TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GreyNoise

Coordinated Grafana Exploitation Attempts on 28 September

2025-10-02 · Read original ↗

ATT&CK techniques detected

2 predictions
T1190Exploit Public-Facing Application
65%
"coordinated grafana exploitation attempts on 28 september for executive audiences, please see the accompanying situation report ( sitrep ) for this activity. on 28 september 2025, greynoise observed a sharp one - day surge of exploitation attempts targeting cve - 2021 - 43798 — a…"
T1588.006Vulnerabilities
32%
"two ips geolocated to china are worth highlighting : - 60. 186. 152. 35 - 122. 231. 163. 197 both belong to chinanet - backbone, were first observed on 28 september, active only that day, and overwhelmingly focused on grafana. threat context exploitation of older, high - impact v…"

Summary

GreyNoise observed a sharp one-day surge of exploitation attempts targeting CVE-2021-43798 — a Grafana path traversal vulnerability that enables arbitrary file reads. All observed IPs are classified as malicious.