Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

The Shadowserver Foundation

@shadowserver@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Our mission is to make the Internet more secure by bringing to light vulnerabilities, malicious activity and emerging threats. Join our Alliance!

2734 Followers
0 Following
42 Posts
Joined November 17, 2022
Web:
https://shadowserver.org
Dashboard:
https://dashboard.shadowserver.org
Reports:
https://www.shadowserver.org/what-we-do/network-reporting/get-reports/
Github:
https://github.com/The-Shadowserver-Foundation
Alliance:
https://www.shadowserver.org/partner/
Training (Shadowserver-in-a-box):
https://github.com/The-Shadowserver-Foundation/training
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 3mo ago

We shared a one-off "FortiBleed" dataset of compromised Fortinet devices in our Compromised Website Report https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/ thanks to collaboration with SOCRadar!

Stats:
Dashboard World map view:
https://dashboard.shadowserver.org/statistics/combined/map/?date_range=other_value&day=2026-06-18&map_type=std&source=compromised_website&source=compromised_website6&tag=fortibleed%2B&data_set=count&scale=log&auto_update=on

Dashboard Tree map view:
https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=other_value&day=2026-06-18&source=compromised_website&source=compromised_website6&tag=fortibleed%2B&data_set=count&scale=log&auto_update=on

IP data tagged 'fortibleed' in https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/ with timestamp set to 2026-06-18

SOCRadar FortiBleed checker: https://socradar.io/free-tools/fortibleed

Background: https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/

12
0
7
1
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 2mo ago
Yesterday we reported out an additional dataset found on the #Fortibleed threat actors systems in a one-off special report - https://www.shadowserver.org/what-we-do/network-reporting/fortibleed-additional-dataset-special-report/ The data was shared with us by SpyCloud (https://spycloud.com/) & covers 35000 new IPs not previously reported. The report also contains over 1000 IPs where the threat actor ran credential sniffing in June. Check out SpyCloud's analysis here: https://spycloud.com/blog/what-spycloud-found-inside-the-fortibleed-threat-actor-infrastructure/ Thank you to SpyCloud for the collaboration! Global Stats: Dashboard World Map view: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=other_value&day=2026-06-26&map_type=std&source=special&data_set=count&scale=log&auto_update=on Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=other_value&day=2026-06-26&source=special&data_set=count&scale=log&auto_update=on #CyberCivilDefense
8
0
7
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 2mo ago
We’re excited to welcome Backblaze to the Shadowserver Alliance as a Bronze Tier Partner! Backblaze is a premier, high-performance cloud storage platform. https://www.backblaze.com With our Alliance Partners, we’ll make the Internet more secure and raise the bar on cybersecurity. Join the Alliance and become part of the community: https://www.shadowserver.org/partner/
4
0
3
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 3mo ago

New one-off SocGholish Compromised WordPress Sites Special Report run today, in continued support of international LE partners in Operation Endgame #cybercrime disruption:

https://shadowserver.org/news/socgholish-compromised-wordpress-sites-special-report/

Great work once again everyone involved!

1,441,695 credentials covering period 2023-05-17 to 2026-05-25, from 1,134,542 domains hosted on 271,176 unique IP addresses, across 7,550 different ASNs in 187 countries/territories globally.

Report technical details available here (dated 2026-06-18):

https://shadowserver.org/what-we-do/network-reporting/critical-socgholish-compromised-wordpress-sites-special-report

WordPress site users/admins (plus their friends and colleagues):

Please read the defensive guidance provided, check your sites and remediate any signs of compromise immediately.

7
1
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 4mo ago

Attention!

cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026

See Public Dashboard for stats: https://dashboard.shadowserver.org/statistics/honeypot/device/tree/?date_range=1&vendor=cpanel&data_set=count&scale=log&auto_update=on

44K unique IP number is based on cPanel spike of devices seen scanning/running exploits/brute force attacks against our honeypot sensors.

https://dashboard.shadowserver.org/statistics/honeypot/device/time-series/?date_range=7&vendor=cpanel&dataset=unique_ips&limit=100&group_by=vendor&stacking=stacked&auto_update=on

You can find likely newly compromised instances in our honeypot based reports with cPanel set in the device_vendor of the attacking device

- Darknet Events Report https://www.shadowserver.org/what-we-do/network-reporting/honeypot-darknet-events-report/
- Honeypot HTTP Scanner Events Report
https://www.shadowserver.org/what-we-do/network-reporting/honeypot-http-scanner-events/

- Honeypot Brute Force Events Report
https://www.shadowserver.org/what-we-do/network-reporting/honeypot-brute-force-events-report/

You can also find exposed cPanel/WHM instances in our Device ID reporting with ~650K IPs seen hosting https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&vendor=cpanel&dataset=count&limit=1000&group_by=geo&stacking=stacked&auto_update=on

12
0
7
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 2mo ago
We shared out ~2000 unique IPs exposing secrets that are known to have been harvested by a threat actor. IP data in our Compromised Website report: https://shadowserver.org/what-we-do/network-reporting/compromised-website-report/ for your network/constituency with the 'stolen-key' tag (dated 2026-07-02). Check your reports! Thank you to our anonymous partner for the contribution!
4
0
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 3mo ago

Heads up! New report going out daily: the Initial Access Broker Report https://shadowserver.org/what-we-do/network-reporting/initial-access-broker-report/ on compromised hosts likely under control of IABs

Data thanks to collaboration with anonymous researchers & SpyCloud
- thank you!

Check your free daily reports from us!

6
0
2
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 4mo ago

We published a "Shadowserver-in-a-box" platform based on IntelMQ + ELK that can ingest, process and visualize our threat/vulnerability/victim data feeds. Available as a VM or Docker image for free download. Use it for training or in production!

https://github.com/The-Shadowserver-Foundation/training

For usage, you need to request a test API key (or you can use your production API key if you have one already). Please send requests via https://www.shadowserver.org/contact/

Test API key provides access to test/dummy data.

“Shadowserver-in-a-box” development was supported by the cyber capacity building project under the ECOWAS-G7 partnership for cybersecurity, the “Joint Platform for Advancing Cyber Security” (JPAC) in West Africa.

The project was launched by the ECOWAS Commission in collaboration with Germany’s G7 presidency in 2022, commissioned by the German Federal Foreign Office & the European Union Commission in 2023 & implemented by Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH.

#CyberCivilDefense

9
0
2
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 2mo ago
SimpleHelp CVE-2026-48558 is now confirmed exploited-in-the-wild and on US CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48558 We are scanning for SimpleHelp CVE-2026-48558 vulnerable instances since 2026-06-16. We see 439 unpatched in our 2026-07-01 scan. Most (268) found in the US. Raw IP data in https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ for your network/constitiuency Dashboard World Map view: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-48558%2B&data_set=count&scale=log&auto_update=on We also recently collaborated with Validin for additional domain based detections, thank you! Patch info: https://simple-help.com/security/simplehelp-security-update-2026-05
3
0
2
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 5mo ago

We’re excited to announce that the Canadian Centre for Cyber Security (CCCS) has increased its annual Shadowserver Alliance Partnership tier from Gold to Diamond! Thank you CCCS for your generous support and for being a valuable and trusted partner in making the Internet more secure.

Become an Alliance Partner today: https://www.shadowserver.org/partner/

9
0
4
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 3mo ago

Shadowserver is excited to share its cybersecurity insights and actionable recommendations in a report aimed at helping ECOWAS stakeholders make West Africa more secure!

Read the report & accompanying fact sheets in English, French & Portuguese at https://www.shadowserver.org/news/shadowserver-report-provides-cybersecurity-insights-and-recommendations-for-ecowas-member-states-in-west-africa/

Direct links (full report) -

English: https://www.shadowserver.org/wp-content/uploads/2026/06/SSF001-ECOWAS-Report-ENG-FINAL.pdf

French: https://www.shadowserver.org/wp-content/uploads/2026/06/SSF001-ECOWAS-Report-FRE-FINAL.pdf

Portuguese: https://www.shadowserver.org/wp-content/uploads/2026/06/SSF001-ECOWAS-Report-PT-FINAL.pdf

Direct links (fact sheet) -

English: https://www.shadowserver.org/wp-content/uploads/2026/06/SSF001-ECOWAS-Fact-Sheet-ENG-FINAL.pdf

French: https://www.shadowserver.org/wp-content/uploads/2026/06/SSF001-ECOWAS-Fact-Sheet-FRE-FINAL.pdf

Portuguese: https://www.shadowserver.org/wp-content/uploads/2026/06/SSF001-ECOWAS-Fact-Sheet-PT-FINAL.pdf

4
0
0
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 2mo ago

We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with Validin. Around 950 exposed instances now seen globally (no vulnerability assessment). CVE-2026-46817 attempts have been observed in the wild by DefusedCyber

IP data for your network/constituency shared in our Device ID reporting (device_vendor Oracle device_model Oracle E-Business Suite)

World Map view of exposed Oracle EBS instances (no vulnerability assessment): https://dashboard.shadowserver.org/statistics/iot-devices/map/?date_range=1&vendor=oracle&model=oracle+e-business+suite&data_set=count&scale=log&auto_update=on

CVE-2026-46817 NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-46817

Patch info from Oracle: https://www.oracle.com/security-alerts/cspumay2026.html

2
0
0
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 3mo ago

We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today. We see 19 vulnerable instances in our own scans, with at least 2 backdoored (thanks to Saudi for the tip!). However, all remaining likely compromised too.

While our detection is on the lowish side due to multiple Ivanti Sentry instances not reachable in our scans (blocklisted?), if you have not patched now you are most likely compromised.

Vulnerable IP data shared in our Vulnerable HTTP reporting tagged 'cve-2026-10520' https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

Compromised IP data shared in our Compromised Website reporting tagged as 'ivanti-sentry,injected-code,backdoor'. See: https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/

Advisory/patch: https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US

3
0
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 1mo ago

Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to US CISAKnown Exploited Vulnerability catalog last few weeks.

This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23

Data for these is shared in our Vulnerable HTTP reporting with the appropriate CVE tags:
https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

Dashboard World Map:
https://dashboard.shadowserver.org/statistics/combined/map/?date_range=other_value&day=2026-07-23&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-50522%2B&tag=cve-2026-56164%2B&tag=cve-2026-58644%2B&data_set=count&scale=log&auto_update=on

Dashboard Tree Map:
https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=other_value&day=2026-07-23&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-50522%2B&tag=cve-2026-56164%2B&tag=cve-2026-58644%2B&data_set=count&scale=log&auto_update=on

Tracker:
https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-50522%2B&tag=cve-2026-56164%2B&tag=cve-2026-58644%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

MS Advisories:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164

1
0
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 2mo ago

More Operation Endgame #cybercrime disruption success this week, with a new one-off StealC Historical Bot Special Report run overnight (2026-06-24), continuing our support for international LE partners:

https://shadowserver.org/news/stealc-historical-bot-infection-special-report/

29,475,727 events with 9,886,903 logins & 9,624,328 password hashes from 5,787,992 URLs, stolen from 384,781 Windows hardware device IDs with 364,057 unique IP addresses, spread across 16,477 different Autonomous System Numbers (ASNs) in 231 countries or territories globally.

StealC Historical Bot Special Report technical details and sample data available here (dated 2026-06-24):

https://shadowserver.org/what-we-do/network-reporting/critical-stealc-historical-bot-infections-special-report/

As with SocGholish Compromised WordPress Sites Special Report run last week (2026-06-18), if you receive a StealC alert from us or your service provider/national CSIRT, please follow remediation advice and change passwords immediately!

2
0
0
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 2mo ago

Last week we added scanning for Joomla JCE editor extension CVE-2026-48907 vulnerable instances. This RCE vulnerability is exploited in the wild & on US CISA KEV. 4840 vulnerable instances seen 2026-06-22 down from 5146 on 2026-06-19. Top affected: US

https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-48907%2B&data_set=count&scale=log&auto_update=on

Raw IP data shared in our Vulnerable HTTP reporting https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ tagged 'cve-2026-48907' filtered by network/constituency

Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-48907%2B&data_set=count&scale=log&auto_update=on

Patch info: https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites

2
0
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 4mo ago

We are scanning & reporting daily Wazuh CVE-2026-30893 (CVSS 9.9) vulnerable instances, with over 3500 IPs seen unpatched on 2026-05-10. See advisory & update to latest version: https://github.com/wazuh/wazuh/security/advisories/GHSA-m8rw-v4f6-8787 ...

Worth keeping your security platforms up to date!

IP data for your network/constituency shared in Vulnerable HTTP reporting, tagged 'cve-2026-30893: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

Public Dashboard tree map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-30893%2B&data_set=count&scale=log&auto_update=on

NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-30893

#CyberCivilDefense #cybersecurity

4
0
4
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 4mo ago

We are tagging CVE-2026-6973 Ivanti EPMM instances seen in our daily scans. 362 IPs seen unpatched on 2026-05-10, down from 562 IPs on 2026-05-08 when we first added the detection. See Ivanti advisory for details - https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US

CVE-2026-6973 is on US CISA KEV.

Raw IP data in our Vulnerable HTTP reporting https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ tagged 'cve-2026-6973'

Public Dashboard tree map overview of vulnerable instances:
https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-6973%2B&data_set=count&scale=log&auto_update=on

CVE-2026-6973 patch tracker:
https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-6973%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

4
0
2
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 6mo ago
Replying to @shadowserver@infosec.exchange
IIS EOL tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=eol-iis%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on Image
7
0
2
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 5mo ago

We’re excited to welcome KPN to the Shadowserver Alliance as a bronze tier partner!

KPN is a leading telecommunications and IT provider in the Netherlands. https://www.kpn.com/algemeen/english

Together we will raise the bar on cybersecurity to make the Internet more secure.

Become a Shadowserver Alliance partner today:
https://www.shadowserver.org/partner

6
0
0
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 6mo ago

Great to support our international LE and private sector partners in Tycoon 2FA phishing-as-a-service #cybercrime disruption:

shadowserver.org/news/tycoon-...

New nCSIRT-only Tycoon 2FA Domains Special Report run 2026-03-04 (historical C2/panel/infra domains)

https://www.shadowserver.org/what-we-do/network-reporting/info-tycoon-2fa-domains-special-report/

Operation successfully coordinated by Europol, via EC3 Cyber Intelligence Extension Programme (CIEP). Civil legal action by Microsoft DCU

Millions of phishing emails, 96K victims globally

Key domains seized/sinkholed/suspended, thousands of criminal users potentially impacted

7
0
0
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 3mo ago

Happy to once again support LE partners in disruption of the AudiA6 service, allegedly responsible for $389 million USD in cryptocurrency money laundering:

https://justice.gov/usao-edpa/pr/two-charged-connection-cryptocurrency-money-laundering-service-allegedly-laundered

https://secretservice.gov/newsroom/releases/2026/06/two-charged-connection-cryptocurrency-money-laundering-service-allegedly

https://europol.europa.eu/media-press/newsroom/news/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering-pipeline

2
0
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 5mo ago

F5 BIG-IP APM CVE-2025-53521 impact has recently been updated from a DoS to RCE (see: https://my.f5.com/manage/s/article/K000156741) & added to US CISA KEV (https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-53521)

We are fingerprinting & sharing F5 BIG-IP APM instances - over 17.1K IPs seen on 2026-03-31 globally. This is just a population assessment.

IP data is shared in our Device ID reporting https://www.shadowserver.org/what-we-do/network-reporting/device-identification-report/ with device_vendor set to 'F5', device_model set to 'BIG-IP APM'

Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/iot-devices/tree/?date_range=1&vendor=f5&model=big-ip+apm&data_set=count&scale=log&auto_update=on

Dashboard World Map view:
https://dashboard.shadowserver.org/statistics/iot-devices/map/?date_range=1&vendor=f5&model=big-ip+apm&data_set=count&scale=log&auto_update=on

Top affected: US, Japan

If you have APM running on your services/network make sure you are patched & review for any compromise

NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2025-53521

5
1
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 3mo ago

We added scanning of Automatic Tank Gauge (ATG) systems to our Accessible ICS reporting with 1061 IPs seen on 2026-06-05 (on port 10001/tcp).

This is after weeding out vast majority which appear to be honeypots (including ports 8001/9001). Vast majority exposed are in the US.

IP data in https://www.shadowserver.org/what-we-do/network-reporting/accessible-ics-report/ (tagged 'atg’)

Dashboard World Map view: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=ics&tag=atg&data_set=count&scale=log&auto_update=on

These should not be publicly exposed - read why at https://www.cisa.gov/resources-tools/resources/cisa-and-partners-urge-hardening-automatic-tank-gauge-systems from US CISA

See also: https://www.bitsight.com/blog/critical-vulnerabilities-discovered-automated-tank-gauge-systems

2
0
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 3mo ago

Very happy to support CrowdStrike and Google in the disruption of the Glassworm botnet, which features 4x C2 channels, and targets developers via open-source supply chains: https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/

Sinkhole data became available via our free daily Sinkhole Event and Sinkhole HTTP Event network reports yesterday (2026-05-27):

https://shadowserver.org/what-we-do/network-reporting/sinkhole-events-report/

https://shadowserver.org/what-we-do/network-reporting/sinkhole-http-events-report/

infection:glassworm and
tag:solana or tag:bittorrent

Daily aggregated country level statistics available via our public Dashboard:

Graph
https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=sinkhole&source=sinkhole6&tag=glassworm&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

Heatmap
https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=sinkhole&source=sinkhole6&tag=glassworm&data_set=count&scale=log&auto_update=on

Worldmap
https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=sinkhole&source=sinkhole6&tag=glassworm&data_set=count&scale=log&auto_update=on

#CyberCivilDefense

2
0
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 5mo ago

We are now scanning daily for CVE-2026-34197 (Apache ActiveMQ Improper Input Validation Vulnerability) which has recently been added to US CISA KEV.

6364 IPs seen vulnerable on 2026-04-19 based on a version check.

Dashboard Tree Map view:
https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=activemq&tag=cve-2026-34197%2B&data_set=count&scale=log&auto_update=on

IP data shared in our Accessible ActiveMQ reporting https://www.shadowserver.org/what-we-do/network-reporting/accessible-activemq-service-report/

For Dashboard viewing, select sources 'activemq' and 'cve-2026-34197'

ActiveMQ Security advisory: https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt

Background with details from Horizon3.ai https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/

CISA KEV entry: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34197

NVD CVE entry: https://nvd.nist.gov/vuln/detail/CVE-2026-34197

3
0
2
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 5mo ago
Replying to @shadowserver@infosec.exchange
We have also added CVE-2026-2699 tagging to our scans, which now detect unpatched Progress ShareFile instances. 120 IPs seen on 2026-04-06: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-2699%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on CVE-2026-2699 Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-2699%2B&data_set=count&scale=log&auto_update=on IP data in Vulnerable HTTP reporting: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/
3
0
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 6mo ago

We added Microsoft SharePoint CVE-2026-20963 (post-auth deserialization RCE) to our scanning & daily feeds. 1109 IPs found running vulnerable instances worldwide (close to 1900 FQDNs) on 2026-03-19, with 510 IPs in the US.

Dashboard World Map: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-20963%2B&data_set=count&scale=log&auto_update=on

Vulnerable IPs (tagged 'cve-2026-20963') shared daily in our Vulnerable HTTP reporting: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

CVE-2026-20963 is known exploited in the wild and on US CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-20963

Check for compromise.

Microsoft Advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963

CVE-2026-20963 Dashboard Tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-20963%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-20963%2B&data_set=count&scale=log&auto_update=on

#CyberCivilDefense

3
0
2
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 4mo ago

We are scanning/reporting daily Zimbra Collaboration Suite instances vulnerable to CVE-2025-48700, that can allow unauthorized access to sensitive information. This vulnerability is exploited in the wild and on US CISA KEV. We see over 10.5K IPs unpatched 2026-04-23.

IP data in Vulnerable HTTP reporting: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

See https://wiki.zimbra.com/wiki/Security_Center for patch info.

Dashboard World Map view: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-48700%2B&data_set=count&scale=log&auto_update=on

Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-48700%2B&data_set=count&scale=log&auto_update=on

CVE-2025-48700 Tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-48700%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

2
0
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 5mo ago

We are also scanning & reporting Microsoft SharePoint CVE-2026-32201 (Improper input validation in SharePoint allows an unauthorized attacker to perform spoofing over a network). This vulnerability is known exploited in the wild & on US CISA KEV. 1370 IPs seen unpatched.

IP data shared in Vulnerable HTTP reporting: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

Dashboard World Map view: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-32201%2B&data_set=count&scale=log&auto_update=on

Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-32201%2B&data_set=count&scale=log&auto_update=on

CVE-2026-32201 tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-32201%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on
(Numbers down from 2026-04-15 when we found 1745 unpatched)

This is a version based scan.

Microsoft Advisory: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-32201

2
0
3
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 5mo ago

Thank you to Precursor Security for becoming a Shadowserver Alliance Silver Tier Partner!

Precursor Security delivers pen testing, 24/7 managed SOC, and more. https://www.precursorsecurity.com

Together with our Alliance Partner community, we’ll make the Internet more secure.

2
0
0
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 7mo ago

Running End-of-Life devices or apps is a major security risk. The US CISA has recently released a Directive on the topic: https://www.cisa.gov/news-events/directives/bod-26-02-mitigating-risk-end-support-edge-devices

It's worth mentioning we share many End-of-Life devices/apps in our daily reporting, tagged 'eol'.

See: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=exchange&source=exchange6&source=http_vulnerable&source=http_vulnerable6&tag=eol%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

Over 57.5K IPs seen tagged with 'eol' in our exposed web service reporting alone! IP data shared for example in
https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

Dashboard World Map view: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=exchange&source=exchange6&source=http_vulnerable&source=http_vulnerable6&tag=eol%2B&data_set=count&scale=log&auto_update=on

Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=exchange&source=exchange6&source=http_vulnerable&source=http_vulnerable6&tag=eol%2B&data_set=count&scale=log&auto_update=on

4
0
0
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 5mo ago
Replying to @shadowserver@infosec.exchange
We added CVE-2026-35616 scans based on the vulnerability detector developed by Bishop Fox https://bishopfox.com/blog/api-authentication-bypass-in-forticlient-ems-7-4-5-7-4-6-cve-2026-35616 Over 60 IPs still assessed as vulnerable: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-35616%2B&data_set=count&scale=log&auto_update=on Data shared daily in our Vulnerable HTTP reporting: https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/
2
0
1
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 6mo ago

We are continuing to expand our n8n RCE vulnerability scanning - most recently adding CVE-2026-27495 (CVSS 9.4) tagging as well. You can track our various n8n scan results here for the most well known critical vulns: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-68613%2B&tag=cve-2025-68668%2B&tag=cve-2026-21858%2B&tag=cve-2026-21877%2B&tag=cve-2026-25053%2B&tag=cve-2026-25056%2B&tag=cve-2026-27495%2B&dataset=unique_ips&limit=100&group_by=tag&stacking=overlap&auto_update=on

Top affected: US, Germany & France.

IP data on vulnerable instances is tagged 'n8n' & with a cve tag (like cve-2026-27495) in our Vulnerable HTTP reporting - https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

Latest n8n critical RCE vulns (all covered with above tag):

https://github.com/n8n-io/n8n/security/advisories/GHSA-wxx7-mcgf-j869
https://github.com/n8n-io/n8n/security/advisories/GHSA-vpcf-gvg4-6qwr
https://github.com/n8n-io/n8n/security/advisories/GHSA-jjpj-p2wh-qf23

If you receive an alert from us, please patch.

World Map view of all n8n vulnerable instances we track: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=n8n%2B&data_set=count&scale=log&auto_update=on

#CyberCivilDefense

3
0
2
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 6mo ago

Cisco SD-WAN incidents: we are sharing information on identified Cisco SD-WAN instances in Device ID reporting - https://www.shadowserver.org/what-we-do/network-reporting/device-identification-report/

We see over 5.5K Cisco SD-WAN IPs (control plane) (https://dashboard.shadowserver.org/statistics/iot-devices/tree/?date_range=1&vendor=cisco&model=cisco+sd-wan+%28peering%29&data_set=count&scale=log), & over 270 management interfaces (https://dashboard.shadowserver.org/statistics/iot-devices/tree/?date_range=1&vendor=cisco&type=device-management&model=cisco+sd-wan&data_set=count&scale=log)

We are also sharing SSH port 830 data in our Accessible SSH reporting - this includes potential NETCONF instances https://www.shadowserver.org/what-we-do/network-reporting/accessible-ssh-report/

Around 90K SSH instances seen exposed, but this includes generic SSH population (NETCONF uses SSH).

Background: https://www.ncsc.gov.uk/news/exploitation-cisco-catalyst-sd-wans

https://blog.talosintelligence.com/uat-8616-sd-wan/

https://www.cyber.gov.au/sites/default/files/2026-02/ACSC-led%20Cisco%20SD-WAN%20Hunt%20Guide.pdf

https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide

#CyberCivilDefense

3
0
3
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 6mo ago

Thanks to collaboration with the Canadian Centre for Cyber Security we can share more comprehensive information on FreePBX instances running webshells, with still over 900 IPs seen compromised.

Dashboard Victim overview (Tree map) https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=compromised_iot&source=compromised_website&source=compromised_website6&tag=freepbx-compromised%2B&data_set=count&scale=log&auto_update=on

IP data in our Compromised Website report, tagged 'freepbx-compromised' - https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/

Compromised FreePBX tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=compromised_iot&source=compromised_website&source=compromised_website6&tag=freepbx-compromised%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

These compromises are likely via CVE-2025-64328

Additional background from Fortinet: https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp

3
0
3
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 7mo ago

We have started to report webshells (or other exploitation artifacts) found on Ivanti EPMM devices, likely compromised via CVE-2026-1281. 56 IPs found on 2026-02-06

Data in https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/

Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=compromised_website&source=compromised_website6&tag=ivanti-epmm-compromised%2B&data_set=count&scale=log&auto_update=on

Thank you to the KSA NCA for the heads up!

If you receive an alert from us, please review the security advisory and guidance from Ivanti at https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340 including the Exploitation Detection RPM Package co-developed by Ivanti & @NCSC_NL@social.overheid.nl

2
0
0
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 18mo ago

We started scanning for IoT devices compromised by the Eleven11bot DDoS botnet, with ~86.4K discovered on 2025-03-03. IP data is shared daily in our Compromised IoT report https://www.shadowserver.org/what-we-do/network-reporting/compromised-iot-report/

Top affected: US (24.7K), UK (10.8K).

Dashboard map view: https://dashboard.shadowserver.org/statistics/combined/map/?map_type=std&day=2025-03-03&source=compromised_iot&tag=eleven11bot%2B&geo=all&data_set=count&scale=log

For background, please see Nokia Deepfield Emergency Response Team (ERT) @deepfield@infosec.exchange announcement: @deepfield@infosec.exchange

Dashboard breakdown by US state:

https://dashboard.shadowserver.org/statistics/combined/map/region/?map_type=std&day=2025-03-03&source=compromised_iot&geo=US&scale=log

8
1
4
0
Open post
The Shadowserver Foundation @shadowserver@infosec.exchange
· 6mo ago

We are scanning & reporting IceWarp CVE-2025-14500 (CVSS 9.8, pre-auth command injection RCE) instances. 1278 IPs seen 2026-03-01 (version based check).

Patch info: https://support.icewarp.com/hc/en-us/community/posts/40040980098705-EPOS-Update-2-build-9-14-2-0-9

IP data in https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

Dashboard World Map view: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-14500%2B&data_set=count&scale=log&auto_update=on

If you receive an alert from us, please update!

NVD entry: https://nvd.nist.gov/vuln/detail/cve-2025-14500

Background: https://www.zerodayinitiative.com/advisories/ZDI-25-1072/

#CyberCivilDefense

1
0
2
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:13:09 UTC