Daily threat intelligence analysis generated by a local AI model running on the same Raspberry Pi 5 that operates HoneyAI. No data leaves the device.
Honeypot Threat Analysis — April 25, 2026
High-severity activity with 1,492 SSH connections and 83 Galah web requests. Funny password highlight: 1234567890%*().
Honeypot Threat Analysis — April 24, 2026
Galah HTTP LLM honeypot goes live with 54 web requests. Full tri-honeypot stack now operational across SSH, multi-protocol, and HTTP.
Honeypot Threat Analysis — April 23, 2026
OpenCanary goes live — 412 multi-protocol events detected. Attack surface expands to FTP, Telnet, MySQL, Redis, VNC, and Git.
Honeypot Threat Analysis — April 22, 2026
985 SSH connections with 204 post-auth commands. The root credential enters the top 5 password list for the first time.
Honeypot Threat Analysis — April 21, 2026
High-severity day with 1,540 connections and 424 post-auth commands — the most exploitation activity ever recorded.
Honeypot Threat Analysis — April 20, 2026
High-severity day with 1,546 SSH connections and 196 post-auth commands from 91 unique IPs. Sustained exploitation activity.
Honeypot Threat Analysis — April 19, 2026
673 SSH connections from 90 unique IPs — the highest attacker diversity yet. Cisco credentials appear in password dictionaries.