VNC attacks & scanning (port 5900)
VNC/RFB remote desktop — unauthenticated access and auth-challenge capture.
Observed by OffSeq honeypot sensors · last 7 days · #1 most-attacked service · last seen just now
1,156,241
Attacks
831
Distinct source IPs
5900
Port · tcp
The #1 most-attacked service across the fleet in the last 7 days.
OffSeq honeypots emulating VNC recorded 1,156,241 attacks from 831 distinct source IPs over the last 7 days. VNC/RFB remote desktop — unauthenticated access and auth-challenge capture.
Top CVEs exploited across the fleet (last 7 days)
Fleet-wide, not scoped to VNC.
- CVE-2019-0708501
- CVE-2024-4577479
- CVE-2021-26855479
- CVE-2017-9841401
- CVE-2017-0144252
- CVE-2025-324890