Threat Pulse
Weekly AI-generated threat intelligence reports based on live honeypot data.
27 reports published.
Pulse #17
Threat Pulse W29 — Massive Scan Surge & Critical RCE Cluster
Probe volume exploded 372% week-over-week to 372,467 events, driven by a coordinated scan surge and a tightly synchronized cluster of critical RCE campaigns. Telnet and SSH facades absorbed the bulk of traffic, while Hikvision, PHPUnit, Apache, and GeoServer exploits each registered ~85K hits.
13 Jul 2026
Pulse #16
Threat Pulse W28 — Massive Scan Surge & Critical RCE Campaign Blitz
Week 28 saw a 167.6% spike in inbound probes (211,219 total), driven by a concentrated scan campaign from US-hosted infrastructure and a coordinated multi-vector RCE blitz targeting IoT, web, and database services simultaneously.
06 Jul 2026
Pulse #15
Threat Pulse W27 — Telnet Flood & Mass RCE Campaign Surge
Probe volume hit 94,222 this week (+19.4%), driven overwhelmingly by a single US-based scanner hammering Telnet facades. Five critical RCE campaigns ran simultaneously at identical hit counts, suggesting coordinated or automated multi-exploit tooling.
29 Jun 2026
Pulse #14
Threat Pulse W26 — Massive Surge: Telnet Storm & Critical RCE Blitz
Week of May 29–June 22 saw 841,504 inbound probes — a 439.5% spike — dominated by telnet scanning and a synchronized multi-campaign RCE blitz targeting Hikvision, Apache, GeoServer, and PHPUnit. Botnet credential patterns and IoT-linked payloads signal active exploitation infrastructure buildup.
22 Jun 2026
Pulse #13
Threat Pulse W25 — Massive Scan Surge & Critical RCE Campaign Flood
Inbound probes surged 262% to 564,734 this week, driven by an aggressive telnet scanning campaign and near-identical hit counts across four critical RCE campaigns. Credential brute-forcing against database and IoT targets intensified significantly.
15 Jun 2026
Pulse #12
Threat Pulse W24 — Massive Scan Surge & Critical RCE Campaign Blitz
Probe volume surged 150.8% to 391,261 events, driven by a dominant Telnet scanning campaign and a synchronized wave of critical-severity RCE exploits. Multiple CVE-targeting campaigns each logged over 77,000 hits, signaling coordinated multi-vector exploitation.
08 Jun 2026
Pulse #11
Threat Pulse W23 — Mass Scan Surge & Critical RCE Campaign Blitz
Inbound probes surged 32.7% to 207,040 this week, driven by an aggressive Telnet-targeting scan campaign from DigitalOcean-hosted infrastructure. Five critical RCE campaigns ran concurrently, targeting Hikvision, PHPUnit, Apache, GeoServer, and Exchange.
01 Jun 2026
Pulse #10
Threat Pulse W22 — Massive Scan Surge & Critical RCE Campaign Blitz
Total probes surged 44.5% to 369,533 this week, driven by a dominant scan wave and a synchronized multi-vector RCE campaign. Telnet facades absorbed 90% of traffic, while four critical-severity exploit campaigns each registered ~64,858 hits.
25 May 2026
Pulse #9
Threat Pulse W21 — Massive Telnet Surge & Critical RCE Campaign Blitz
Week of May 11–18 saw a 407% spike in inbound probes (296,633 total), driven by an aggressive Telnet scanning campaign. Five critical RCE campaigns hit simultaneously, and Mirai-style IoT credential stuffing dominated auxiliary channels.
18 May 2026
Pulse #8
Threat Pulse W20 — Sharp Volume Drop with Persistent RCE Campaign Pressure
Inbound probes fell 57.5% to 54,368 this week, driven by a collapse in scan activity. Despite lower volume, critical RCE campaigns remained fully active, and Mirai-style credential stuffing surged on fake-telnet facades.
11 May 2026