At The Edge Clear: August 17 - 23, 2026

Table of Contents
Loading nav...

‍

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

‍

Commercial Scanner Drove Log4Shell Volume

Analysis Period: August 17 - 23, 2026

Roughly three fifths of the traffic carrying the Log4Shell exploitation tag this period came from one address range that resolves to a commercial vulnerability management service, not from an adversary. The flaws whose source populations contained nothing benign ran at two-digit volumes, well below anything a volume-ordered remediation queue surfaces. Defenders should rank on Known Exploited Vulnerabilities (KEV) listing and internet reachability instead, and resolve the operator behind an attempt figure before acting on it.

‍

By The Numbers:

  • 61% β€” Of Log4Shell tag traffic came from one commercial scanner.
  • ~8x β€” More sources sweeping SharePoint for ToolShell than attempting the exploit.
  • 100% β€” GeoServer XML external entity sources classed malicious.
  • 1 day β€” Both SD-WAN known-exploited bursts, then near silence.

‍

Preview Findings:

1. One address range carried most of the Log4Shell tag volume

Log4Shell, CVE-2021-44228, still draws heavy traffic. This period, 61% of the attempts carrying its exploitation tag came from a single range that resolves to a commercial vulnerability management service. The same range supplied 35% of generic cross-site scripting request volume and 26% of double URL encoding volume, but only 1% of broad signatures such as Generic Sensitive File Access Attempt. Inflation is worst where a flaw is most famous.

2. Sources are sweeping SharePoint farms for the ToolShell web shell

Roughly eight times more sources spent this period checking whether SharePoint farms already carry the ToolShell web shell than attempting the exploit itself. They did so on every one of the seven days. A patch closes the route in; it does not remove a shell already written. Organizations that patched in July and closed the ticket should reopen it as an artifact hunt.

3. Two SD-WAN management flaws, one single day

Adversaries attempted flaws in Cisco Catalyst SD-WAN Manager and Citrix NetScaler SD-WAN on 17 August. Both are in CISA's KEV catalog and were disclosed nine years apart. Each burst lasted one day and neither source set contained a benign member. A controller sits above every branch site it configures. Build detection on first sighting of the request path rather than on a rate threshold.

4. GeoServer discovery ran ahead of the attempts

Adversaries attempted a known exploited GeoServer XML external entity flaw across the final three days of the period. They ran at 12, 16 and 7 sources on 21, 22 and 23 August, every one classified malicious. Discovery traffic against the same product ran far heavier and across the whole window. That gap between discovery and exploitation is the warning time a patch cycle has to beat.

‍

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

‍Request a demo to learn more about GreyNoise's data and intelligence.

‍

‍

‍

‍

‍

‍

‍

‍

‍

‍

‍

‍

Read the transcript

‍

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

‍

Commercial Scanner Drove Log4Shell Volume

Analysis Period: August 17 - 23, 2026

Roughly three fifths of the traffic carrying the Log4Shell exploitation tag this period came from one address range that resolves to a commercial vulnerability management service, not from an adversary. The flaws whose source populations contained nothing benign ran at two-digit volumes, well below anything a volume-ordered remediation queue surfaces. Defenders should rank on Known Exploited Vulnerabilities (KEV) listing and internet reachability instead, and resolve the operator behind an attempt figure before acting on it.

‍

By The Numbers:

  • 61% β€” Of Log4Shell tag traffic came from one commercial scanner.
  • ~8x β€” More sources sweeping SharePoint for ToolShell than attempting the exploit.
  • 100% β€” GeoServer XML external entity sources classed malicious.
  • 1 day β€” Both SD-WAN known-exploited bursts, then near silence.

‍

Preview Findings:

1. One address range carried most of the Log4Shell tag volume

Log4Shell, CVE-2021-44228, still draws heavy traffic. This period, 61% of the attempts carrying its exploitation tag came from a single range that resolves to a commercial vulnerability management service. The same range supplied 35% of generic cross-site scripting request volume and 26% of double URL encoding volume, but only 1% of broad signatures such as Generic Sensitive File Access Attempt. Inflation is worst where a flaw is most famous.

2. Sources are sweeping SharePoint farms for the ToolShell web shell

Roughly eight times more sources spent this period checking whether SharePoint farms already carry the ToolShell web shell than attempting the exploit itself. They did so on every one of the seven days. A patch closes the route in; it does not remove a shell already written. Organizations that patched in July and closed the ticket should reopen it as an artifact hunt.

3. Two SD-WAN management flaws, one single day

Adversaries attempted flaws in Cisco Catalyst SD-WAN Manager and Citrix NetScaler SD-WAN on 17 August. Both are in CISA's KEV catalog and were disclosed nine years apart. Each burst lasted one day and neither source set contained a benign member. A controller sits above every branch site it configures. Build detection on first sighting of the request path rather than on a rate threshold.

4. GeoServer discovery ran ahead of the attempts

Adversaries attempted a known exploited GeoServer XML external entity flaw across the final three days of the period. They ran at 12, 16 and 7 sources on 21, 22 and 23 August, every one classified malicious. Discovery traffic against the same product ran far heavier and across the whole window. That gap between discovery and exploitation is the warning time a patch cycle has to beat.

‍

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

‍Request a demo to learn more about GreyNoise's data and intelligence.

‍

‍

‍

‍

‍

‍

‍

‍

‍

‍

‍

‍