.png)
β
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
β
Analysis Period: August 01 β August 10, 2026
This period's four findings share one exposure pattern: each involves a system that holds credentials or files for a secondary environment, so a successful attempt against one would likely open the next without a second exploit. Exploitation attempts reached six managed file transfer products, a business intelligence platform and a web application framework inside ten days, one of them compressed into a single day.
β
β
Exploitation attempts reached CrushFTP, MOVEit Transfer, GoAnywhere MFT, SolarWinds Serv-U, Wing FTP Server and Cleo, each on a CVE in CISA's Known Exploited Vulnerabilities (KEV) catalog. Of the 37 sources on one CrushFTP authentication bypass rated 9.8, 26 arrived on 02 August. Reconnaissance ran continuously underneath, at 58,237 probes against 760 exploitation attempts.
Attempts to bypass the Apache Superset login rose from three sources on 08 August to 40 on 09 August. The same day, sources sending payloads built to force an outbound callback rose from a steady 11 to 20, up to 90. The flaw is a signing key Superset ships by default, so remediation is a key rotation and a restart.
Two directory traversal flaws in Next.js each drew several hundred malicious sources, 458 and 409, moving day for day: a burst on 02 August, silence by 06 August, then a restart on 07 August. Almost every source carries both signatures, so this is one population of scanners, not two campaigns.
One cloud-hosted source ran credential file and cloud metadata harvesting for three days, 03 to 05 August, finished among the ten loudest sources of the period, and has not been seen since. Daily sources on cloud instance credential access climbed across the window, from 6 on 01 August to 227.
β
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
βRequest a demo to learn more about GreyNoise's data and intelligence.
β
β
β
β
β
β
β
β
β
β
β
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
β
Analysis Period: August 01 β August 10, 2026
This period's four findings share one exposure pattern: each involves a system that holds credentials or files for a secondary environment, so a successful attempt against one would likely open the next without a second exploit. Exploitation attempts reached six managed file transfer products, a business intelligence platform and a web application framework inside ten days, one of them compressed into a single day.
β
β
Exploitation attempts reached CrushFTP, MOVEit Transfer, GoAnywhere MFT, SolarWinds Serv-U, Wing FTP Server and Cleo, each on a CVE in CISA's Known Exploited Vulnerabilities (KEV) catalog. Of the 37 sources on one CrushFTP authentication bypass rated 9.8, 26 arrived on 02 August. Reconnaissance ran continuously underneath, at 58,237 probes against 760 exploitation attempts.
Attempts to bypass the Apache Superset login rose from three sources on 08 August to 40 on 09 August. The same day, sources sending payloads built to force an outbound callback rose from a steady 11 to 20, up to 90. The flaw is a signing key Superset ships by default, so remediation is a key rotation and a restart.
Two directory traversal flaws in Next.js each drew several hundred malicious sources, 458 and 409, moving day for day: a burst on 02 August, silence by 06 August, then a restart on 07 August. Almost every source carries both signatures, so this is one population of scanners, not two campaigns.
One cloud-hosted source ran credential file and cloud metadata harvesting for three days, 03 to 05 August, finished among the ten loudest sources of the period, and has not been seen since. Daily sources on cloud instance credential access climbed across the window, from 6 on 01 August to 227.
β
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
βRequest a demo to learn more about GreyNoise's data and intelligence.
β
β
β
β
β
β
β
β
β
β