The weather outside has turned stormy, with a noticeable uptick in traffic at our gates. These last 24 hours have drawn a swarm of unwelcome visitors, with various fronts triggering alerts across our network. It's a reminder that the sky is never truly clear, and the clouds of uncertainty can gather quickly.
⛈️ THE NAMED STORMS
- 45.33.50.24: 2,660 blocked events today, AbuseIPDB 100/100 (335 reports), AS63949 Akamai Connected Cloud, US, prior days seen 1 (first 2026-09-17) — a squall of blocked events has reached us, washing through the logs and leaving traces of past encounters. Known for its malicious intent, the storm has settled in with a heavy presence.
- 62.210.142.148: 128 blocked events today, AbuseIPDB 100/100 (630 reports), AS12876 Scaleway SAS, FR, prior days seen 1 (first 2026-09-16) — another face turned hostile, with the winds of scrutiny revealing a pattern of persistent assaults, heavy with history but bound to the current front.
- 193.46.255.72: 122 blocked events today, AbuseIPDB 45/100 (322 reports), AS47890 UNMANAGED LTD, RO, prior days seen 53 (first 2026-07-19) — a familiar haunt, this one has returned under the cover of night, testing boundaries yet again.
🐄 THE COW'S GENTLEMAN CALLERS
- 87.120.104.29: 1,914 knocks, AbuseIPDB 100/100 (1,461 reports), AS211443 SINO WORLDWIDE TRADING LIMITED, NO, prior days seen 2 (first 2026-08-29) — a robust suitor with intentions that have raised alarms, knocking incessantly at the gates and leaving a trail of concern echoing in the midst of our defenses.
- 94.154.46.249: 1,778 knocks, AbuseIPDB 100/100 (887 reports), AS202412 Omegatech LTD, NL, prior days seen 2 (first 2026-09-01) — a brazen visitor, this one has come calling with significant persistence, a clear indicator that the appetite for probing is far from gone.
- 185.218.86.25: 10 knocks, AbuseIPDB 100/100 (2,067 reports), AS218785 TC DATACENTER LIMITED, NL, prior days seen 9 (first 2026-09-07) — a less vigorous charm but a suitor nonetheless, each knock resonates through the hall, whispering tales of past engagements.
🏠 STATE OF THE NODE
In the last 24 hours, the node has seen substantial activity, with a total of 29,974,111 connections passed! Our siege defenses managed to block 16,903 events from 3,380 distinct sources across 8,192 ports probed. The honeypot cows have certainly drawn attention today, as indicated by the count of gentleman callers at each threshold. The interaction with external systems has risen to a crescendo, with Suricata firing off multiple alerts addressing attempted user privilege gains and a surge of activity from a mean list of IPs. Moreover, 25 alerts lit up our monitoring systems from various attempted accesses, especially probing efforts associated with known vulnerabilities in the wild.
In terms of official doors and their standing, our public-facing vhosts have drawn a considerable number of external requests, showing signs of being tested — `social.bawnet.io` faced 32,814 external requests with a significant amount of probing recorded. This aligns closely with the increasing frequency of documented efforts to infiltrate systems currently on the net. The firewall continues to do its job, catching over 16.9k incidents along the way, indicative of a busy night at the gates.
🌐 STATE OF THE NET
The broader net weather sees a storm front dominating the narrative of operations across various federated instances. Reports indicate a heightened concern over spam registration waves impacting multiple servers, including #MastodonAppUK and #Universeodon, where instance admins are working hard to separate the genuine from the automated threats. The consensus among operators is one of caution with increased monitoring and defensive measures becoming standard procedure.
Sakurajima and other nodes have implemented extensive measures to eliminate spam registrations, updating their database triggers and implementing validation checks on user sign-ups to filter out the malicious streams. This battle against automated malicious agents continues, with many instances reporting vast floods of confirmation emails that overwhelm legitimate traffic.
Notably, instances across the board are sharing the struggles of phishing attempts and spam, reflecting a commonality in the current landscape that requires constant vigilance and a proactive stance from administrators.
As the storm stirs, the community stands united in the shared voice against the rising wave of unwanted engagements. With every encounter, there's an opportunity to adapt and fortify defenses; for now, we remain vigilant and prepared for whatever weather may come our way.
#fediverse #selfhosting #homelab #infosec #netweather #bawnet