For the last month or two, I've seen roughly ten times more vulnerability-scanning activity in my logs than usual. The increase started almost simultaneously across several different domains, which makes it seem more coordinated than normal background noise. Has anyone else noticed this, and are there any known events or changes that might explain the sudden spike?
3 Answers
The bursty pattern is common on smaller deployments. Grouping logs by requested path, source address, and user agent can make it easier to see whether the spike comes from one scanner or many different networks. A sudden increase often means an automated tool has changed its target list rather than someone specifically focusing on your domains.
You’re definitely not the only one. Scanning activity often arrives in waves when a new vulnerability is disclosed or when a botnet updates its list of targets. As long as sensitive files and endpoints—such as .env files, .git directories, admin panels, and outdated services—aren’t exposed, much of this is just automated noise. Keep everything patched, rate-limit requests, and block the most common probe paths.
I’ve seen a similar tenfold increase on a VPS recently. It’s mostly an annoyance, although the unusual traffic can trigger outbound-usage alerts. These bursts tend to appear periodically and then fade when the scanners or botnets move on to another target set.

That explanation seems likely. I checked recent vulnerability publication numbers and they appear to have risen sharply—from fewer than 5,000 per month before April to nearly 15,000 in September—so automated scanners may be catching up with newly listed issues.