What Linux servers are actually attacked with
SecAI blocked 17,506 attacks from 7,655 distinct addresses across 10 monitored Linux servers, 1 September to 26 September 2026. Most of it is password guessing against SSH. About 34% of those addresses attacked more than one of the servers.
What they were trying
Every row is a group of blocks that was large enough to publish. Attacks counts blocks; addresses counts the distinct sources behind them. They are very different numbers. One address can be blocked hundreds of times, and conflating the two is the easiest way to make a fleet this size sound larger than it is.
| Category | Attacks blocked | Distinct addresses | Servers |
|---|---|---|---|
| SSH password guessing | 14,888 | 6,205 | 10 |
| Web scanning and probing | 2,194 | 1,359 | 7 |
| Floods and connection exhaustion | 234 | 137 | 7 |
| Correlated compromise pattern | 100 | 56 | 6 |
| Other | 87 | 87 | 7 |
The one thing a single server could not tell you
About 34% of the addresses that attacked one of these servers also attacked at least one other: 2,591 of 7,655. These servers belong to unrelated businesses in unrelated industries; they have nothing in common except being reachable.
That is worth saying plainly: almost none of this is aimed at anybody. It is the internet working through address space. A server is not attacked because of what it hosts or who runs it. It is attacked because it answered.
What this is, and what it is not
- It is a small fleet. 10 servers. Enough to be worth publishing, not enough to describe the internet, and the number is next to every figure for that reason.
- It is blocks, not attempts. An attack SecAI did not block is not counted, so these are floors rather than totals.
- There are no countries or networks here. Only about six per cent of blocked addresses have ever been geolocated, and only because somebody opened that finding. A chart from that sample would describe SecAI’s operators, not the attackers.
- There are no ports or services. They are not recorded on a block, and inferring them from the attack type would be inventing data.
- There is no “time to first attack”. The obvious query says a median of zero hours, and it is wrong: it measures when SecAI started watching, not when the server came online. That claim needs a server watched from its first hour.
- Small groups are withheld. A day or a category seen on fewer than 3 servers, or with fewer than 25 events, is not published, because on a fleet this size a thin group is a customer.
Questions
10 Linux servers monitored by SecAI. That is a small fleet, and every figure on this page is a figure about those servers rather than about the internet. We publish the sample size next to the numbers for that reason.
An address that SecAI blocked on a customer’s server, and that the agent confirmed it had blocked. Password guessing against SSH, scanning and probing of web servers, floods, and WordPress abuse. A block that was only proposed, or that failed, is not counted.
No. It is counts. The attacker’s address is used to count distinct attackers and then discarded; no customer address, hostname, organisation or server identifier is stored in the published tables or returned by the public endpoint, and a group too small to be anonymous is never published at all.
Because SecAI has only looked up the country of about six per cent of the addresses it has blocked, and it looked them up because somebody happened to open that finding. A chart from that sample would show what SecAI’s operators clicked on, not where attacks come from. It needs systematic enrichment first, and until then the honest thing is to leave it out.
Is your server in this already?
Every server here was being attacked before SecAI arrived. The free assessment reads how yours is set up and tells you what an attacker would find, in about a minute, without changing anything.
Rebuilt hourly. Last computed 26/09/2026, 05:42:15 UTC.