Advertisement
Identifying Origin IP Addresses Behind Cloudflare and WAF Services
Examine technical methods used to discover backend origin IPs hidden behind Cloudflare, including DNS history, TLS fingerprinting, and outbound leaks.
Scans Target Model Context Protocol Servers and AI Credentials
Security researchers observe an increase in scans targeting Model Context Protocol (MCP) servers and AI credentials, potentially exposing sensitive data.
GitHub API Abuse: Detecting Ghost Account Reconnaissance Campaigns
Threat actors are leveraging thousands of ghost accounts to map GitHub organizations via API abuse, facilitating future targeted supply chain attacks.
GitHub API Abuse: Attackers Map Corporate Orgs via Dormant Accounts
Datadog Security Labs warns of systematic GitHub API enumeration campaigns using dormant accounts and compromised OAuth tokens to map corporate organizations.
Automated Favicon.ico Reconnaissance for Host Enumeration
Understand how attackers automate favicon.ico analysis for host reconnaissance. Learn to identify and defend against this common, yet often overlooked, enumeration…
JDY Botnet: China-Linked Campaign Targets US Military Networks
Analysis of the China-linked JDY botnet's expanded targeting of U.S. military networks, its reconnaissance TTPs, and critical mitigation strategies.
Advertisement
Detecting API Discovery Scans for swagger.json: Security Guide
Analysis of automated scans for swagger.json and OpenAPI files. Learn how to secure RESTful APIs against discovery-based attacks and reconnaissance.
FBI Disrupts First VPN Service Used by Ransomware Groups
The FBI and international partners dismantled First VPN, a specialized service used by dozens of ransomware groups for reconnaissance and intrusions.
Emerging Reconnaissance: Attackers Actively Probe AI Models
DShield sensors detect increasing scanning activity targeting popular AI models like Claude and Hugging Face, signaling a potential new attack vector for threat actors.
TrueConf Zero-Day: Exploitation Against Asian Governments
A Chinese threat actor is actively exploiting a TrueConf video conferencing zero-day to conduct reconnaissance and achieve privilege escalation against Asian government…
Analysis of 'iranbot' Message in Cowrie Honeypot Logs
A peculiar 'iranbot_was_here' message, alongside Telnet logins and portscans, was observed in Cowrie honeypot logs, signaling potential reconnaissance activity.
Adminer & phpMyAdmin: Attacker Scans Target Database Management Tools
Runtime Rebel observes increased honeypot scans targeting Adminer and phpMyAdmin.
Analyzing Proxy Scanner Activity: Monitoring /proxy/ URI Patterns
Threat actors are shifting scanning patterns to identify open proxies using /proxy/ URI prefixes. Learn how to detect and mitigate these reconnaissance scans.
CyberStrikeAI Exploitation: AI Tools Targeting Fortinet Firewalls
Threat actors are repurposing CyberStrikeAI to automate reconnaissance and exploit critical vulnerabilities in Fortinet FortiGate firewalls and edge devices.
Automated Reconnaissance Targeting React2Shell Implementations
Analysis of a specialized toolkit currently utilized by threat actors to identify and exploit React2Shell vulnerabilities within enterprise network perimeters.