
TXOne Honeypot Report: 2026 H1 Threat Landscape
TXOne Threat Intelligence System honeypot data for January–June 2026 shows attackers leaning hard on old exposure rather than novel exploits. Three independent telemetry streams — CVE-tagged IPS hits, unique payload diversity, and ICS/OT protocol scanning — all spiked in March, though raw session volume peaked in May. Over 91% of malware downloads arrived over SMB (445/TCP), and 97% of sessions from the top 99 attacker IPs traced to cloud and VPS hosting rather than residential networks. Only 15% of the 589 observed CVEs were disclosed in 2025–2026; the rest were known or misconfigured issues, including a 27-year-old default-SNMP finding. Credential attempts also showed a new Solana validator–focused cluster alongside standard IoT stuffing.
Aug 24, 2026


