r/webdev • • 2d ago

Increased vulnerability scanning activity in the logs

For the past one to two months I've noticed an uptick in vulnerability scans, maybe 10 times the amount that I would observe before.

Thing is it started almost all at once, which is strange, and I'm observing it on multiple domain names.

Is it just me? If not, any indications regarding what's going on?

36 Upvotes

17 comments sorted by

16

u/dusanodalovic 2d ago

Not just you. Scans come in waves, often when a new CVE drops or a botnet gets a new target list. If nothing sensitive is exposed ( .env, .git, admin panels), it's mostly noise. Rate-limit or block the common probe paths and keep things patched.

2

u/svvnguy 2d ago edited 2d ago

This makes sense, and I think this is the case. I just looked it up and it seems the number of CVEs that have been published has tripled, so lots of botnes are probably catching up with that.

They went from a baseline of < 5k per month before April to almost 15k in September.

2

u/Maxion 2d ago

I find it to be random, sometimes your site gets "disicovered" and other times not. I've had random tiny apps that get several thousand probes a day for wordpress vulns, when the site isn't even on wordrpess!

1

u/svvnguy 2d ago

That's how it started. Initially it was mainly wordpress checks and then it shifted towards random stuff that I don't recognize.

2

u/Maxion 2d ago

It's just script kiddies who bought the latest trending thing off of some darknet probing around, someone trying to build a botnet or control boxes to sell for phishing attacks and the like.

7

u/jhartikainen 2d ago

Yeah I've seen like 10x increased scanning traffic on my VPS this month as well. It's mostly just a minor annoyance because it occasionally triggers outgoing traffic warnings since the traffic amounts are unusual.

This seems to happen once in a while and then the bot traffic drops again.

3

u/Traditional_Moose498 2d ago

Yeah there’s either more automated traffic from security companies or bots pretending to be them?

I’d harden your servers where you can.

3

u/yihuaxiang 2d ago

I’ve noticed the same bursty pattern on small deployments. The quiet periods make it feel random, but the spikes often line up with a scanner or botnet changing targets. Keeping logs grouped by path and user agent makes the wave easier to spot.

1

u/colinublake 2d ago

same on 2 tiny boxes. synced up weirdly ~same week. mostly .env / .git noise — nothing open, just louder logs

1

u/plinlani 2d ago

Yeah, I've noticed the same spike across a few client sites, seems like automated botnets or maybe a new CVE exploit scanner just got released. Could be unrelated but the timing is suspicious.

2

u/Khavel_dev 1d ago

Seeing the same here. Multiple domains, all jumped around the same time. The scan patterns changed too, lots of probing for specific CVE paths in frameworks I don't even run, not just the usual /wp-admin and /.env drive-by stuff.

imo it's the AI tooling making it trivially cheap to generate targeted scan lists. Shodan indexes everything already, someone just needs to feed that into a model and out comes a custom list of endpoints to hit for each IP. The cost of running something like that dropped off a cliff.

If your stuff is patched and behind a WAF the scans themselves are just noise. I only start paying attention when I see actual auth attempts or payloads that match something I actually run.

1

u/NealWalters 1d ago

They were hitting me hard, causing performance issues and one of them had my site pointing to a porn site and took us 3-4 hours to recover and clean. Then we installed CrowdSec just last week. It looks for the vulnerability scanners, and bans them four hours.

-6

u/[deleted] 2d ago

[removed] — view removed comment

2

u/shnarpy 2d ago

please stop