Andrew Morris
@andrewmorr.is
📤 1209
📥 257
📝 184
🔳 founder of
@greynoise.io
. computers, networks, technology enthusiast. big goober.
React2Shell exploitation frequency in GreyNoise dec 5-dec 6
about 5 hours ago
2
14
9
Remember folks- it's only a crypto miner until it isn't
1 day ago
0
5
0
React Server CVE-2025-55182 popping off in
@greynoise.io
right now. Blog from
@hrbrmstr.dev
up:
www.greynoise.io/blog/cve-202...
2 days ago
3
4
1
one thing about me is that I love windows. the building fixture. not the operating system.
5 days ago
1
1
0
Shamlessly reposting from elsewhere- you can easily communicate between Linux VMs and guests using VSOCK (
man7.org/linux/man-pa...
). Here's some silly examples of bidirectional chat btwn host & guest using Socat. Or connecting via SSH to my home router from the VM without TCP/IP. No code required.
9 days ago
1
10
2
on the surface this appears to be a massive credential stuffing campaign against Palo Alto's. please audit your successful logins and enable MFA. good catch
@remyhax.bsky.social
www.greynoise.io/blog/palo-al...
loading . . .
Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High
GreyNoise has identified a significant escalation in malicious activity targeting Palo Alto Networks GlobalProtect portals. Beginning on 14 November 2025, activity rapidly intensified, culminating in ...
https://www.greynoise.io/blog/palo-alto-scanning-surges-90-day-high
16 days ago
0
5
0
People always make fun of me for being polite to LLMs and I like to joke that I want to be on the good side of the robots when they take over the world. But really it just feels like a nasty habit to reinforce being an asshole on the computer. Unless we're playing Modern Warfare and you're 12.
17 days ago
0
10
2
POV you're my new 42U server rack in the garage and I just turned the lights off and saw your lights blinking in the dark for the first time
loading . . .
18 days ago
1
7
0
did you know you can quickly figure out if an ethernet port/cable supports PoE by putting it on your lips and feeling whether it electrocutes you or not
18 days ago
1
2
0
We've hired Colonel Shawn Smagh to up our
@greynoise.io
intel reporting game and we've started producing weekly intelligence briefs. This week's is a banger.
19 days ago
0
8
2
reposted by
Andrew Morris
GreyNoise
about 1 month ago
Happy Halloween from your fave GreyNerds 🍬🍫
4
13
6
Annual candy bracket is done. I'm gonna need some time to reflect.
about 1 month ago
1
6
0
ned flanders
about 1 month ago
2
22
0
we did a pew pew map btw
threat-map.greynoise.io
about 1 month ago
1
5
2
I've just received word that we're preparing for this years annual
@greynoise.io
halloween candy bracket. Twix won years 1-2. 100 Grand won last year on a complete fluke. I might write a blog post about how last year's candy bracket undermined my faith in the democratic process.
about 1 month ago
1
8
1
excuse me for talking to you like a human ass being
about 2 months ago
0
1
0
when it comes to a head it will have been obvious in hindsight
about 2 months ago
0
7
1
big week in the morris household. we've started tracking ORBs at
@greynoise.io
and I'm shitposting again btw (h/t
@hrbrmstr.dev
)
about 2 months ago
2
13
1
DuckDB GraphQL btw
duckdb.org/2025/10/22/d...
about 2 months ago
2
9
0
Played Broken Arrow last night on Steam and its sick
about 2 months ago
0
1
0
full moon AND full lunar eclipse tomorrow btw
3 months ago
1
6
1
doing some ground floor reporting (celebrating my uncles 80th birthday)
3 months ago
0
8
0
just accidentally spilled some water on my shorts which dried instantly. This is how I realized I've been wearing a swimsuit as shorts.
3 months ago
2
4
0
psychic.labs.greynoise.io
- Offline, in-memory bitmaps of GreyNoise data. Available now.
4 months ago
0
8
1
Super proud of the folks at
@thinkstcanary.canary.tools
. They continue to inspire me every day.
techcrunch.com/2025/05/29/a...
loading . . .
A decade in, bootstrapped Thinkst Canary reaches $20M in ARR without VC funding | TechCrunch
Reflecting on 10 years since its launch, the honeypot maker explains why the company did not take on any VC funding.
https://techcrunch.com/2025/05/29/a-decade-in-bootstrapped-thinkst-canary-reaches-20m-in-arr-without-vc-funding/
6 months ago
0
25
0
www.labs.greynoise.io/grimoire/202...
loading . . .
AyySSHush: Tradecraft of an emergent ASUS botnet – GreyNoise Labs
Using an AI powered network traffic analysis tool we built called SIFT, GreyNoise has caught multiple anomalous network payloads with zero-effort that are attempting to disable TrendMicro security fea...
https://www.labs.greynoise.io/grimoire/2025-03-28-ayysshush/
6 months ago
1
7
3
7 months ago
0
1
1
anyways I'm putting real ass routers on the GreyNoise grid now and they're getting popped. shoved this one in my apartment onto a sensor in Russia.
7 months ago
0
13
0
hxxps[:]//youtu[.]be/6skuCiLCjRA?si=JIbO4aZP0MlW6G04
7 months ago
0
0
0
7 months ago
2
1
0
I'm doing a little bit of research on model context protocol (MCP) servers. I ripped back a few thousand repos from github and am doing some automated analysis on their codebases. Here's the language stats on ~2,100 MCP repos. More to come.
7 months ago
2
4
0
did a silly little watercolor
7 months ago
0
5
0
in the past 24 hours traffic out of Spain down ~50%, traffic out of Portugal down 90% in terms of raw signals in
@greynoise.io
7 months ago
0
4
0
Did a quick talk on edge device security and how insanely broken it is for the incredible folks at the Belgian Cybersecurity Center. Here are the slides.
www.slideshare.net/slideshow/th...
loading . . .
The Big Hairy Edge Device Security Problem
The Big Hairy Edge Device Security Problem - Download as a PDF or view online for free
https://www.slideshare.net/slideshow/the-big-hairy-edge-device-security-problem/278416382
8 months ago
0
9
0
TL;DR - Attackers still use these old ass vulns because they're STILL WORKING
www.greynoise.io/blog/greynoi...
loading . . .
GreyNoise Uncovers Unique Risks From Resurgent Cybersecurity Vulnerabilities
Attackers from every corner of the internet are exploiting a uniquely dangerous class of cyber flaws: resurgent vulnerabilities.
https://www.greynoise.io/blog/greynoise-uncovers-unique-risks-from-resurgent-cybersecurity-vulnerabilities
8 months ago
1
19
10
the answer to this is literally always yes
8 months ago
0
5
0
Yall are beyond not ready about the shit we're cooking up with
@censys.bsky.social
and
@greynoise.io
powers combined
censys.com/blog/hunting...
loading . . .
Hunting Botnets With CursorAI, GreyNoise, Censys, and Censeye
Threat hunting is made easier and simpler by combining the power of Censys, GreyNoise, CursorAI, and Censeye.
https://censys.com/blog/hunting-botnets-with-cursorai-greynoise-censys-and-censeye
8 months ago
0
25
8
Pope Francis was a great leader. I'm really sad he's dead. I'll never forget in his first months of being pope when a journalist asked him what he thought about an openly gay priest and he responded "Who am I to judge?". Which translated, to me, to: "none of us are anyone to judge". Rest in peace.
8 months ago
0
8
0
on the bright side we're finally going to live in a world without software vulnerabilities
8 months ago
1
56
11
shitposting on bluesky feels like farting in an elevator
8 months ago
0
7
1
the more european a website looks the more i KNOW they're damn sure not setting cookies when i slam that "reject all but essential" button
8 months ago
0
4
0
got the new server runnin
8 months ago
0
4
0
Feels silly to have to say this but Trump's "directing of investigation" & attacks on Chris Krebs (and "suspensions of cleared staff" at S1) are fucking demented
8 months ago
2
11
0
telling the AI to write some tests real quick. 100% coverage.
8 months ago
0
5
1
reposted by
Andrew Morris
nzyme - Close Access Denial
8 months ago
Nzyme v2.0.0-alpha.16 has been released, featuring several new capabilities and improvements — including drone detection.
www.nzyme.org/blog/project...
loading . . .
nzyme - Nzyme v2.0.0-alpha.16 has been released
Nzyme - Free and open Network Defense System.
https://www.nzyme.org/blog/project/2025/04/10/release-v200-alpha-16
0
5
2
8 months ago
0
1
0
beating this dead horse just a little bit more- what are some of your favorite write ups of real ass breaches? one of mine is Phineas Fisher's hackingteam writeup:
web.archive.org/web/20160421...
and
web.archive.org/web/20160417...
add a skeleton here at some point
8 months ago
2
7
0
idk why this cracks me up so much. "hey man is it cool if me and 32 of my close buds come over?"
8 months ago
1
13
0
One of the missing-est things in this cursed field is "A DENOMINATOR". Were doing reasonably well on tracking actor TTPs and such, but we're really missing ground truth/empirics on breaches and how they happen and products/how well they work. Alas, we're spending shitloads on sales and marketing
add a skeleton here at some point
8 months ago
3
4
0
imagine how fast the state of information security would advance if there was no risk at all of "reputation damage/brand loss" and every single incident response report and post-mortem was detailed, public, indexed & searchable for all to see and learn from
8 months ago
4
27
8
Load more
feeds!
log in