As cited
Copy frozen at (site build).
threat intel
Scans for Proxmox Servers
Proxmox servers are experiencing increased scanning and brute force attack attempts targeting port 8006, following publication of a vulnerability advisory affecting unsupported version 7. Attackers are probing the authentication endpoint at /api2/json/access/ticket with credential stuffing and fingerprinting techniques, leaving detectable 401 and 308 status codes in proxy logs.
Why it matters: Organizations running Proxmox VE should monitor proxy logs for repeated failed authentication attempts to the access ticket endpoint and implement rate limiting or IP-based protections, as active reconnaissance suggests opportunistic exploitation attempts.
- Source published
- First seen by Cybersecurity Tracker