Three million internet-facing FTP servers are running without encryption right now. Not in 1998. Right now, in 2026. If any of them live in your environment — or touch your supply chain — credential theft isn’t a risk, it’s a scheduled event. This is exactly the kind of legacy exposure where ipban stops being a “nice to have” and starts being the thing keeping your auth logs from becoming someone else’s password dump.

And FTP isn’t alone this week. Vercel got popped through a compromised AI side tool. ZionSiphon is crawling Israeli water OT subnets. Discontinued TP-Link routers are still catching exploit attempts a year after anyone bothered to patch them. The through-line is uncomfortable: the attack surface you forgot about is the one actively being probed.

File transfer server exploitation
Legacy file transfer protocols remain a prime target for credential harvesting.

The Legacy Protocol Problem Isn’t Going Away

Half of six million FTP servers exposed to the public internet don’t support encryption. That’s the ShadowServer data, and it should make you physically wince. Plaintext auth. Plaintext data. Anyone on the path gets credentials for free, and from there it’s lateral movement into whatever that FTP box can reach.

Here’s the part sysadmins don’t want to hear: you probably have one. Maybe it’s a vendor integration nobody’s touched since 2019. Maybe it’s a build artifact drop. Maybe it’s the thing finance uses to exchange files with that one ancient partner. It doesn’t matter why it exists — it matters that brute-force scanners found it before you remembered it.

The TP-Link story is the same disease in a different costume. Attackers have been hammering a flaw in discontinued routers for a full year. No successful payload execution yet, per the researchers, but the attempts never stop. That’s the thing about automated scanning — it doesn’t get bored and it doesn’t forgive exposed services.

Why Edge IP Controls Still Win This Fight

When the protocol itself is broken and the vendor is gone, you’re not patching your way out. You’re gating access. That’s the whole job of a firewall-level IP banning layer: drop the noise before it ever reaches an authentication prompt that you already know is weak.

The Vercel breach drives this home from a different angle. Attackers compromised Context.ai — a third-party AI tool an employee was using — then pivoted into that employee’s Google Workspace and onward into Vercel’s internal systems. Limited customer credentials leaked. ShinyHunters reportedly wants $2M for the stolen data. No FTP involved. But the pattern is identical: a trusted-looking source becomes the pivot, and every downstream system that didn’t rate-limit, geofence, or auto-ban suspicious authentication traffic got a harder incident to scope.

What actual edge-level enforcement buys you when the upstream is compromised:

  • Brute force protection on any exposed auth endpoint — FTP, SSH, RDP, SMB — before the weak protocol becomes the problem
  • Automatic banning of repeat-offender IPs so your logs stop drowning in noise
  • Geofencing on services that have no business being reachable from half the planet
  • Threat intel feeds that preemptively block known bad infrastructure

None of that fixes FTP’s plaintext problem. It just means the attacker needs to get auth credentials some other way — from a phishing kit, a stealer log, a compromised vendor — rather than spraying your exposed service until one username hits.

What to do Monday morning

Stop treating “we’ll migrate off FTP eventually” as a security posture. Three actions, in order:

First, inventory every exposed service on ports 21, 22, 23, 3389, 445, and the usual suspects. Not what should be exposed — what actually is. External scan, not internal asset list. They don’t match; they never match.

Second, put every one of those services behind an IP banning layer with aggressive thresholds. Three failed auths in sixty seconds should buy an hour’s ban minimum. IPBan Pro handles this across Windows and Linux with shared threat intelligence, so a bad actor hitting your FTP in Frankfurt gets blocked on your SSH in Singapore before they even try.

Third, kill the services you can’t justify. If the vendor integration can move to SFTP or HTTPS, migrate it this quarter. If it can’t, put it on a VPN or an allowlist. The half of FTP that still speaks plaintext exists because someone kept deferring the decision.

OT, AI Tools, and the Expanding Blast Radius

ZionSiphon is the one that should keep OT operators up at night. Darktrace flagged it targeting Israeli water and desalination systems — persistence, config tampering, local subnet scanning for OT-relevant services. That last part is the tell. The malware isn’t aiming at the internet-facing edge. It’s landing somewhere inside and then walking the subnet looking for things that shouldn’t have been reachable in the first place.

If your ICS network depends on “nobody knows it’s there” as a control, ZionSiphon is the proof of concept for why that ends badly. Internal IP banning, east-west segmentation, and aggressive authentication rate limits on every management interface aren’t paranoid. They’re the minimum viable response to malware specifically designed to hunt inside your perimeter.

The Vercel-via-Context.ai chain closes the loop. Employees are adopting AI tools faster than your security team can review them. Each one is a new pivot point, a new set of credentials, a new SaaS trust relationship. You’re not going to ban AI adoption. What you can do is make sure that when one of these tools gets popped — and they will — the blast radius stops at whatever edge controls you put in place.

Legacy protocols, abandoned hardware, third-party AI, OT quiet zones. Different stories, same lesson: the boring, old-fashioned practice of gating access by IP and aggressively banning bad actors is doing more load-bearing work in 2026 than anyone predicted.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.