CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The Coverage Gap: Why Your Blocklist Is Missing 119,000 Malicious IPs Today

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1847

As cited

Copy frozen at (site build).

threat intel

The Coverage Gap: Why Your Blocklist Is Missing 119,000 Malicious IPs Today

GreyNoise analyzed 119,842 malicious IP addresses against 11 major threat intelligence feeds and found that these feeds covered only an average of 2% of the malicious IPs, highlighting significant gaps in static blocklist coverage. The research underscores that relying solely on blocklists leaves organizations exposed to the majority of known malicious infrastructure. This limitation suggests practitioners need layered defenses beyond traditional blocklist-based approaches.

Why it matters: Security teams relying on threat feeds and blocklists for network defense are exposed to over 98% of tracked malicious IPs that go undetected, requiring evaluation of supplementary detection methods and threat intelligence sources.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary