Threat Pulse W41 — Oracle-Sourced Scan Surge & Critical RCE Blitz
Executive Summary
Week 41 (2026-10-02 to 2026-10-05) recorded 76,606 inbound probes, a significant 60.9% decrease from the prior week. However, this reduction is largely a statistical artifact driven by one dominant scanning source rather than a genuine decline in threat activity. Five critical-severity RCE campaigns remained fully active, targeting widespread vulnerabilities in Hikvision, PHPUnit, Apache, GeoServer, and Microsoft Exchange. The overall threat posture remains elevated.
Attack Volume & Trends
| Metric | Value | vs. Prior Week |
|---|---|---|
| Total Probes | 76,606 | -60.9% |
| Recon | 48,134 | — |
| Scan | 15,009 | — |
| Exploit | 10,733 | — |
| Bruteforce | 2,103 | — |
| RCE | 462 | — |
| Auth | 171 | — |
Facade breakdown:
| Facade | Hits |
|---|---|
| fake-http | 29,784 |
| fake-https | 29,254 |
| fake-ssh | 9,702 |
| fake-telnet | 5,741 |
| fake-postgres | 1,048 |
| fake-redis | 532 |
| fake-mysql | 371 |
| fake-mongodb | 174 |
HTTP and HTTPS facades together absorbed 77% of all traffic, consistent with attacker focus on web-facing infrastructure. SSH and Telnet remain persistently targeted, reflecting ongoing credential-stuffing and IoT exploitation activity. Database facades (PostgreSQL, Redis, MySQL, MongoDB) collectively received 2,125 hits, a lower share but indicative of automated service discovery sweeps.
The volume drop from the prior week should be interpreted cautiously. A single source IP contributed 55,583 events — approximately 72.6% of all weekly traffic. Stripping that single actor, underlying baseline activity remains broadly consistent with previous weeks.
Top Threat Actors
| Rank | ASN / Org | Country | Events | Dominant Behavior |
|---|---|---|---|---|
| 1 | Oracle Corporation | NL | 55,583 | Scan |
| 2 | Amarutu Technology Ltd | DE | 1,637 | Scan |
| 3 | Oracle Corporation | NL | 762 | Scan |
| 4 | ZORNTECH WEB SOLUTIONS | TR | 620 | Scan |
| 5 | ZORNTECH WEB SOLUTIONS | TR | 616 | Scan |
Key observations:
- Oracle Corporation (NL) netblocks contributed two entries in the top five, collectively accounting for 56,345 events (73.6% of total weekly volume). This is consistent with scanner infrastructure — whether commercial, research, or abused cloud compute — hosted on Oracle Cloud's Amsterdam region. The volume and behavioral signature (dominant scan type) suggest an automated, wide-spectrum reconnaissance sweep rather than a targeted intrusion campaign.
- Amarutu Technology Ltd (DE) is a frequently observed hosting provider associated with bulk-scanner and proxy infrastructure. Its presence as second-highest source is consistent with prior weeks.
- ZORNTECH WEB SOLUTIONS (TR) contributed two closely numbered source IPs with nearly identical event counts (620 and 616), strongly suggesting coordinated or paired scanning from the same operator.
Active Campaigns
All five tracked campaigns reported 61,603 hits each this week — a figure that precisely matches the dominant Oracle scanner's activity, suggesting these campaign detections are largely attributable to that single scanning source probing for vulnerable endpoints at scale.
| Campaign | Severity | Type | Hits |
|---|---|---|---|
| Hikvision ISAPI RCE | Critical | RCE | 61,603 |
| PHPUnit eval-stdin RCE | Critical | RCE | 61,603 |
| Apache Path Traversal / RCE | Critical | Path Traversal | 61,603 |
| GeoServer OGC Filter RCE | Critical | RCE | 61,603 |
| Exchange ProxyLogon | Critical | RCE | 61,603 |
Campaign analysis:
- Hikvision ISAPI RCE: Targets unpatched IP cameras and NVR systems via the ISAPI interface. Exploitation grants unauthenticated remote code execution. Widely exploited by botnet operators for DDoS recruitment.
- PHPUnit eval-stdin RCE (CVE-2017-9841): A legacy vulnerability in PHPUnit that exposed a test utility to unauthenticated code execution via POST to
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php. Despite its age, it remains a high-yield target due to abandoned or unaudited web applications. - Apache Path Traversal / RCE: Likely encompasses CVE-2021-41773 / CVE-2021-42013 or similar Apache HTTP Server traversal chains enabling file disclosure and command execution.
- GeoServer OGC Filter RCE (CVE-2024-36401): A critical vulnerability disclosed in mid-2024 allowing unauthenticated RCE via OGC filter evaluation. Continued presence confirms this remains an actively exploited, unpatched attack surface across internet-facing GIS deployments.
- Exchange ProxyLogon (CVE-2021-26855 et al.): A multi-year-old but persistently targeted Exchange exploitation chain. Continued high-volume probing indicates a large population of unpatched Exchange servers remains reachable.
The uniform hit count across all campaigns strongly implies a single automated toolset cycling through a comprehensive exploit checklist per target, rather than five independent campaign operators.
Notable Paths & Techniques
The following paths received significant unsolicited traffic outside of tracked campaigns:
| Path / Probe | Hits | Assessment |
|---|---|---|
/ |
2,027 | Root enumeration; fingerprinting server type and response behavior |
/login |
1,254 | Generic login panel discovery; precursor to credential attacks |
/login/ |
919 | Trailing-slash variant; bypasses naive path-based filtering |
/cgi-bin/ |
900 | CGI directory enumeration; targets legacy CGI scripts and shellshock-style payloads |
/phpmyadmin/ |
875 | phpMyAdmin discovery; common target for default/weak credential attacks |
/manager/ |
874 | Tomcat Manager interface probe; targets default Tomcat credentials |
/cgi-bin-sdb/ |
874 | Vendor-specific CGI path; associated with embedded device firmware (routers, NAS) |
database=postgres |
347 | PostgreSQL service fingerprinting; likely automated DB discovery |
UNSTABLE |
192 | Malformed or protocol-violation probe; may be fuzzer or misconfigured scanner artifact |
/robots.txt |
184 | Standard reconnaissance step; attackers mine disallowed paths for sensitive endpoints |
Notable technique observations:
- The
/loginand/login/split (1,254 + 919 = 2,173 combined hits) highlights that attackers routinely probe both normalized and trailing-slash variants to defeat simple string-match defenses. /cgi-bin-sdb/is particularly associated with embedded device interfaces (notably some QNAP and Synology NAS paths), indicating IoT/NAS-targeting alongside traditional web server exploitation.- The
UNSTABLEprobe string is anomalous and warrants monitoring — it may reflect a fuzzing framework probing for parser errors, or a misconfigured tool leaking internal state labels. database=postgresappearing as a notable probe outside the fake-postgres facade suggests HTTP-level parameter injection scanning, where attackers embed database identifiers in web request parameters to probe for backend exposure.
Geographic Distribution
| Country | Events | % of Total | Notes |
|---|---|---|---|
| Netherlands (NL) | 57,455 | 75.0% | Dominated by Oracle Cloud scanner infrastructure |
| United States (US) | 2,420 | 3.2% | Mixed commercial hosting; diverse tooling |
| China (CN) | 2,417 | 3.2% | Consistent presence; broad recon and exploit activity |
| Germany (DE) | 2,175 | 2.8% | Includes Amarutu bulk-scanner traffic |
| France (FR) | 1,533 | 2.0% | Hosting and VPS infrastructure |
| Turkey (TR) | 1,443 | 1.9% | Includes ZORNTECH coordinated scanning |
| Pakistan (PK) | 1,082 | 1.4% | Elevated vs. baseline; monitor for trend continuation |
| Romania (RO) | 1,010 | 1.3% | Common proxy/VPS abuse origin |
Excluding the dominant NL scanner, the remaining 19,151 events distribute more evenly across US, CN, DE, FR, TR, PK, and RO — a distribution consistent with prior weeks and reflecting the standard global attacker ecosystem. Pakistan's share at 1,082 events merits continued observation to determine whether it represents a sustained increase or a transient spike.
Recommendations
- Prioritize patching for active RCE targets. All five active campaigns target known, CVE-assigned vulnerabilities. Organizations running Hikvision cameras, internet-facing GeoServer, Exchange, Apache HTTP Server, or legacy PHP applications with PHPUnit in vendor paths should verify patch status immediately.
- Remove or restrict PHPUnit from production environments. CVE-2017-9841 affects a development dependency that should never be deployed to production. Audit
vendor/directories in all web-accessible document roots.
- Block or rate-limit probes to high-value administrative paths. Paths such as
/manager/,/phpmyadmin/, and/cgi-bin/should either be blocked at the perimeter for non-administrative source ranges or served a non-responsive stub to reduce attacker signal.
- Investigate Oracle Cloud ingress. If your environment is receiving large volumes of scan traffic originating from Oracle Cloud (AS136907 / AS31898 NL ranges), evaluate whether geo-based or ASN-based rate limiting is appropriate for your threat model. Consider reporting abusive scanning to Oracle's abuse contact.
- Monitor the
UNSTABLEprobe signature. This anomalous string should be logged and cross-correlated with any application-layer errors in production systems. It may indicate a fuzzing framework probing for unstable parser behavior.
- Watch Pakistan-origin traffic trends. At 1,082 events this week, PK-origin probes are worth tracking over the next 2–3 weeks to determine if this represents a new campaign origin or isolated activity.
- Ensure database services are not internet-exposed. PostgreSQL, Redis, MySQL, and MongoDB facades all received unsolicited traffic. No database service should be bound to a public interface without a documented operational requirement and enforced authentication.