.png)
β
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
β
Analysis Period: July 20-July 27, 2026
GreyNoise has tracked this credential-harvesting fleet since early July; this week one TLS client fingerprint and an identical tool kit link 64 rented hosts running as a single operation. Separately, one coordinated cluster of 300 hosts probed Citrix and Palo Alto gateways together, and two WordPress Core flaws that chain toward remote code execution stayed under probing after their CISA KEV listing.
β
β
One TLS fingerprint and an identical toolkit link 64 hosts running as a single credential-harvesting operation on rented infrastructure across several providers (Bucklog SARL, the 3xK Tech range). It crawls for exposed secret files at volume, driving about 6% of everythingGreyNoise observed. Hunt the shared fingerprint across providers.
A separate cluster of 300 rented hosts probed Citrix NetScaler and Palo Alto Networks GlobalProtect at once, every host carrying both a Citrix Bleed 2 (CVE-2025-5777, CISA KEV) exploit attempt signature and a GlobalProtect login scanner signature, from United States and Nordic hosting.
Two WordPress Core flaws added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 20 July kept drawing probing this week: CVE-2026-60137 (SQL injection), roughly 95 non-research sources, and CVE-2026-63030 (CVSS 9.8), which chains with it toward remote code execution. WordPress Core runs a very large share of public websites.
Each operation is defined by a durable behavior, a shared fingerprint or a co-occurring signature set, that persists as source addresses rotate. Last week's highest-volume brute force source, a United States ISP host, is still active but down about 73%.
β
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
βRequest a demo to learn more about GreyNoise's data and intelligence.
β
β
β
β
β
β
β
β
β
β
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
β
Analysis Period: July 20-July 27, 2026
GreyNoise has tracked this credential-harvesting fleet since early July; this week one TLS client fingerprint and an identical tool kit link 64 rented hosts running as a single operation. Separately, one coordinated cluster of 300 hosts probed Citrix and Palo Alto gateways together, and two WordPress Core flaws that chain toward remote code execution stayed under probing after their CISA KEV listing.
β
β
One TLS fingerprint and an identical toolkit link 64 hosts running as a single credential-harvesting operation on rented infrastructure across several providers (Bucklog SARL, the 3xK Tech range). It crawls for exposed secret files at volume, driving about 6% of everythingGreyNoise observed. Hunt the shared fingerprint across providers.
A separate cluster of 300 rented hosts probed Citrix NetScaler and Palo Alto Networks GlobalProtect at once, every host carrying both a Citrix Bleed 2 (CVE-2025-5777, CISA KEV) exploit attempt signature and a GlobalProtect login scanner signature, from United States and Nordic hosting.
Two WordPress Core flaws added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 20 July kept drawing probing this week: CVE-2026-60137 (SQL injection), roughly 95 non-research sources, and CVE-2026-63030 (CVSS 9.8), which chains with it toward remote code execution. WordPress Core runs a very large share of public websites.
Each operation is defined by a durable behavior, a shared fingerprint or a co-occurring signature set, that persists as source addresses rotate. Last week's highest-volume brute force source, a United States ISP host, is still active but down about 73%.
β
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
βRequest a demo to learn more about GreyNoise's data and intelligence.
β
β
β
β
β
β
β
β
β