.png)
β
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
β
Analysis Period: August 17 - 23, 2026
Roughly three fifths of the traffic carrying the Log4Shell exploitation tag this period came from one address range that resolves to a commercial vulnerability management service, not from an adversary. The flaws whose source populations contained nothing benign ran at two-digit volumes, well below anything a volume-ordered remediation queue surfaces. Defenders should rank on Known Exploited Vulnerabilities (KEV) listing and internet reachability instead, and resolve the operator behind an attempt figure before acting on it.
β
β
Log4Shell, CVE-2021-44228, still draws heavy traffic. This period, 61% of the attempts carrying its exploitation tag came from a single range that resolves to a commercial vulnerability management service. The same range supplied 35% of generic cross-site scripting request volume and 26% of double URL encoding volume, but only 1% of broad signatures such as Generic Sensitive File Access Attempt. Inflation is worst where a flaw is most famous.
Roughly eight times more sources spent this period checking whether SharePoint farms already carry the ToolShell web shell than attempting the exploit itself. They did so on every one of the seven days. A patch closes the route in; it does not remove a shell already written. Organizations that patched in July and closed the ticket should reopen it as an artifact hunt.
Adversaries attempted flaws in Cisco Catalyst SD-WAN Manager and Citrix NetScaler SD-WAN on 17 August. Both are in CISA's KEV catalog and were disclosed nine years apart. Each burst lasted one day and neither source set contained a benign member. A controller sits above every branch site it configures. Build detection on first sighting of the request path rather than on a rate threshold.
Adversaries attempted a known exploited GeoServer XML external entity flaw across the final three days of the period. They ran at 12, 16 and 7 sources on 21, 22 and 23 August, every one classified malicious. Discovery traffic against the same product ran far heavier and across the whole window. That gap between discovery and exploitation is the warning time a patch cycle has to beat.
β
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
βRequest a demo to learn more about GreyNoise's data and intelligence.
β
β
β
β
β
β
β
β
β
β
β
β
β
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
β
Analysis Period: August 17 - 23, 2026
Roughly three fifths of the traffic carrying the Log4Shell exploitation tag this period came from one address range that resolves to a commercial vulnerability management service, not from an adversary. The flaws whose source populations contained nothing benign ran at two-digit volumes, well below anything a volume-ordered remediation queue surfaces. Defenders should rank on Known Exploited Vulnerabilities (KEV) listing and internet reachability instead, and resolve the operator behind an attempt figure before acting on it.
β
β
Log4Shell, CVE-2021-44228, still draws heavy traffic. This period, 61% of the attempts carrying its exploitation tag came from a single range that resolves to a commercial vulnerability management service. The same range supplied 35% of generic cross-site scripting request volume and 26% of double URL encoding volume, but only 1% of broad signatures such as Generic Sensitive File Access Attempt. Inflation is worst where a flaw is most famous.
Roughly eight times more sources spent this period checking whether SharePoint farms already carry the ToolShell web shell than attempting the exploit itself. They did so on every one of the seven days. A patch closes the route in; it does not remove a shell already written. Organizations that patched in July and closed the ticket should reopen it as an artifact hunt.
Adversaries attempted flaws in Cisco Catalyst SD-WAN Manager and Citrix NetScaler SD-WAN on 17 August. Both are in CISA's KEV catalog and were disclosed nine years apart. Each burst lasted one day and neither source set contained a benign member. A controller sits above every branch site it configures. Build detection on first sighting of the request path rather than on a rate threshold.
Adversaries attempted a known exploited GeoServer XML external entity flaw across the final three days of the period. They ran at 12, 16 and 7 sources on 21, 22 and 23 August, every one classified malicious. Discovery traffic against the same product ran far heavier and across the whole window. That gap between discovery and exploitation is the warning time a patch cycle has to beat.
β
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
βRequest a demo to learn more about GreyNoise's data and intelligence.
β
β
β
β
β
β
β
β
β
β
β
β