Activity timeline
T1595.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 15 reports, and 35 of the 35 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1595.001 Scanning IP Blocks is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1595 Active Scanning. Threadlinqs maps 35 of 2623 tracked threats (1.3%) to it; by severity that is 17 critical, 13 high, 5 medium.
Threats that use T1595.001 most often also use T1190 Exploit Public-Facing Application (32 threats), T1046 Network Service Discovery (24 threats), T1595.002 Vulnerability Scanning (21 threats), T1078 Valid Accounts (16 threats), T1133 External Remote Services (16 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
6 tracked threat actors appear in the threats that use T1595.001; the most frequent are Static Tundra (2), FSB Center 16 (1), FortiBleed operator (1), INC Ransom (1), INC Ransom - G1032 (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1595.001.
Data sources
Telemetry that can reveal T1595.001, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 35 tracked threats that use T1595.001.
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…critical
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…critical
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)critical
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- CVE-2026-64849 — MLflow Server-Side Request Forgery (SSRF) Vulnerability in Model Registry Webhookscritical
- CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russiahigh
- Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to…high
- SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)critical
- OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerabilitymedium
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…high
- Progress ShareFile Zero-Day Path Traversal Flaw Forces Storage Zone Controller Shutdownhigh
- US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB…medium
- FSB Centre 16 (Berserk Bear/Energetic Bear) targets global critical national infrastructure via vulnerable…high
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…high
- Internet-Wide Reconnaissance Scans Target MCP Servers and Claude/Cursor AI-Agent Credentialsmedium
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…high
- CVE-2025-3248 & CVE-2026-5027: Langflow RCE and Path Traversal Chained for Flodrix Botnet Deploymentcritical
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…critical
- CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)critical
- CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)critical
- Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide…medium
- AI Compute Hijacking: Stolen Ollama Server Wired Into Autonomous "VAPT" Exploit Pipeline (Sysdig)high
- FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operationscritical
- CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitationcritical
- FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet'…critical
- Exposed RDP / RDWeb Misconfigurations Exploited for Initial Access and Lateral Movement (Huntress 2026)high
- SolarWinds Serv-U DoS (CVE-2026-28318) — Actively Exploited Uncontrolled Resource Consumption via…high
- WantToCry Ransomware — Remote SMB Encryption Campaign Targeting Internet-Exposed TCP 139/445 (Sophos CTU)high
Detection coverage
Threadlinqs maintains 46 detection rules mapped to T1595.001 (SPL 22, KQL 9, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1595 Active Scanning — 340 tracked threats at the technique level.