๐บ๐ธ
Ar1s
2026-09-17 16:13:05
(1 hour ago)
[1:2061026] ET WEB_SERVER Next.js Middleware Authorization Bypass (CVE-2025-29927) ::: Port: 80/TCP
Exploited Host
๐ง๐ช
Ivo Vynckier
2026-09-17 15:01:00
(3 hours ago)
35.185.71.33 - - [17/Sep/2026:09:43:51 +0200] "GET /service-account.json HTTP/2.0" 404 2310 "-" "Moz ...
show more
35.185.71.33 - - [17/Sep/2026:09:43:51 +0200] "GET /service-account.json HTTP/2.0" 404 2310 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.185.71.33 - - [17/Sep/2026:09:43:51 +0200] "GET /credentials.json HTTP/2.0" 404 2310 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.185.71.33 - - [17/Sep/2026:09:43:51 +0200] "GET /secrets.json HTTP/2.0" 404 2310 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.185.71.33 - - [17/Sep/2026:09:43:51 +0200] "GET /secrets.yml HTTP/2.0" 404 2310 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
show less
Web App Attack
๐จ๐ญ
backslash
2026-09-17 10:36:01
(7 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
Anonymous
2026-09-17 10:35:02
(7 hours ago)
Bot / scanning and/or hacking attempts: GET /aws-exports.js HTTP/2.0, GET /config.py HTTP/2.0, GET / ...
show more
Bot / scanning and/or hacking attempts: GET /aws-exports.js HTTP/2.0, GET /config.py HTTP/2.0, GET /_payload.json HTTP/2.0, GET /env.old HTTP/2.0, GET /@fs/root/.env?raw?? HTTP/2.0, GET /push_config.json HTTP/2.0, GET /google-service-account.json HTTP/2.0, GET /.env.prod.bak HTTP/2.0, GET /firebase.json HTTP/2.0, GET /debug/vars HTTP/2.0, GET /.env.production.bak HTTP/2.0, GET /.env.docker HTTP/2.0, GET /api/.env.bak HTTP/2.0, GET /public/admin.json HTTP/2.0, GET /dashboard/_payload.json HTTP/2.0, GET /config/gcp-credentials.json HTTP/2.0, GET /config/firebase-admin.json HTTP/2.0, GET /firebase-admin.json HTTP/2.0, GET /@fs/proc/self/environ?import&raw?? HTTP/2.0, GET /google-services.json HTTP/2.0, GET /gcp-service.json HTTP/2.0, GET /@fs/.env?raw?? HTTP/2.0, GET /gcp-key.json HTTP/2.0, GET /admin/_payload.json HTTP/2.0
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 10:26:43
(7 hours ago)
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 35.185.71.33 - - [17/Sep/2026:12:26:29 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.185.71.33 - - [17/Sep/2026:12:26:29 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.185.71.33 - - [17/Sep/2026:12:26:30 +0200] "GET /.ssh/known_hosts HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.185.71.33 - - [17/Sep/2026:12:26:30 +0200] "GET /.ssh/authorized_keys HTTP/2.0" 404 1338 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexit
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-09-17 09:00:22
(9 hours ago)
[17/Sep/2026:10:00:35.849598 +0100] aqusMyJpx3jPjoq9PxlM6gAAAEM 35.185.71.33 48744 188.246.206.60 70 ...
show more
[17/Sep/2026:10:00:35.849598 +0100] aqusMyJpx3jPjoq9PxlM6gAAAEM 35.185.71.33 48744 188.246.206.60 7081
[17/Sep/2026:10:00:37.918169 +0100] aqusNSJpx3jPjoq9PxlM8AAAAFE 35.185.71.33 48842 188.246.206.60 7081
...
show less
Brute-Force
๐ฆ๐บ
rubixstudios
2026-09-17 08:42:02
(9 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-17 08:12:49
(9 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 06:49:20
(11 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.185.71.33 - - [17/Sep/2026:08:49:01 +0200] "GET /.ssh/authorized_keys HTTP/2.0" 301 489 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-17 06:32:52
(11 hours ago)
Attack against Apache (too many 404s)
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(12 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
Savvii
2026-09-17 05:55:17
(12 hours ago)
20 attempts against mh-misbehave-ban on milky
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-17 05:51:49
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Eric
2026-09-17 05:42:46
(12 hours ago)
[Thu Sep 17 05:42:45.537472 2026] [security2:error] [pid 797835:tid 797835] [client 35.185.71.33:0] ...
show more
[Thu Sep 17 05:42:45.537472 2026] [security2:error] [pid 797835:tid 797835] [client 35.185.71.33:0] [client 35.185.71.33] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/rclone.conf"] [unique_id "aqt91fF2fcQ_YrER2_l-qQAAAB4"]
[Thu Sep 17 05:42:45.955918 2026] [security2:error] [pid 797825:tid 797825] [client 35.185.71.33:0] [client 35.185.71.33] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-17 05:40:13
(12 hours ago)
Web App Attack