At The Edge Clear: September 8 – 14, 2026

Table of Contents
Loading nav...

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

Commodity Crawlers Now Carry AI Platform Exploits

Analysis Period: September 8 – September 14, 2026

Adversaries attempted two known exploited remote code execution flaws in the AI application platform Langflow from addresses that also collected environment files and enumerated WordPress installations. Four hosts on consumer and carrier networks carried more than a third of all alternative-port SSH crawling, and one address carried more than half of the Remote Desktop crawling GreyNoise observed. Patch Langflow and rank sources by volume.

By The Numbers:

  • 95% — Of Langflow flaw sources came from two hosting providers.
  • 36% — Of alternative-port SSH crawling came from four hosts.
  • 56% — Of all RDP crawling came from one address.

Preview Findings:

1. Two known exploited Langflow flaws arrived inside a commodity crawler sweep

Adversaries attempted CVE-2025-3248 and CVE-2026-0770 in Langflow, both in CISA's Known Exploited Vulnerabilities catalog, at 3,968 and 4,770 connection attempts and both new to this brief series. Every address GreyNoise recorded on either flaw also carries a generic web crawling tag, roughly nine in ten collected environment files and enumerated WordPress installations, and about four in five requested repository configuration. Two hosting providers supply roughly 95% of those addresses, so the source count measures provider egress.

2. Adversaries swept SSH from consumer and carrier networks

Five of the ten highest-volume sources this period ran SSH enumeration and credential attacks, and GreyNoise classifies all five malicious. Four placed effectively all their SSH contact on ports other than 22, 36% of all alternative-port SSH crawling observed. Two shared client fingerprints group those four across four separate networks, marking a common tool class. Reputation policy scoped to hosting providers does not reach them.

3. One address supplied more than half of all Remote Desktop crawling observed

That address supplied 56% of all Remote Desktop crawling GreyNoise observed and three fifths of the credential attempts inside it. Those attempts ran 3.6% of what that source sent, so a detection keyed to failed logins sees a fraction of the pressure.

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

Request a demo to learn more about GreyNoise's data and intelligence.

Read the transcript

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

Commodity Crawlers Now Carry AI Platform Exploits

Analysis Period: September 8 – September 14, 2026

Adversaries attempted two known exploited remote code execution flaws in the AI application platform Langflow from addresses that also collected environment files and enumerated WordPress installations. Four hosts on consumer and carrier networks carried more than a third of all alternative-port SSH crawling, and one address carried more than half of the Remote Desktop crawling GreyNoise observed. Patch Langflow and rank sources by volume.

By The Numbers:

  • 95% — Of Langflow flaw sources came from two hosting providers.
  • 36% — Of alternative-port SSH crawling came from four hosts.
  • 56% — Of all RDP crawling came from one address.

Preview Findings:

1. Two known exploited Langflow flaws arrived inside a commodity crawler sweep

Adversaries attempted CVE-2025-3248 and CVE-2026-0770 in Langflow, both in CISA's Known Exploited Vulnerabilities catalog, at 3,968 and 4,770 connection attempts and both new to this brief series. Every address GreyNoise recorded on either flaw also carries a generic web crawling tag, roughly nine in ten collected environment files and enumerated WordPress installations, and about four in five requested repository configuration. Two hosting providers supply roughly 95% of those addresses, so the source count measures provider egress.

2. Adversaries swept SSH from consumer and carrier networks

Five of the ten highest-volume sources this period ran SSH enumeration and credential attacks, and GreyNoise classifies all five malicious. Four placed effectively all their SSH contact on ports other than 22, 36% of all alternative-port SSH crawling observed. Two shared client fingerprints group those four across four separate networks, marking a common tool class. Reputation policy scoped to hosting providers does not reach them.

3. One address supplied more than half of all Remote Desktop crawling observed

That address supplied 56% of all Remote Desktop crawling GreyNoise observed and three fifths of the credential attempts inside it. Those attempts ran 3.6% of what that source sent, so a detection keyed to failed logins sees a fraction of the pressure.

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

Request a demo to learn more about GreyNoise's data and intelligence.