GreyNoise + CrowdStrike: Real-Time Edge Intelligence in Falcon Next-Gen SIEM and Charlotte Agentic SOAR
GreyNoise expanded its CrowdStrike Falcon integration with Next-Gen SIEM dashboards, correlation rules, and Charlotte Agentic SOAR playbooks.
GreyNoise announced an expanded integration with the CrowdStrike Falcon platform, adding purpose-built content for Falcon Next-Gen SIEM and Charlotte Agentic SOAR. The integration includes a dedicated SIEM dashboard, correlation rules that detect allowed inbound traffic from malicious infrastructure, and SOAR playbooks that inject GreyNoise threat context into automated response workflows.
Threat actors are posing as AI crawlers to hunt for exposed credentials
GreyNoise observed scanners spoofing AI crawler user agents from 824 IPs to harvest .env files and cloud credentials; no confirmed theft.
GreyNoise researchers found attackers disguising automated scanning as AI crawler traffic, using six crawler names from four AI companies including Anthropic's ClaudeBot, OpenAI, Google, and Perplexity. Between July 28 and August 23, 2026, the six names arrived from 824 IP addresses spread across 795 /24 networks that matched no published vendor ranges, shared one HTTP client fingerprint that had used more than 1,500 user agent strings, and never requested /robots.txt. The scanners targeted /.env, /.env.production, /.env.bak, and /.aws/credentials, hunting secrets, cloud access keys, private keys, and password stores, while forged Amazon crawler names appeared at greater volume under undocumented user agents. GreyNoise could not confirm whether any file was returned or any organization affected, and published all 824 addresses and targeted paths for defenders.
A New Way to Navigate GreyNoise
GreyNoise launched a redesigned Visualizer that consolidates internet-noise analysis workflows into one interface.
GreyNoise introduced a redesigned Visualizer interface for its internet noise and scanning intelligence platform. The redesign groups related workflows in one place to make the platform's capabilities easier to navigate. It is a product usability update with no security impact.
GreyNoise Welcomes New SVP of Adversary Operations
GreyNoise hires a former Google Threat Intelligence leader as SVP of Adversary Operations to expand proactive threat discovery and disruption.
GreyNoise announced the appointment of a new Senior Vice President of Adversary Operations. The hire previously led threat intelligence at Google and will drive proactive discovery and disruption of cyber threats. The announcement is a company personnel update with no product, vulnerability, or incident details.
AI-powered attack exploited PaperCut flaws to hack 395 organizations
AI-driven campaign exploited PaperCut flaws CVE-2026-81578 and CVE-2026-82078, compromising 440 servers at 395 organizations in 48 countries.
GreyNoise reports a likely Russian-speaking threat actor used hundreds of AI agents combining OpenAI Codex and DeepSeek models to build, test, and refine exploits for CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF, launching the campaign on August 31. At least 440 PaperCut instances at 395 organizations across 48 countries were compromised, with the education sector accounting for roughly half of victims and the US most targeted. Attackers harvested credentials from 280 victims, obtained OS or domain secrets from 147, and gained admin privileges at 12 organizations, using LSASS dumping, pass-the-hash, noPac, and DCSync to dump NTDS.DIT. The adversary went from empty workspace to first RCE in under four hours, and compromised at least 11 organizations within 26 seconds once the campaign launched.