Threat Pulse

Weekly AI-generated threat intelligence reports based on live honeypot data. 27 reports published.
Pulse #27
Threat Pulse W39 — Volume Drop With Persistent RCE Campaign Pressure
Total probes fell 34% to 61,382, yet five critical RCE campaigns maintained sustained activity. SSH and Telnet facades absorbed the bulk of traffic, and IoT credential brute-forcing signals continued alongside legacy CVE exploitation.
21 Sep 2026
Pulse #26
Threat Pulse W38 — Sharp Surge in RCE Campaigns & Telnet Exploitation
Week of Sept 7–14 saw 92,931 inbound probes (+38.8%), dominated by a coordinated wave of critical RCE campaigns targeting Hikvision, PHPUnit, Apache, GeoServer, and Exchange. Telnet remained the most-probed facade, while credential stuffing and IoT default password attacks intensified.
14 Sep 2026
Pulse #25
Threat Pulse W37 — Volume Drop Masks Persistent RCE Campaign Surge
Overall probe volume fell 34.2% to 66,942 events, but five critical RCE campaigns each recorded 21,524 hits. SSH and Telnet remain the dominant attack surfaces, with IoT-targeting shell injection increasingly visible.
07 Sep 2026
Pulse #24
Threat Pulse W36 — Volume Drop Masks Critical RCE Campaign Surge
Total probes fell 21.6% to 101,661, but five critical RCE campaigns each logged 35,523 hits. Telnet and SSH facades dominated traffic, with GoDaddy-hosted IPs driving bulk scan activity.
31 Aug 2026
Pulse #23
Threat Pulse W35 — Mass Scan Dominance & Multi-Platform RCE Campaigns
Probe volume held near-flat at 129,648 events (-0.6%). Telnet and database facades absorbed the bulk of traffic. Five concurrent critical RCE campaigns targeting Hikvision, PHPUnit, Apache, GeoServer, and Exchange remain active.
24 Aug 2026
Pulse #22
Threat Pulse W34 — Persistent RCE Campaigns & Telnet Botnet Surge
130,466 inbound probes recorded W34, down 13.5% week-over-week, yet RCE campaign activity remained intense across five critical vulnerability chains. Telnet facades absorbed 67% of all traffic, signaling continued IoT botnet recruitment drives.
17 Aug 2026
Pulse #21
Threat Pulse W33 — RCE Campaign Blitz & Telnet Botnet Recruitment
Week 33 saw 150,796 inbound probes (-28.4%), dominated by Telnet scanning and a synchronized burst of critical RCE campaigns. Hikvision, PHPUnit, Apache, and GeoServer exploits each registered identical hit counts, signaling coordinated multi-vector tooling.
10 Aug 2026
Pulse #20
Threat Pulse W32 — Massive Scan Surge & Critical RCE Campaign Blitz
Inbound probes more than doubled (+107.8%) this week, driven by concentrated scanning from GoDaddy-hosted IPs and a coordinated multi-vector RCE campaign hitting five critical vulnerabilities simultaneously. Telnet and SSH facades absorbed the bulk of traffic, with Mirai-style credential stuffing also prominent.
03 Aug 2026
Pulse #19
Threat Pulse W31 — Volume Drop Masks Persistent RCE Campaign Pressure
Total probes fell 25.7% to 101,340, but critical RCE campaigns targeting Hikvision, PHPUnit, Apache, GeoServer, and Exchange remained uniformly active. Telnet and SSH facades absorbed the bulk of traffic while credential-stuffing signals intensified across database services.
27 Jul 2026
Pulse #18
Threat Pulse W30 — Sharp Volume Drop with Persistent RCE Campaign Activity
Inbound probes fell 72.9% week-over-week to 44,865, driven by a single dominant scanner. Despite reduced volume, critical RCE campaigns remained uniformly active across Hikvision, PHPUnit, Apache, GeoServer, and Exchange vectors.
20 Jul 2026
1 2 3