๐บ๐ธ
TPI-Abuse
2026-07-27 16:09:28
(54 minutes ago)
(mod_security) mod_security (id:210492) triggered by 3.133.134.13 (ec2-3-133-134-13.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.133.134.13 (ec2-3-133-134-13.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 12:09:22.499197 2026] [security2:error] [pid 938659:tid 938659] [client 3.133.134.13:43652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newcitypark.com"] [uri "/.git/config"] [unique_id "ameCsgcGKjLyzKPSk7geSAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:35:41
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 3.133.134.13 (ec2-3-133-134-13.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.133.134.13 (ec2-3-133-134-13.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:35:34.678935 2026] [security2:error] [pid 200004:tid 200004] [client 3.133.134.13:34656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newcastle91.org"] [uri "/.git/config"] [unique_id "amd6xmgqgUx9dwojTVucGwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
pixiekat
2026-07-27 15:07:51
(1 hour ago)
[Mon Jul 27 16:07:50.214110 2026] [security2:error] [pid 3334545:tid 3334631] [client 3.133.134.13:5 ...
show more
[Mon Jul 27 16:07:50.214110 2026] [security2:error] [pid 3334545:tid 3334631] [client 3.133.134.13:52962] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "140"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "newburycomics.spacecadetgrrl.me"] [uri "/"] [unique_id "amd0RqWOoqUhKjxFPN9KHgAAAU8"]
[Mon Jul 27 16:07:50.563983 2026] [security2:error] [pid 3334545:tid 3334630] [client 3.133.134.13:52976] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "140"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "newburycomics.spacecadetgrrl.me"] [uri "/"] [unique_id "amd0RqWOoqUhKjxFPN9KHwAAAU4"]
[Mon
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-07-27 14:05:29
(2 hours ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:42:22
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.133.134.13 (ec2-3-133-134-13.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.133.134.13 (ec2-3-133-134-13.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:42:19.234616 2026] [security2:error] [pid 263030:tid 263030] [client 3.133.134.13:36658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "new.taekwondoit.com"] [uri "/.git/config"] [unique_id "amcn-7qjLOPWdCSr12psOQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
tedmichalik.com
2026-07-27 09:25:05
(7 hours ago)
3.133.134.13 - - [27/Jul/2026:05:24:53 -0400] "GET /.git/config HTTP/1.1" 404 35841 "-" "Mozilla/5.0 ...
show more
3.133.134.13 - - [27/Jul/2026:05:24:53 -0400] "GET /.git/config HTTP/1.1" 404 35841 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 07:36:50
(9 hours ago)
Excessive 404/403 errors
Brute-Force
๐ฎ๐น
VHosting
2026-07-27 06:30:03
(10 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-27 05:58:33
(11 hours ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-27 04:56:56
(12 hours ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478) MV:{"then": "$1:__proto__:then", "status": "resol...
show less
Hacking
๐ฑ๐ป
garmtech.com
2026-07-25 00:47:49
(2 days ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking