Public vulnerability counts cover 26 Sept 2026, 01:14 – 27 Sept 2026, 01:14 UTC. Sensor counts cover the separate sensor window above.
01 / Traffic
Observation activity
24 H
86,384 eventsHourly · UTC
4.2k2.1k0
Events before deduplication. The first and last intervals may be partial.
02 / Honeypots
Attempt distribution
Deduplicated attempts, grouped by honeypot type. 0 events are not yet linked to a deduplicated attempt and are excluded from this chart.
03 / Geography
Observed traffic origins
COUNTRY
41 countries observed2,739 geolocated events
FewerMore events13.7 % geolocated
Map uses the 20,000 most recent events out of 86,384 in this window. Source infrastructure location, not attribution to a country or actor. 17,261 sampled events have no represented country.
04 / Attack techniques
Recognized techniques
01Failed login3,194 observations
02Login attempt3,063 observations
03Reconnaissance411 observations
04Command fingerprint68 observations
05Path traversal48 observations
06File artifact44 observations
07Reported shell command39 observations
08Reported download command8 observations
Behavior matches in the 20,000 most recent eligible events. An event can match several techniques. A CVE is not required to recognize an attack technique.
Ranked by groups with an active CVE association, including leads that need confirmation. Review each CVE’s confidence and supporting evidence. This is observed honeypot activity, not a global exploitation ranking or proof of successful compromise. Public findings require at least 4 distinct sources and must complete the disclosure delay.