Andrew Morris
@andrewmorr.is
📤 1166
📥 162
📝 158
🔳 founder of
@greynoise.io
. computers, networks, technology enthusiast. big goober.
full moon AND full lunar eclipse tomorrow btw
about 1 month ago
1
6
1
doing some ground floor reporting (celebrating my uncles 80th birthday)
about 1 month ago
0
8
0
just accidentally spilled some water on my shorts which dried instantly. This is how I realized I've been wearing a swimsuit as shorts.
about 2 months ago
2
4
0
psychic.labs.greynoise.io
- Offline, in-memory bitmaps of GreyNoise data. Available now.
about 2 months ago
0
8
1
Super proud of the folks at
@thinkstcanary.canary.tools
. They continue to inspire me every day.
techcrunch.com/2025/05/29/a...
loading . . .
A decade in, bootstrapped Thinkst Canary reaches $20M in ARR without VC funding | TechCrunch
Reflecting on 10 years since its launch, the honeypot maker explains why the company did not take on any VC funding.
https://techcrunch.com/2025/05/29/a-decade-in-bootstrapped-thinkst-canary-reaches-20m-in-arr-without-vc-funding/
5 months ago
0
25
0
www.labs.greynoise.io/grimoire/202...
loading . . .
AyySSHush: Tradecraft of an emergent ASUS botnet – GreyNoise Labs
Using an AI powered network traffic analysis tool we built called SIFT, GreyNoise has caught multiple anomalous network payloads with zero-effort that are attempting to disable TrendMicro security fea...
https://www.labs.greynoise.io/grimoire/2025-03-28-ayysshush/
5 months ago
1
7
3
5 months ago
0
1
1
anyways I'm putting real ass routers on the GreyNoise grid now and they're getting popped. shoved this one in my apartment onto a sensor in Russia.
5 months ago
0
13
0
hxxps[:]//youtu[.]be/6skuCiLCjRA?si=JIbO4aZP0MlW6G04
5 months ago
0
0
0
5 months ago
2
1
0
I'm doing a little bit of research on model context protocol (MCP) servers. I ripped back a few thousand repos from github and am doing some automated analysis on their codebases. Here's the language stats on ~2,100 MCP repos. More to come.
5 months ago
2
4
0
did a silly little watercolor
5 months ago
0
5
0
in the past 24 hours traffic out of Spain down ~50%, traffic out of Portugal down 90% in terms of raw signals in
@greynoise.io
6 months ago
0
4
0
Did a quick talk on edge device security and how insanely broken it is for the incredible folks at the Belgian Cybersecurity Center. Here are the slides.
www.slideshare.net/slideshow/th...
loading . . .
The Big Hairy Edge Device Security Problem
The Big Hairy Edge Device Security Problem - Download as a PDF or view online for free
https://www.slideshare.net/slideshow/the-big-hairy-edge-device-security-problem/278416382
6 months ago
0
9
0
TL;DR - Attackers still use these old ass vulns because they're STILL WORKING
www.greynoise.io/blog/greynoi...
loading . . .
GreyNoise Uncovers Unique Risks From Resurgent Cybersecurity Vulnerabilities
Attackers from every corner of the internet are exploiting a uniquely dangerous class of cyber flaws: resurgent vulnerabilities.
https://www.greynoise.io/blog/greynoise-uncovers-unique-risks-from-resurgent-cybersecurity-vulnerabilities
6 months ago
1
19
10
the answer to this is literally always yes
6 months ago
0
5
0
Yall are beyond not ready about the shit we're cooking up with
@censys.bsky.social
and
@greynoise.io
powers combined
censys.com/blog/hunting...
loading . . .
Hunting Botnets With CursorAI, GreyNoise, Censys, and Censeye
Threat hunting is made easier and simpler by combining the power of Censys, GreyNoise, CursorAI, and Censeye.
https://censys.com/blog/hunting-botnets-with-cursorai-greynoise-censys-and-censeye
6 months ago
0
25
8
Pope Francis was a great leader. I'm really sad he's dead. I'll never forget in his first months of being pope when a journalist asked him what he thought about an openly gay priest and he responded "Who am I to judge?". Which translated, to me, to: "none of us are anyone to judge". Rest in peace.
6 months ago
0
8
0
on the bright side we're finally going to live in a world without software vulnerabilities
6 months ago
1
56
11
shitposting on bluesky feels like farting in an elevator
6 months ago
0
7
1
the more european a website looks the more i KNOW they're damn sure not setting cookies when i slam that "reject all but essential" button
6 months ago
0
4
0
got the new server runnin
6 months ago
0
4
0
Feels silly to have to say this but Trump's "directing of investigation" & attacks on Chris Krebs (and "suspensions of cleared staff" at S1) are fucking demented
6 months ago
2
11
0
telling the AI to write some tests real quick. 100% coverage.
6 months ago
0
5
1
reposted by
Andrew Morris
nzyme - Close Access Denial
6 months ago
Nzyme v2.0.0-alpha.16 has been released, featuring several new capabilities and improvements — including drone detection.
www.nzyme.org/blog/project...
loading . . .
nzyme - Nzyme v2.0.0-alpha.16 has been released
Nzyme - Free and open Network Defense System.
https://www.nzyme.org/blog/project/2025/04/10/release-v200-alpha-16
0
5
2
6 months ago
0
1
0
beating this dead horse just a little bit more- what are some of your favorite write ups of real ass breaches? one of mine is Phineas Fisher's hackingteam writeup:
web.archive.org/web/20160421...
and
web.archive.org/web/20160417...
add a skeleton here at some point
6 months ago
2
7
0
idk why this cracks me up so much. "hey man is it cool if me and 32 of my close buds come over?"
6 months ago
1
13
0
One of the missing-est things in this cursed field is "A DENOMINATOR". Were doing reasonably well on tracking actor TTPs and such, but we're really missing ground truth/empirics on breaches and how they happen and products/how well they work. Alas, we're spending shitloads on sales and marketing
add a skeleton here at some point
6 months ago
3
4
0
imagine how fast the state of information security would advance if there was no risk at all of "reputation damage/brand loss" and every single incident response report and post-mortem was detailed, public, indexed & searchable for all to see and learn from
6 months ago
4
27
8
the most boomer email giveaway there is is a custom, colored font
6 months ago
1
5
0
turkey pesto 👀
6 months ago
1
6
0
reposted by
Andrew Morris
GreyNoise
6 months ago
🚨 Surge in Palo Alto Networks Login Scanning Activity: Nearly 24,000 unique IPs have attempted access over the past 30 days. Full analysis ⬇️
#PANOS
#PaloAltoNetworks
#Vulnerability
loading . . .
Surge in Palo Alto Networks Scanner Activity Indicates Possible Upcoming Threats
Over the last 30 days, nearly 24,000 unique IP addresses have attempted to access these portals. The pattern suggests a coordinated effort to probe network defenses and identify exposed or vulnerable ...
https://www.greynoise.io/blog/surge-palo-alto-networks-scanner-activity
0
10
6
in a bind you can use paper towels as filters in your chemex. nobody will stop you
6 months ago
0
5
0
I can't stop responding to Signal messages with "I will pray for victory 🙏🏻"
7 months ago
1
23
0
some light reading
7 months ago
2
9
0
hear me out...... GPU accelerated JQ
7 months ago
0
5
0
Me and mister Rudis (
@hrbrmstr.dev
) are going over the
@greynoise.io
2024 Mass Exploitation Report LIVE in 13 minutes. Come hang out.
add a skeleton here at some point
7 months ago
0
3
3
first firing squad execution in a few decades took place recently, regrettably in my home town. this is a good account of it.
apnews.com/article/sout...
loading . . .
Violent and sudden. What a firing squad execution looked like through my eyes
An Associated Press journalist served as media eyewitness to the execution of Brad Sigmon by firing squad Friday in South Carolina.
https://apnews.com/article/south-carolina-firing-squad-eyewitness-account-sigmon-427cccb55be58954af4434e89bcc41d8
7 months ago
0
1
0
I'm enjoying Cursor for building APIs and navigating unfamiliar codebases. I've noticed Cursor (like a human engineer) sometimes gets tunnel-visioned if not guided properly, doing mega dumb shit like hardcoding things that make no sense just to try to get your ask to work. Also, Aider rules too.
7 months ago
3
4
0
I know people stopped bitching about this a few years ago but what was the big kerfuffle about systemd? I started using it regularly over the past ~year for various things and I like it a lot? Seems good? Is it just ..... not init.d??
7 months ago
1
0
0
pov i'm making you dinner
7 months ago
4
9
0
reposted by
Andrew Morris
Raphael Mudge
7 months ago
Dig through this timeline and you'll figure out what I'm here to do. I spoke to a commercial leader in the offensive security space last year. My words: you're fucking it up. What I didn't say: I feel compelled, even though I DON'T want the bullshit, to try and fix it. What does all of this mean?
2
23
14
this is crazy cuz how was I blasting so fast thru that toll they figured it out in the Philippines???
7 months ago
1
4
1
full moon tonight
@lennart.0x58ed.com
7 months ago
1
4
0
reposted by
Andrew Morris
Catalin Cimpanu
7 months ago
GreyNoise has detected a coordinated campaign exploiting SSRF vulnerabilities across several software products. The sudden spike in attacks began on March 9 and is originated from a group of 400 IP addresses.
www.greynoise.io/blog/new-ssr...
0
24
5
a silly little AI paradox is that a large language model is actually more likely to solve problems on older technology vs newer technology since there's a higher likelihood that it was trained on that technology's documentation
7 months ago
0
2
0
I wanted to learn how to write a little Bluesky bot that interacts with local LLMs so I banged out a quick little bot called
@imagedescriber.info
. You can @ it with an image or as a response to an image in a thread and it will simply describe the images to you as a text response.
7 months ago
2
7
3
test post 2 please ignore
7 months ago
1
4
0
test post please ignore
7 months ago
1
0
0
Load more
feeds!
log in