNoise's data and intelligence.

‍