Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Network ‘background noise’ may predict the next big edge-device vulnerability  – CyberScoop
AttackFeed by Joe Wagner | Network ‘background noise’ may predict the next big edge-device vulnerability  - CyberScoop

Network ‘background noise’ may predict the next big edge-device vulnerability  – CyberScoop

Posted on April 20, 2026 By Matt Kapko No Comments on Network ‘background noise’ may predict the next big edge-device vulnerability  – CyberScoop
Attack Feeds

Attackers rarely exploit an edge-device vulnerability indiscriminately. Typically, they first test how widely the flaw can be used and how much access it can provide, then move on to steal data or disrupt operations.

Pre-attack surveillance and planning leaves a lot of noise in its wake. These signals — particularly spikes in traffic that are hitting specific vendors — can act as an early-warning system, often preceding public vulnerability disclosures, according to research GreyNoise shared exclusively with CyberScoop prior to its release. 

Roughly half of every activity surge GreyNoise detected during a 103-day study last winter was followed by a vulnerability disclosure from the same targeted vendor within three weeks, GreyNoise said in its report.

Researchers determined that the median warning of an impending vulnerability disclosure arrived nine days before the targeted vendor issued a public alert to its customers.

“Virtually every time we see large scale spikes in reconnaissance and inventory activity looking for a certain device, it’s because somebody knows about a vulnerability,” Andrew Morris, founder and chief architect at GreyNoise, told CyberScoop.

“Within a few days or weeks — usually within the responsible disclosure timeline — a new very bad vulnerability comes out,” he added.

GreyNoise insists that every day of advance notice matters, giving defenders an opportunity to defend against and thwart potential attacks before they occur. 

The real-time network edge scanning platform spotted 104 distinct activity surges across 18 vendors during its study period. These embedded systems, including routers, VPNs, firewalls and other security systems, consistently account for the most commonly exploited vulnerabilities.

“Attackers love hacking security devices like security appliances. The irony of that is just not lost on me at all,” Morris said.

“It hasn’t gotten bad enough for us to start taking the security of these devices seriously,” he added. “It’s not bad enough for us to take it seriously enough to start ripping these things out and replacing them with new devices or new vendors.”

GreyNoise linked traffic surges to a swarm of vulnerabilities disclosed by vendors across the market, including Cisco, Palo Alto Networks, Fortinet, Ivanti, HPE, MicroTik, TP-Link, VMware, Juniper, F5, Netgear and others.

“It’s becoming scientifically empirical, and it’s becoming more like meteorology than mysticism,” Morris said. “This is like clockwork now.”

GreyNoise breaks these traffic surges down to measure intensity and breadth. Session counts indicate how hard existing sources are hammering a specific vendor and unique source IP counts demonstrate how widely new infrastructure is joining the activity, researchers wrote in the report.

“When both the intensity and breadth of targeting increase simultaneously, it signals a coordinated escalation,” the report said. 

“When you see a session spike against one of your vendors and new source IPs joining at the same time, treat it as a high-confidence reason to look harder. When you see only an IP spike, do not assume a vulnerability is coming,” researchers added. 

The study bolsters other research from Verizon, Google Threat Intelligence Group and Mandiant — landing during what GreyNoise calls “the most aggressive period of edge device exploitation on record.”

This activity doesn’t happen in a vacuum and threat groups aren’t flooding edge devices with traffic for free or for fun, according to Morris.

“People tend to treat internet background noise like it’s this unexplainable phenomenon,” he said. “They’re clearly trying to test the existence of a vulnerability in order to compromise the systems.”

The post Network ‘background noise’ may predict the next big edge-device vulnerability appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain  – The Hacker News
Next Post: Why Most AI Deployments Stall After the Demo  – The Hacker News ❯

You may also like

AttackFeed by Joe Wagner | Institutional DeFi: Building Secure Bridges Between Decentralized Protocols and Corporate Treasury  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Institutional DeFi: Building Secure Bridges Between Decentralized Protocols and Corporate Treasury  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 4, 2026
AttackFeed by Joe Wagner | Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software  - The Hacker News
Attack Feeds
Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software  – The Hacker News
April 25, 2026
AttackFeed by Joe Wagner | Amazon: Low-Skill Hacker Used AI Tools to Breach FortiGate Devices Globally  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Amazon: Low-Skill Hacker Used AI Tools to Breach FortiGate Devices Globally  – Hackread – Cybersecurity News, Data Breaches, AI and More
February 24, 2026
AttackFeed by Joe Wagner | CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV  - The Hacker News
Attack Feeds
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV  – The Hacker News
April 29, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.