Some IPs probe a CVE's exact exploit path weeks before it's public, and if you're recording, you can see it.
On April 11 one of our honeypots logged 16 requests for the cPanel WHM login path on port 2087 from 85[.]122[.]114[.]177, an address that has never touched us otherwise, before or since. 17 days later cPanel disclosed CVE-2026-41940, a 9.8 auth bypass in exactly that flow.
Method, formulas, and the live table:
https://honeylabs.net/blog/probe-17-days-before-the-cve
#ThreatIntel #ThreatHunting #Honeypots #CVE #InfoSec #DFIR
Remote
HoneyLabs
@HoneyLabs@infosec.exchange
HoneyLabs is an open-source threat intelligence platform. We gather honeypot data on all TCP ports and provide this via MCP, cURL, and our web interface. Currently, we have more than 28 million probes to investigate!
0 Followers
0 Following
5 Posts
Joined July 13, 2026
HoneyLabs:
Open post
Added new tools!
cve_lookup, top_attackers by=cve, and a better ioc_lookup.
https://honeylabs.net/mcp
0
0
0
0
Open post
AI crawler impersonation is getting more prevalent these days. Here's a campaign of 26 hosts, scanning with 42,321 different Anthropic user-agents
https://honeylabs.net/blog/spoofed-ai-crawlers-one-client
0
0
0
0
Open post
Replying to @hrbrmstr@mastodon.social
@hrbrmstr@mastodon.social Specialised local LLMs for honeypots seems like a really cool angle. Will be keeping an eye on them!
0
1
0
0
Open post
Replying to @hrbrmstr@mastodon.social
@hrbrmstr@mastodon.social Ah, I thought the site referenced using a local LLM. I wonder how they defend against injection attacks. Would be a wild way to priv esc a honeypot.
0
0
0
0