The Early Actors page is live! While I expect this list to grow a lot over time, you can check it out now: https://honeylabs.net/pre-disclosure
This feature detects systems targeting specific, narrow CVE exploit paths days or weeks before any public NVD disclosure or exploit tooling even exists.
I'll write a blog post about it once there is more data to analyze.
Remote
HoneyLabs
@HoneyLabs@infosec.exchange
HoneyLabs is a Dutch threat intel platform built on our own open-source honeypots, Spip and Loom. We capture our own telemetry across all TCP ports. 51M+ records and going!
89 Followers
124 Following
6 Posts
Joined July 13, 2026
HoneyLabs:
LinkedIn :/:
Open post
Some IPs probe a CVE's exact exploit path weeks before it's public, and if you're recording, you can see it.
On April 11 one of our honeypots logged 16 requests for the cPanel WHM login path on port 2087 from 85[.]122[.]114[.]177, an address that has never touched us otherwise, before or since. 17 days later cPanel disclosed CVE-2026-41940, a 9.8 auth bypass in exactly that flow.
Method, formulas, and the live table:
https://honeylabs.net/blog/probe-17-days-before-the-cve
#ThreatIntel #ThreatHunting #Honeypots #CVE #InfoSec #DFIR
0
0
0
0
Open post
Added new tools!
cve_lookup, top_attackers by=cve, and a better ioc_lookup.
https://honeylabs.net/mcp
0
0
0
0
Open post
AI crawler impersonation is getting more prevalent these days. Here's a campaign of 26 hosts, scanning with 42,321 different Anthropic user-agents
https://honeylabs.net/blog/spoofed-ai-crawlers-one-client
0
0
0
0
Open post
Replying to
@hrbrmstr@mastodon.social Specialised local LLMs for honeypots seems like a really cool angle. Will be keeping an eye on them!
0
2
0
0
Open post
Replying to
@hrbrmstr@mastodon.social Ah, I thought the site referenced using a local LLM. I wonder how they defend against injection attacks. Would be a wild way to priv esc a honeypot.
0
0
0
0
