Skip to main content
← All Articles

Tag

#Reconnaissance

15 articles

Advertisement

MEDIUM
Cloud Security

Identifying Origin IP Addresses Behind Cloudflare and WAF Services

Examine technical methods used to discover backend origin IPs hidden behind Cloudflare, including DNS history, TLS fingerprinting, and outbound leaks.

Runtime Rebel Intel
4 min read · Jul 20, 2026
MEDIUM
Threat Intel

Scans Target Model Context Protocol Servers and AI Credentials

Security researchers observe an increase in scans targeting Model Context Protocol (MCP) servers and AI credentials, potentially exposing sensitive data.

Runtime Rebel Intel
4 min read · Jul 13, 2026
MEDIUM
Threat Intel

GitHub API Abuse: Detecting Ghost Account Reconnaissance Campaigns

Threat actors are leveraging thousands of ghost accounts to map GitHub organizations via API abuse, facilitating future targeted supply chain attacks.

Runtime Rebel Intel
4 min read · Jul 11, 2026
GitHub API Abuse: Attackers Map Corporate Orgs via Dormant Accounts
MEDIUM
Threat Intel

GitHub API Abuse: Attackers Map Corporate Orgs via Dormant Accounts

Datadog Security Labs warns of systematic GitHub API enumeration campaigns using dormant accounts and compromised OAuth tokens to map corporate organizations.

Runtime Rebel Intel
4 min read · Jul 9, 2026
INFO
Threat Intel

Automated Favicon.ico Reconnaissance for Host Enumeration

Understand how attackers automate favicon.ico analysis for host reconnaissance. Learn to identify and defend against this common, yet often overlooked, enumeration…

Runtime Rebel Intel
4 min read · Jun 29, 2026
HIGH
Threat Intel

JDY Botnet: China-Linked Campaign Targets US Military Networks

Analysis of the China-linked JDY botnet's expanded targeting of U.S. military networks, its reconnaissance TTPs, and critical mitigation strategies.

Runtime Rebel Intel
4 min read · Jun 10, 2026

Advertisement

MEDIUM
Threat Intel

Detecting API Discovery Scans for swagger.json: Security Guide

Analysis of automated scans for swagger.json and OpenAPI files. Learn how to secure RESTful APIs against discovery-based attacks and reconnaissance.

Runtime Rebel Intel
3 min read · Jun 3, 2026
HIGH
Threat Intel

FBI Disrupts First VPN Service Used by Ransomware Groups

The FBI and international partners dismantled First VPN, a specialized service used by dozens of ransomware groups for reconnaissance and intrusions.

Runtime Rebel Intel
4 min read · May 22, 2026
INFO
Threat Intel

Emerging Reconnaissance: Attackers Actively Probe AI Models

DShield sensors detect increasing scanning activity targeting popular AI models like Claude and Hugging Face, signaling a potential new attack vector for threat actors.

Runtime Rebel Intel
5 min read · Apr 15, 2026
CRITICAL
Threat Intel

TrueConf Zero-Day: Exploitation Against Asian Governments

A Chinese threat actor is actively exploiting a TrueConf video conferencing zero-day to conduct reconnaissance and achieve privilege escalation against Asian government…

Runtime Rebel Intel
4 min read · Apr 3, 2026
INFO
Threat Intel

Analysis of 'iranbot' Message in Cowrie Honeypot Logs

A peculiar 'iranbot_was_here' message, alongside Telnet logins and portscans, was observed in Cowrie honeypot logs, signaling potential reconnaissance activity.

Runtime Rebel Intel
5 min read · Mar 19, 2026
INFO
Threat Intel

Adminer & phpMyAdmin: Attacker Scans Target Database Management Tools

Runtime Rebel observes increased honeypot scans targeting Adminer and phpMyAdmin.

Runtime Rebel Intel
5 min read · Mar 18, 2026
MEDIUM
Threat Intel

Analyzing Proxy Scanner Activity: Monitoring /proxy/ URI Patterns

Threat actors are shifting scanning patterns to identify open proxies using /proxy/ URI prefixes. Learn how to detect and mitigate these reconnaissance scans.

Runtime Rebel Intel
4 min read · Mar 16, 2026
HIGH
Threat Intel

CyberStrikeAI Exploitation: AI Tools Targeting Fortinet Firewalls

Threat actors are repurposing CyberStrikeAI to automate reconnaissance and exploit critical vulnerabilities in Fortinet FortiGate firewalls and edge devices.

Runtime Rebel Intel
3 min read · Mar 3, 2026
Automated Reconnaissance Targeting React2Shell Implementations
HIGH
Vulnerabilities

Automated Reconnaissance Targeting React2Shell Implementations

Analysis of a specialized toolkit currently utilized by threat actors to identify and exploit React2Shell vulnerabilities within enterprise network perimeters.

Runtime Rebel Intel
2 min read · Feb 23, 2026