๐บ๐ธ
Ar1s
2026-09-30 01:46:19
(9 hours ago)
[1:2061026] ET WEB_SERVER Next.js Middleware Authorization Bypass (CVE-2025-29927) ::: Port: 80/TCP
Exploited Host
๐ฌ๐ง
venus.launch.bz
2026-09-30 00:13:18
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.86.246.222 (US/United States/222.24 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.86.246.222 (US/United States/222.246.86.136.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-29 23:31:50
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.86.246.222 (222.246.86.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.86.246.222 (222.246.86.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:31:44.266684 2026] [security2:error] [pid 17573:tid 17584] [client 136.86.246.222:37334] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||surdick.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "surdick.com"] [uri "/z9x8c7v6b5-debug-trigger-surdick.com"] [unique_id "arxKYFfug8SxE73HcvKxcAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-09-29 21:27:54
(14 hours ago)
AetherFox VoidGuard detected: [Tue Sep 29 21:27:53.441308 2026] [security2:error] [pid 467610:tid 46 ...
show more
AetherFox VoidGuard detected: [Tue Sep 29 21:27:53.441308 2026] [security2:error] [pid 467610:tid 467614] [client 136.86.246.222:43490] [client 136.86.246.222] ModSecurity: Access denied with code 403 (phase 1). String match "/.env" at REQUEST_URI. [file "/etc/modsecurity/AetherFox.conf"] [line "99"] [id "100067"] [msg ".env access blocked by AetherFox VoidGuard"] [tag "custom-blocklist"] [hostname "draconigen.net"] [uri "/.env"] [unique_id "arwtWQ6ct5zVho4N-MiYKwAAAEE"]
[Tue Sep 29 21:27:53.600170 2026] [security2:error] [pid 467610:tid 467655] [client 136.86.246.222:43446] [client 136.86.246.222] ModSecurity: Access denied with code 403 (phase 1). String match "/.env" at REQUEST_URI. [file "/etc/modsecurity/AetherFox.conf"] [line "99"] [id "100067"] [msg ".env access blocked by AetherFox VoidGuard"] [tag "custom-blocklist"] [hostname "draconigen.net"] [uri "/.env.backup"] [unique_id "arwtWQ6ct5zVho4N-MiYMAAAAFg"]
[Tue Sep 29 21:27:53.601927 2026] [security2:error]
...
show less
Hacking
Bad Web Bot
๐ฌ๐ง
Swiptly
2026-09-29 21:15:37
(14 hours ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:40:42
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.86.246.222 (222.246.86.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.86.246.222 (222.246.86.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:40:34.773150 2026] [security2:error] [pid 32577:tid 32577] [client 136.86.246.222:55346] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||player-care.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "player-care.com"] [uri "/z9x8c7v6b5-debug-trigger-player-care.com"] [unique_id "arwiQlWn6m4Fge3CD-aAMQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-29 18:37:06
(17 hours ago)
(badbots) Bad bot user-agent [redacted] from 136.86.246.222 (US/United States/222.246.86.136.bc.goog ...
show more
(badbots) Bad bot user-agent [redacted] from 136.86.246.222 (US/United States/222.246.86.136.bc.googleusercontent.com)
show less
Hacking
Anonymous
2026-09-29 17:37:35
(18 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
WizardsToolkit
2026-09-29 17:34:18
(18 hours ago)
tried to access forbidden files; attempted to access /app/.env
Web App Attack
Anonymous
2026-09-29 17:13:01
(18 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-29 17:01:51
(18 hours ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.86.246.222 - - [29/Sep/2026:19:01:46 +0200] "GET /.env.example HTTP/1.1" 404 7386 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 16:52:57
(18 hours ago)
suspicious behavior
Blog Spam
Brute-Force
Web App Attack
Anonymous
2026-09-29 16:40:06
(19 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-29 16:22:27
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.86.246.222 (222.246.86.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.86.246.222 (222.246.86.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 12:22:19.332866 2026] [security2:error] [pid 13784:tid 13784] [client 136.86.246.222:34176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "support2.bwill.dev"] [uri "/.env"] [unique_id "arvlu424W2MF2LCD2SgsCQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-29 16:17:38
(19 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack