| |
Most of the CVE-2026-4020 attackers are the same client
A sophisticated single attacker is behind 99.1% of CVE-2026-4020 exploitation attempts, despite appearing to come from hundreds of different IPs and user-agents. The operation uses a Google Cloud fleet of thousands of short-lived instances with rotating identifiers to systematically harvest credentials and configuration files across 36,000+ ports, treating newly discovered vulnerabilities as just another target in their automated collection routine. The attacker's HTTP fingerprint remains constant across all requests, revealing that while they rotate IP addresses and user-agents to evade traditional defenses, the underlying request structure betrays their single unified operation.
Read Full Article →
← More Tech news