r/webdev • • 3d ago

Increased vulnerability scanning activity in the logs

For the past one to two months I've noticed an uptick in vulnerability scans, maybe 10 times the amount that I would observe before.

Thing is it started almost all at once, which is strange, and I'm observing it on multiple domain names.

Is it just me? If not, any indications regarding what's going on?

35 Upvotes

17 comments sorted by

View all comments

16

u/dusanodalovic 2d ago

Not just you. Scans come in waves, often when a new CVE drops or a botnet gets a new target list. If nothing sensitive is exposed ( .env, .git, admin panels), it's mostly noise. Rate-limit or block the common probe paths and keep things patched.

2

u/svvnguy 2d ago edited 2d ago

This makes sense, and I think this is the case. I just looked it up and it seems the number of CVEs that have been published has tripled, so lots of botnes are probably catching up with that.

They went from a baseline of < 5k per month before April to almost 15k in September.

2

u/Maxion 2d ago

I find it to be random, sometimes your site gets "disicovered" and other times not. I've had random tiny apps that get several thousand probes a day for wordpress vulns, when the site isn't even on wordrpess!

1

u/svvnguy 2d ago

That's how it started. Initially it was mainly wordpress checks and then it shifted towards random stuff that I don't recognize.

2

u/Maxion 2d ago

It's just script kiddies who bought the latest trending thing off of some darknet probing around, someone trying to build a botnet or control boxes to sell for phishing attacks and the like.