Public vulnerability counts cover 24 Sept 2026, 22:59 – 25 Sept 2026, 22:59 UTC. Sensor counts cover the separate sensor window above.
01 / Traffic
Observation activity
24 H
96,943 eventsHourly · UTC
5.1k2.5k0
Events before deduplication. The first and last intervals may be partial.
02 / Honeypots
Attempt distribution
Deduplicated attempts, grouped by honeypot type. 0 events are not yet linked to a deduplicated attempt and are excluded from this chart.
03 / Geography
Observed traffic origins
COUNTRY
33 countries observed7,058 geolocated events
FewerMore events35.3 % geolocated
Map uses the 20,000 most recent events out of 96,943 in this window. Source infrastructure location, not attribution to a country or actor. 12,942 sampled events have no represented country.
04 / Attack techniques
Recognized techniques
01Failed login2,067 observations
02Login attempt2,036 observations
03Reconnaissance716 observations
04Path traversal45 observations
05Command fingerprint29 observations
06File artifact11 observations
07Reported shell command7 observations
08Command injection4 observations
Behavior matches in the 20,000 most recent eligible events. An event can match several techniques. A CVE is not required to recognize an attack technique.
Ranked by groups with an active CVE association, including leads that need confirmation. Review each CVE’s confidence and supporting evidence. This is observed honeypot activity, not a global exploitation ranking or proof of successful compromise. Public findings require at least 4 distinct sources and must complete the disclosure delay.