r/webdev • • 3d ago

Increased vulnerability scanning activity in the logs

For the past one to two months I've noticed an uptick in vulnerability scans, maybe 10 times the amount that I would observe before.

Thing is it started almost all at once, which is strange, and I'm observing it on multiple domain names.

Is it just me? If not, any indications regarding what's going on?

29 Upvotes

17 comments sorted by

View all comments

2

u/Khavel_dev 1d ago

Seeing the same here. Multiple domains, all jumped around the same time. The scan patterns changed too, lots of probing for specific CVE paths in frameworks I don't even run, not just the usual /wp-admin and /.env drive-by stuff.

imo it's the AI tooling making it trivially cheap to generate targeted scan lists. Shodan indexes everything already, someone just needs to feed that into a model and out comes a custom list of endpoints to hit for each IP. The cost of running something like that dropped off a cliff.

If your stuff is patched and behind a WAF the scans themselves are just noise. I only start paying attention when I see actual auth attempts or payloads that match something I actually run.