Threat Observatory

What Linux servers are actually attacked with

SecAI blocked 17,506 attacks from 7,655 distinct addresses across 10 monitored Linux servers, 1 September to 26 September 2026. Most of it is password guessing against SSH. About 34% of those addresses attacked more than one of the servers.

7,655
distinct attacking addresses
17,506
attacks blocked
10
servers observed
34%
of addresses hit more than one server

What they were trying

Every row is a group of blocks that was large enough to publish. Attacks counts blocks; addresses counts the distinct sources behind them. They are very different numbers. One address can be blocked hundreds of times, and conflating the two is the easiest way to make a fleet this size sound larger than it is.

CategoryAttacks blockedDistinct addressesServers
SSH password guessing14,8886,20510
Web scanning and probing2,1941,3597
Floods and connection exhaustion2341377
Correlated compromise pattern100566
Other87877

The one thing a single server could not tell you

About 34% of the addresses that attacked one of these servers also attacked at least one other: 2,591 of 7,655. These servers belong to unrelated businesses in unrelated industries; they have nothing in common except being reachable.

That is worth saying plainly: almost none of this is aimed at anybody. It is the internet working through address space. A server is not attacked because of what it hosts or who runs it. It is attacked because it answered.

What this is, and what it is not

  • It is a small fleet. 10 servers. Enough to be worth publishing, not enough to describe the internet, and the number is next to every figure for that reason.
  • It is blocks, not attempts. An attack SecAI did not block is not counted, so these are floors rather than totals.
  • There are no countries or networks here. Only about six per cent of blocked addresses have ever been geolocated, and only because somebody opened that finding. A chart from that sample would describe SecAI’s operators, not the attackers.
  • There are no ports or services. They are not recorded on a block, and inferring them from the attack type would be inventing data.
  • There is no “time to first attack”. The obvious query says a median of zero hours, and it is wrong: it measures when SecAI started watching, not when the server came online. That claim needs a server watched from its first hour.
  • Small groups are withheld. A day or a category seen on fewer than 3 servers, or with fewer than 25 events, is not published, because on a fleet this size a thin group is a customer.

How this data is collected and what is left out

Questions

How many servers is this based on?

10 Linux servers monitored by SecAI. That is a small fleet, and every figure on this page is a figure about those servers rather than about the internet. We publish the sample size next to the numbers for that reason.

What counts as an attack here?

An address that SecAI blocked on a customer’s server, and that the agent confirmed it had blocked. Password guessing against SSH, scanning and probing of web servers, floods, and WordPress abuse. A block that was only proposed, or that failed, is not counted.

Does this page contain customer data?

No. It is counts. The attacker’s address is used to count distinct attackers and then discarded; no customer address, hostname, organisation or server identifier is stored in the published tables or returned by the public endpoint, and a group too small to be anonymous is never published at all.

Why are there no attacking countries on this page?

Because SecAI has only looked up the country of about six per cent of the addresses it has blocked, and it looked them up because somebody happened to open that finding. A chart from that sample would show what SecAI’s operators clicked on, not where attacks come from. It needs systematic enrichment first, and until then the honest thing is to leave it out.

Is your server in this already?

Every server here was being attacked before SecAI arrived. The free assessment reads how yours is set up and tells you what an attacker would find, in about a minute, without changing anything.

Rebuilt hourly. Last computed 26/09/2026, 05:42:15 UTC.