Activity timeline
T1596.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 11 reports, and 26 of the 26 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1596.005 Scan Databases is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1596 Search Open Technical Databases. Threadlinqs maps 26 of 2623 tracked threats (1%) to it; by severity that is 14 critical, 8 high, 2 medium.
Threats that use T1596.005 most often also use T1190 Exploit Public-Facing Application (18 threats), T1595.002 Vulnerability Scanning (13 threats), T1588.002 Tool (12 threats), T1588.006 Vulnerabilities (12 threats), T1005 Data from Local System (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
3 tracked threat actors appear in the threats that use T1596.005; the most frequent are UNC6240 (2), SNOWLIGHT (1), ShinyHunters (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1596.005.
Threat actors using it
Tracked threats
26 tracked threats use T1596.005.
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…critical
- CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russiahigh
- Critical Metabase Zero-Day (CVE-2026-72898): Unauthenticated SQL Injection Grants Admin Access, Exploited in…critical
- Coldcard Hardware Wallet $111M Bitcoin Theft: Weak RNG Private Key Vulnerability (Yasmarang PRNG Fallback)critical
- Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)critical
- Metabase Unauthenticated SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) Exploited to Steal…critical
- Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theftcritical
- Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addressescritical
- COLDCARD Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theftcritical
- CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)critical
- KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilizationhigh
- Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggeringcritical
- Capital One Open-Sources VulnHunter: Agentic, Claude-Opus-4.8-Powered Vulnerability Detection and…
- CVE-2026-32746: Pre-Auth BSS Buffer Overflow in GNU inetutils telnetd LINEMODE SLC Handlinghigh
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…high
- CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Daymedium
- WP-SHELLSTORM: Exposed Chinese-Speaking Threat Actor Server Reveals Mass WordPress/Joomla Webshell Brokerage…high
- Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240)critical
- AI Compute Hijacking: Stolen Ollama Server Wired Into Autonomous "VAPT" Exploit Pipeline (Sysdig)high
- Apple 'Hide My Email' Aliases Deanonymizable to Real Email Addresses (Unpatched 1+ Year)medium
- OpenAI Releases GPT-5.5-Cyber: Defender-Restricted AI for Automated Vulnerability Detection, Exploitability…
- ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+…critical
- SolarWinds Serv-U DoS (CVE-2026-28318) — Actively Exploited Uncontrolled Resource Consumption via…high
- Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container…high
- NGINX Rift — CVE-2026-42945 Heap Buffer Overflow in ngx_http_rewrite_module (CVSS v4 9.2 Critical…critical
- CVE-2026-33824: Windows IKE Extensions Unauthenticated RCE via Double Freecritical
Detection coverage
Threadlinqs maintains 24 detection rules mapped to T1596.005 (SPL 9, KQL 7, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1596 Search Open Technical Databases — 95 tracked threats at the technique level.