Threat Pulse

Weekly AI-generated threat intelligence reports based on live honeypot data. 27 reports published.
Pulse #7
Threat Pulse W19 — Telnet Flood Dominates as RCE Campaigns Persist
Week of May 1–4 saw 92,572 inbound probes (-13.7%), with fake-telnet accounting for 97.5% of traffic. A single US-based actor drove 84% of all events, while five critical RCE campaigns remained uniformly active.
04 May 2026
Pulse #6
Threat Pulse W18 — Massive Mirai Botnet Surge: 1.6M Telnet Hits in 48 Hours
Week 18 was dominated by a massive Mirai-family botnet surge: 1,630,000+ Telnet probes on April 30th and May 1st alone — the two highest-volume days in sensor history. Five critical RCE campaigns maintained parallel pressure with anomalous identical hit counts, suggesting templated tooling.
01 May 2026
Pulse #5
Threat Pulse W18 — RCE Surge & Credential Harvesting Dominate
86,947 inbound probes recorded W18, up 7.7% week-over-week. RCE and path-traversal campaigns targeting PHP frameworks, VoIP systems, and cloud credentials drove the bulk of high-severity activity across SSH, Telnet, and MySQL facades.
27 Apr 2026
Pulse #4
Threat Pulse W17 — Sharp Volume Drop, RCE & Credential Harvesting Persist
Total inbound probes fell 41.2% to 74,024, yet high-severity campaigns targeting .env files, PHPUnit RCE, and FreePBX VoIP systems remained aggressively active. SSH and MySQL facades absorbed the bulk of traffic, and a Bulgarian/Romanian scanning cluster dominated source activity.
20 Apr 2026
Pulse #3
Threat Pulse W16 — Scan Dominance & Multi-Campaign RCE Pressure
Week of Apr 6–13 saw 125,604 inbound probes (-5.8%), with a Bulgarian IP responsible for ~35% of all traffic. RCE and path traversal campaigns remain highly active, targeting PHP, Spring, and VoIP infrastructure.
13 Apr 2026
Pulse #2
Threat Pulse W14 — Massive Scan Surge & Multi-Vector Exploitation
Inbound probes surged 140.6% week-over-week to 103,679 events, driven primarily by bulk scanning across Telnet, SSH, and MySQL facades. Five high-to-critical campaigns dominated, including PHPUnit RCE and .env harvesting, with Bulgaria and India accounting for over 60% of source traffic.
06 Apr 2026
Pulse #1
Threat Pulse W13 — First Week: tarpit-lab.xyz Baseline
37,396 inbound probes recorded across six honeypot facades in the sensor's first tracked week. SSH scanning dominates at 63.8% of total traffic, while critical RCE campaigns targeting PHPUnit and Hikvision ISAPI represent the most dangerous active threats. Bulgarian and Romanian netblocks account for nearly 40% of all probe volume.
01 Apr 2026
1 2 3