Honeypot Network Harvests 1.5 Million SSH Login Attempts in 30 Days
Harvesting SSH Credentials: Insights from My Honeypot Network

A security researcher shares data from a 30-day honeypot network of 15 servers worldwide, revealing 6,790 unique attacker IPs and 1.5 million login attempts. The top credentials are predictable (root/123456), and attackers are concentrated in Asia and Europe. The post details the technical setup (Ansible, Podman, Python/Paramiko) and plans for expansion.
Most honeypots are currently in Europe (60%) - I plan to add more.