.png)
β
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
β
Analysis Period: August 23 β August 30, 2026
Adversaries targeted several unrelated flaws on the same day, each at roughly the same source count. Some cohorts ended within that day while others kept running. Adversaries escalated a Next.js authorization bypass across the final three days, and source sets of matched size appeared on eight of nine legacy Citrix flaws in a single day. The single-day cohorts are the harder problem: they never sustain enough volume to cross a rate threshold. Counting distinct sources per product family per day is what catches it.
β
β
CVE-2025-29927 lets a caller add one HTTP header so the framework skips its middleware, where many applications place their authentication checks. The application then logs the request as authorized. It is rated CVSS 9.1 and absent from CISA KEV. Daily unique sources went from no more than three to 28, then 426, then 495 across a partial final day. The population was still rising when the window closed.
On 30 August, source sets of matched size appeared on eight of nine Citrix flaws. The products are SD-WAN appliances, XenMobile Server and ShareFile StorageZones, and the ninth, a directory traversal check, stayed at three. All nine produced fewer than 1,000 attempts between them across eight days, so each ranks as minor alone. One of the nine, CVE-2019-12989, is rated CVSS 9.8 and is KEV-listed; the two 2020 flaws are rated 7.5; the remaining six carry no CVSS score, which is itself why a severity-ordered queue never surfaces them. Work all nine as a single inventory pass.
Rented hosts on four networks, 96 in total, ran one scanning toolkit. A self-declared scanning user agent that appears almost nowhere else is confirmed on 43 of them, and the same client fingerprint on 38, though a fingerprint alone marks a tool class rather than an operator. Together they produced roughly a tenth of all traffic observed. A control scoped to any single network covers less than half of it.
CVE-2025-55182 is rated CVSS 10.0 and has been in CISA KEV since December 2025. Attempts eased again this period, and part of that traffic now matches a published tool. It posts to a hardcoded endpoint and ships a variant encoding the payload as UTF-16LE, which a rule written against the ASCII byte string will not match. Detect on the endpoint and request structure.
β
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
βRequest a demo to learn more about GreyNoise's data and intelligence.
β
β
β
β
β
β
β
β
β
β
β
β
β
β
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
β
Analysis Period: August 23 β August 30, 2026
Adversaries targeted several unrelated flaws on the same day, each at roughly the same source count. Some cohorts ended within that day while others kept running. Adversaries escalated a Next.js authorization bypass across the final three days, and source sets of matched size appeared on eight of nine legacy Citrix flaws in a single day. The single-day cohorts are the harder problem: they never sustain enough volume to cross a rate threshold. Counting distinct sources per product family per day is what catches it.
β
β
CVE-2025-29927 lets a caller add one HTTP header so the framework skips its middleware, where many applications place their authentication checks. The application then logs the request as authorized. It is rated CVSS 9.1 and absent from CISA KEV. Daily unique sources went from no more than three to 28, then 426, then 495 across a partial final day. The population was still rising when the window closed.
On 30 August, source sets of matched size appeared on eight of nine Citrix flaws. The products are SD-WAN appliances, XenMobile Server and ShareFile StorageZones, and the ninth, a directory traversal check, stayed at three. All nine produced fewer than 1,000 attempts between them across eight days, so each ranks as minor alone. One of the nine, CVE-2019-12989, is rated CVSS 9.8 and is KEV-listed; the two 2020 flaws are rated 7.5; the remaining six carry no CVSS score, which is itself why a severity-ordered queue never surfaces them. Work all nine as a single inventory pass.
Rented hosts on four networks, 96 in total, ran one scanning toolkit. A self-declared scanning user agent that appears almost nowhere else is confirmed on 43 of them, and the same client fingerprint on 38, though a fingerprint alone marks a tool class rather than an operator. Together they produced roughly a tenth of all traffic observed. A control scoped to any single network covers less than half of it.
CVE-2025-55182 is rated CVSS 10.0 and has been in CISA KEV since December 2025. Attempts eased again this period, and part of that traffic now matches a published tool. It posts to a hardcoded endpoint and ships a variant encoding the payload as UTF-16LE, which a rule written against the ASCII byte string will not match. Detect on the endpoint and request structure.
β
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
βRequest a demo to learn more about GreyNoise's data and intelligence.
β
β
β
β
β
β
β
β
β
β
β
β
β