Activity timeline
T1595.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 64 reports, and 207 of the 207 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1595.002 Vulnerability Scanning is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1595 Active Scanning. Threadlinqs maps 207 of 2623 tracked threats (7.9%) to it; by severity that is 124 critical, 59 high, 19 medium.
Threats that use T1595.002 most often also use T1190 Exploit Public-Facing Application (185 threats), T1005 Data from Local System (85 threats), T1059 Command and Scripting Interpreter (81 threats), T1082 System Information Discovery (80 threats), T1068 Exploitation for Privilege Escalation (76 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
33 tracked threat actors appear in the threats that use T1595.002; the most frequent are ShinyHunters (4), The Gentlemen (3), BonJoviGoesHard (2), Cl0p (2), NoName057(16) (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1595.002.
Data sources
Telemetry that can reveal T1595.002, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 207 tracked threats that use T1595.002.
- CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Cataloghigh
- TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…high
- Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…high
- Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote…critical
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…critical
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)high
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)high
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)high
- Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rowshigh
- Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…high
- ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Sitecritical
- Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…high
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…medium
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OSmedium
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…critical
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…critical
- CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)critical
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leakcritical
- Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red…critical
- Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chainhigh
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)high
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCEcritical
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…medium
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…critical
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wildcritical
Detection coverage
Threadlinqs maintains 472 detection rules mapped to T1595.002 (SPL 170, KQL 137, Sigma 165). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1595 Active Scanning — 340 tracked threats at the technique level.