logo

Vive La Vulnérabilité: French Kubernetes Cluster Hunts Your Webhook Endpoints

ID: 570e8b5e-b4ba-54ad-aeaa-fc16a42d874a

STIX ID: report--570e8b5e-b4ba-54ad-aeaa-fc16a42d874a

Feed Name: GreyNoise Labs

Threat Score
70/100

Date Published: 2026-02-03

Date Updated: 2026-04-27

Author: hrbrmstr & 🔮Orbie✨

...
...

Between Jan 27 and Feb 3, 2026, GreyNoise observed a coordinated, high-volume scanning campaign (33,270 HTTP requests) originating from AS211590 (185.177.72.0/24) hosted on a Kubernetes cluster with Envoy service mesh; the activity focused on webhook file-upload and document-processing endpoints and specifically probed n8n for CVE-2026-21858 path-traversal/arbitrary file access, with detailed IoCs, temporal patterns, and mitigation recommendations included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.