conv.

All stories
Active · 14h

Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

Conversation activity · last 15 hours peak 2/30m

Peak 2 items in one 30m at Aug 12, 9 AM; 25 items over 15 hours Aug 12, 9:46 AM — 2 items · Hacker News 1, Press 1Aug 12, 10:16 AM — 2 items · Hacker News 1, Mastodon 1Aug 12, 10:46 AM — 2 items · Hacker News 2Aug 12, 11:16 AM — 1 item · Mastodon 1Aug 12, 11:46 AM — 2 items · Hacker News 2Aug 12, 12:16 PM — 1 item · Hacker News 1Aug 12, 12:46 PM — 3 items · Hacker News 3Aug 12, 1:16 PM — 1 item · Hacker News 1Aug 12, 1:46 PM — 3 items · Hacker News 3Aug 12, 2:16 PM — no itemsAug 12, 2:46 PM — 1 item · Hacker News 1Aug 12, 3:16 PM — no itemsAug 12, 3:46 PM — 1 item · Hacker News 1Aug 12, 4:16 PM — no itemsAug 12, 4:46 PM — no itemsAug 12, 5:16 PM — no itemsAug 12, 5:46 PM — no itemsAug 12, 6:16 PM — no itemsAug 12, 6:46 PM — 3 items · Hacker News 3Aug 12, 7:16 PM — 1 item · Hacker News 1Aug 12, 7:46 PM — 1 item · Hacker News 1Aug 12, 8:16 PM — 1 item · Hacker News 1Aug 12, 8:46 PM — no itemsAug 12, 9:16 PM — no itemsAug 12, 9:46 PM — no itemsAug 12, 10:16 PM — no itemsAug 12, 10:46 PM — no itemsAug 12, 11:16 PM — no itemsAug 12, 11:46 PM — no itemsAug 13, 12:16 AM — no items 2 items · 9:46 AM
12 PM4 PM8 PMnow · 12:46 AM

Clustered from 25 items across 3 sources. Not yet parsed — the coverage below is the raw record.

Press coverage 1

Social posts 2

Voices from the web unedited

  • On average about 100 (TCP) requests hit my home router per minute doing various probing and scanning. Lots of checking for the telnet port obviously. Sometimes you can see a swarm of entirely different IPs scanning the full port range (probing the ports one-by-one).You'll see a lot of deepfield, censys-scanner, visionheight.com, shadowserver.io…

    binaryturtleHacker News13h agoview on Hacker News ↗
  • 🌗 智能體網路指數:AI 機器人流量統計 | Known Agents ➤ 洞察 AI 時代的流量變革:機器人如何重塑全球網頁生態 ✤ https:// knownagents.com/insights 本文介紹「Known Agents」發表的智能體網路指數(The Agentic Web Index),該指數分析了超過五千個網站的流量數據。研究指出,目前網頁流量中有高達百分之三十五來自機器人,且其中近三成與人工智慧(AI)相關。透過分析機器人與人類流量的消長、AI 對話系統的推薦流量以及 robots.txt 協定的遵循率,揭示了 AI 時代下網頁生態系統的劇烈變革。 + 原來現在有將近三分之一的機器人流量都跟 AI 有關,難怪網站阻擋 AI 爬蟲的需求越來越高。 + 看到…

    GripNews@mastodon.socialMastodon · mstdn.party13h agoview on Mastodon ↗
  • Mass automated vulnerability scans have been a very common thing since years before the advent of this in 2001:https://en.wikipedia.org/wiki/Code_Red_(computer_worm)I remember when 'code red' spread and it had the effect of crapping up the contents of my apache server logs. Fun times.such as:GET…

    walrus01Hacker News5h agoview on Hacker News ↗
  • Very similar experience here. Started July 30, sustained through August 6, when it started a significant ramp-up in volume (5x or so).Most of the traffic is originating in GCP. We're seeing ~70k req/min sustained from Google Cloud IP space (AS396982). Reported to GCP Abuse, they've been non-responsive so far.The main distinguishing factor is the…

    oasisbobHacker News5h agoview on Hacker News ↗
  • Fake Googlebot visits are #1 in website logs I've been working on. At the beginning I was fighting with them using Cloudflare ASN block rules or their managed Bot Fight mode but it appeared to be not only pointless, but also harmful for my websites. Bot Fight mode randomly started blocking real Bing / Google / OpenAI crawlers what wasted crawling…

    ChillyCapyHacker News10h agoview on Hacker News ↗
  • Looks like Google has started rolling out this Web Bot Auth thing which seems like something that should gain adoption or become an open standard. https://developers.google.com/crawling/docs/crawlers-fetcher...Seems like the crawler companies would be incentivized to not want to take responsibility for people spoofing their user agents.

    wilgHacker News8h agoview on Hacker News ↗
  • Just in case any of the authors read HN, I'm getting a pretty crazy rendering bug on this page, where a bunch of the contents are redrawing up and down by a few pixels. It seemed to go away with resizing the width a few times, but I didn't look into it too hard. My page width was probably small on first draw. Incredibly distracting though and hard…

    kevin_nisbetHacker News11h agoview on Hacker News ↗
  • Many of those user-agents listed are often faked. Look up which ASN owns their IP. If I block most VPS providers most of the faked bots vanish. There are still some running from residential and phones using hijacked code (readers that are not really just readers but really multipurpose proxies). On that note, do not trust the linked source code…

    BenderHacker News14h agoview on Hacker News ↗
  • Yeah, It started bothering me enough that I recently put together a system where when a application detects a bad actor(a bot enumerating too fast, a random scan for vulnerabilities, etc) it notifies the firewall. Right now I am just shutting them down, But have plans for a honeypot/tarpit system, something real slow that takes up all their time…

    somatHacker News5h agoview on Hacker News ↗
  • Most servers with port 25565 open get hits from either Minecraft griefer bots, or from a bot that looks for that port and warns anyone on that server about the risks of leaving that port open. It doesn't take a huge scale operation to spam every IPv4 address in the world, there are only 2^32 of them, and even then many of those addresses are…

    deatonHacker News10h agoview on Hacker News ↗