Yesterday we reported out an additional dataset found on the #Fortibleed threat actors systems in a one-off special report - https://www.shadowserver.org/what-we-do/network-reporting/fortibleed-additional-dataset-special-report/ The data was shared with us by SpyCloud (https://spycloud.com/) & covers 35000 new IPs not previously reported. The report also contains over 1000 IPs where the threat actor ran credential sniffing in June. Check out SpyCloud's analysis here: https://spycloud.com/blog/what-spycloud-found-inside-the-fortibleed-threat-actor-infrastructure/ Thank you to SpyCloud for the collaboration! Global Stats: Dashboard World Map view: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=other_value&day=2026-06-26&map_type=std&source=special&data_set=count&scale=log&auto_update=on Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=other_value&day=2026-06-26&source=special&data_set=count&scale=log&auto_update=on #CyberCivilDefense