Automated probing for exposed environment and configuration files across multiple application paths, ...
show moreAutomated probing for exposed environment and configuration files across multiple application paths, including /api/.env, /backend/.env, /app/.env, /config/.env and traversal attempts for .env files. Activity is consistent with automated credential and secret discovery. Requests were unsolicited and blocked.
show less
Automated probing for exposed environment files. Source requested multiple sensitive .env variants i ...
show moreAutomated probing for exposed environment files. Source requested multiple sensitive .env variants including /.env, /.env.local, /.env.production and /.env.backup. Activity is consistent with credential and configuration file reconnaissance. Requests were unsolicited and blocked.
show less
Automated WordPress exploit probing against a private self-hosted service. Source enumerated multipl ...
show moreAutomated WordPress exploit probing against a private self-hosted service. Source enumerated multiple WordPress REST API endpoints and repeatedly sent POST requests to /wp-json/batch/v1 and alternative WordPress installation paths. This behavior is consistent with reconnaissance targeting the WordPress REST API batch endpoint associated with recent WordPress vulnerabilities including CVE-2026-63030. Target does not run WordPress and requests were blocked.
show less
Automated reconnaissance against a private self-hosted service attempting to retrieve sensitive conf ...
show moreAutomated reconnaissance against a private self-hosted service attempting to retrieve sensitive configuration and credential files, including AWS credentials, environment files and application configuration. Activity appears designed to identify exposed secrets or cloud credentials. Requests were unsolicited and blocked.
show less
Automated credential and configuration file reconnaissance against a private self-hosted service. So ...
show moreAutomated credential and configuration file reconnaissance against a private self-hosted service. Source attempted to retrieve sensitive files including /.env, /.env.production, /.aws/credentials and /aws.env. These files may contain passwords, API keys or cloud credentials. Requests were unsolicited and blocked.
show less
Unsolicited attempt to access /.git/config on a private self-hosted web service. This file may expos ...
show moreUnsolicited attempt to access /.git/config on a private self-hosted web service. This file may expose repository configuration and is commonly probed during automated web reconnaissance. Request was blocked with HTTP 403.
show less
Automated WordPress reconnaissance against a private self-hosted service. Source systematically prob ...
show moreAutomated WordPress reconnaissance against a private self-hosted service. Source systematically probed multiple common WordPress installation paths including /blog/, /wordpress/, /wp/, /site/, /test/ and /xmlrpc.php. The target does not run WordPress. Requests were unsolicited and blocked with HTTP 403.
show less
Automated web application reconnaissance against a private self-hosted service. Source probed for Wo ...
show moreAutomated web application reconnaissance against a private self-hosted service. Source probed for WordPress installations and components including /xmlrpc.php and multiple /wp-includes/wlwmanifest.xml paths. The target does not run WordPress. Requests were unsolicited and blocked with HTTP 403.
show less
Repeated unsolicited POST requests to a private self-hosted web service. Requests were automatically ...
show moreRepeated unsolicited POST requests to a private self-hosted web service. Requests were automatically blocked with HTTP 403. No legitimate access expected from this source. Automated web application probing/reconnaissance.
show less
Repeated unsolicited POST requests to a private self-hosted web service. Requests were automatically ...
show moreRepeated unsolicited POST requests to a private self-hosted web service. Requests were automatically blocked with HTTP 403 by reverse proxy/geolocation policy. Activity appears to be automated web application probing/reconnaissance.
show less