Over the past month or two, I've noticed roughly ten times more vulnerability-scanning activity in my server logs than usual. The increase started fairly suddenly and is happening across several different domain names. Has anyone else seen the same pattern, and what might be causing these bursts of scanning?
4 Answers
The sudden timing doesn’t necessarily indicate a problem with your domains. Automated scanners and compromised machines frequently switch target lists at once, which creates noticeable spikes across unrelated sites. Continue monitoring the logs, make sure unnecessary services aren’t exposed, and investigate any successful-looking requests rather than just the scan volume.
I’ve seen a similar tenfold increase on a VPS recently. It was mostly harmless but occasionally triggered unusual outbound-traffic alerts. These campaigns tend to appear in bursts and then fade, so tracking requests by path, source, and user agent can help distinguish a temporary wave from a persistent problem.
Some of the traffic may come from legitimate security scanners, but bots can also imitate them or use similar user-agent strings. I’d treat every request as untrusted, verify what is actually being accessed, and harden the exposed services rather than relying on the claimed identity of the scanner.
You’re definitely not alone. Scanning activity often comes in waves after a new vulnerability is disclosed or when a botnet updates its list of targets. As long as sensitive files and endpoints such as .env files, Git directories, and admin panels aren’t exposed, much of this is just background internet noise. Keep everything patched, rate-limit requests, and block the most common probe paths where practical.

That explanation fits what I’m seeing. The number of newly published vulnerabilities appears to have risen sharply, so automated scanners may simply be catching up with more targets.