The report notes that some hosting providers have begun taking action against these activities, but significant work remains to curtail the growing tide of vulnerability scanning threatening internet-connected devices worldwide. According to recent data compiled by F5 Labs in their February 2025 Sensor Intel Series report, scanning for vulnerabilities increased by a staggering 91% in 2024 compared to the previous year. While researchers at F5 Labs initially suspected that massive scanning for CVE-2023-1389 might be skewing the numbers, further analysis revealed that even when removing this specific threat, the overall traffic still showed a 91% increase. Vulnerability scanning attacks targeting internet-connected devices have surged dramatically over the past year. For instance, CVE-2024-3721, a command injection vulnerability affecting TBK DVR models, surged by two orders of magnitude in January 2025, climbing to fourth place among targeted vulnerabilities. This pattern of scanning predominantly from hosting providers rather than residential networks indicates that attackers are leveraging commercial infrastructure for their campaigns, likely due to the greater bandwidth and stability these services provide. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The trend shows no signs of abating in early 2025 data, suggesting these elevated threat levels may represent a new normal for internet-connected devices. Contrary to what might be expected, the vast majority of scanning doesn’t originate from botnets comprised of compromised consumer devices. The data reveals that command injection vulnerabilities in consumer devices remain particularly attractive to attackers. The TP-Link Archer AX21 router vulnerability (CVE-2023-1389) continues to dominate scanning activity for the sixth consecutive month. Analysis of the “top talkers” by autonomous system number (ASN) revealed that 75% of all traffic originated from just 20 ASNs, with most being hosting providers. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 04 Mar 2025 05:55:04 +0000