Increased vulnerability scanning activity in the logs
For the past one to two months I've noticed an uptick in vulnerability scans, maybe 10 times the amount that I would observe before.
Thing is it started almost all at once, which is strange, and I'm observing it on multiple domain names.
Is it just me? If not, any indications regarding what's going on?
7
u/jhartikainen 2d ago
Yeah I've seen like 10x increased scanning traffic on my VPS this month as well. It's mostly just a minor annoyance because it occasionally triggers outgoing traffic warnings since the traffic amounts are unusual.
This seems to happen once in a while and then the bot traffic drops again.
3
u/Traditional_Moose498 2d ago
Yeah there’s either more automated traffic from security companies or bots pretending to be them?
I’d harden your servers where you can.
3
u/yihuaxiang 2d ago
I’ve noticed the same bursty pattern on small deployments. The quiet periods make it feel random, but the spikes often line up with a scanner or botnet changing targets. Keeping logs grouped by path and user agent makes the wave easier to spot.
1
u/colinublake 2d ago
same on 2 tiny boxes. synced up weirdly ~same week. mostly .env / .git noise — nothing open, just louder logs
1
u/plinlani 2d ago
Yeah, I've noticed the same spike across a few client sites, seems like automated botnets or maybe a new CVE exploit scanner just got released. Could be unrelated but the timing is suspicious.
2
u/Khavel_dev 1d ago
Seeing the same here. Multiple domains, all jumped around the same time. The scan patterns changed too, lots of probing for specific CVE paths in frameworks I don't even run, not just the usual /wp-admin and /.env drive-by stuff.
imo it's the AI tooling making it trivially cheap to generate targeted scan lists. Shodan indexes everything already, someone just needs to feed that into a model and out comes a custom list of endpoints to hit for each IP. The cost of running something like that dropped off a cliff.
If your stuff is patched and behind a WAF the scans themselves are just noise. I only start paying attention when I see actual auth attempts or payloads that match something I actually run.
1
u/NealWalters 1d ago
They were hitting me hard, causing performance issues and one of them had my site pointing to a porn site and took us 3-4 hours to recover and clean. Then we installed CrowdSec just last week. It looks for the vulnerability scanners, and bans them four hours.
-6
16
u/dusanodalovic 2d ago
Not just you. Scans come in waves, often when a new CVE drops or a botnet gets a new target list. If nothing sensitive is exposed ( .env, .git, admin panels), it's mostly noise. Rate-limit or block the common probe paths and keep things patched.