At The Edge Clear: June 15 - 23, 2026

Table of Contents
Loading nav...

‍

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

‍

Amid FortiBleed, GreyNoise Tracks the Fortinet Attack Surface, as Cisco VPN Brute-Force Sources Surge

Analysis Period: June 15 to June 23, 2026

GreyNoise is not attributing this activity to FortiBleed; the brute-force it tracked stood down in early June. Also this week: a German-hosted source harvesting application secrets, and broadening Hikvision camera targeting.

‍

By The Numbers:

  • Fortinet β€” GreyNoise's read on the SSL VPN brute-force surface, which stood down in early June.
  • 3,645 β€” Sources brute-forcing Cisco SSL VPN on June 23, up from double digits a week earlier.
  • Secrets β€” A German-hosted source harvesting Laravel and TeleMessage credentials.
  • Hikvision β€” Camera RCE targeting broadened across new and returning sources (CISA KEV).

‍

Preview Findings:

1. GreyNoise's read amid FortiBleed

Amid FortiBleed, GreyNoise is providing telemetry on the same Fortinet surfaces the reporting names, without attributing the activity at this time. A Fortinet SSL VPN brute-force GreyNoise tracked for months stood down in early June, and exploitation of the named vulnerabilities is minimal. Reset Fortinet credentials and enforce MFA per CISA guidance.

2. Cisco SSL VPN brute-force sources surge

Distinct sources brute-forcing Cisco SSL VPN portals jumped to 3,645 on June 23, from double digits a week earlier. A subset also hit other vendors' VPN logins, so MFA and account lockout belong on every VPN edge, not just Cisco.

3. Secrets-theft source hunts Laravel and TeleMessage credentials

A German-hosted source is harvesting application secrets, probing Laravel CVE-2024-29291 and TeleMessage CVE-2025-48927 (/heapdump, CISA KEV) alongside heavy scanning for exposed .env, Git, AWS, and Spring Boot Actuator files. The focus points to deliberate harvesting, not opportunistic crawling.

4. Hikvision camera targeting broadened

Scanning for the Hikvision /SDK/webLanguage endpoint (CVE-2021-36260, CISA KEV) broadened across new and returning Netherlands-hosted sources. Treat any exposed Hikvision device answering these probes as potentially vulnerable.

‍

‍

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

‍Request a demo to learn more about GreyNoise's data and intelligence.

‍

‍

‍

‍

‍

‍

Read the transcript

‍

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

‍

Amid FortiBleed, GreyNoise Tracks the Fortinet Attack Surface, as Cisco VPN Brute-Force Sources Surge

Analysis Period: June 15 to June 23, 2026

GreyNoise is not attributing this activity to FortiBleed; the brute-force it tracked stood down in early June. Also this week: a German-hosted source harvesting application secrets, and broadening Hikvision camera targeting.

‍

By The Numbers:

  • Fortinet β€” GreyNoise's read on the SSL VPN brute-force surface, which stood down in early June.
  • 3,645 β€” Sources brute-forcing Cisco SSL VPN on June 23, up from double digits a week earlier.
  • Secrets β€” A German-hosted source harvesting Laravel and TeleMessage credentials.
  • Hikvision β€” Camera RCE targeting broadened across new and returning sources (CISA KEV).

‍

Preview Findings:

1. GreyNoise's read amid FortiBleed

Amid FortiBleed, GreyNoise is providing telemetry on the same Fortinet surfaces the reporting names, without attributing the activity at this time. A Fortinet SSL VPN brute-force GreyNoise tracked for months stood down in early June, and exploitation of the named vulnerabilities is minimal. Reset Fortinet credentials and enforce MFA per CISA guidance.

2. Cisco SSL VPN brute-force sources surge

Distinct sources brute-forcing Cisco SSL VPN portals jumped to 3,645 on June 23, from double digits a week earlier. A subset also hit other vendors' VPN logins, so MFA and account lockout belong on every VPN edge, not just Cisco.

3. Secrets-theft source hunts Laravel and TeleMessage credentials

A German-hosted source is harvesting application secrets, probing Laravel CVE-2024-29291 and TeleMessage CVE-2025-48927 (/heapdump, CISA KEV) alongside heavy scanning for exposed .env, Git, AWS, and Spring Boot Actuator files. The focus points to deliberate harvesting, not opportunistic crawling.

4. Hikvision camera targeting broadened

Scanning for the Hikvision /SDK/webLanguage endpoint (CVE-2021-36260, CISA KEV) broadened across new and returning Netherlands-hosted sources. Treat any exposed Hikvision device answering these probes as potentially vulnerable.

‍

‍

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

‍Request a demo to learn more about GreyNoise's data and intelligence.

‍

‍

‍

‍

‍

‍