Sign in

Piotr Kijewski

@piotrkijewski.bsky.social
75 followers 3 following 1 posts

@shadowserver.bsky.social‬

PostsRepliesMedia
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 13/09/2026
We have started reporting out (daily) MikroTik instances with exposed proprietary services, such as WinBox & Bandwidth Test server (btest): www.shadowserver.org/what-we-do/n... Around 2.6M exposed instances shared daily. Top: Brazil, Indonesia, USA Stats: dashboard.shadowserver.org/statistics/c...
183
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026
Still 218 instances of N-able N-central seen unpatched to CVE-2026-86218 pre-auth RCE that is exploited in the wild & on US CISA KEV. Top: US (141) Stats - World Map view: dashboard.shadowserver.org/statistics/c... Tracker: dashboard.shadowserver.org/statistics/c...
132
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026
We shared a one-off share of over 400 compromised PaperCut NG/MF instances (via CVE-2026-81578/CVE-2026-82078) observed by @greynoise.io. IP data in our Compromised Website reporting for 2026-09-11, tagged 'papercut-compromise'. Dashboard Tree Map stats: dashboard.shadowserver.org/statistics/c...
153
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026
We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: www.shadowserver.org/what-we-do/n... At least 21899 IPs seen unpatched 2026-08-31, top US (6.2K) & Germany (5.1K)
153
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 24/08/2026
Alert! Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22. Top: US (41 IPs). Detection in collaboration with @CERT_Polska_en Public Dashboard: dashboard.shadowserver.org/statistics/c...
1103
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 28/08/2026
We are scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (code injection), with 8393 IPs found vulnerable on 2026-08-27. This vulnerability is exploited in the wild and on US CISA KEV. Top affected: China, Germany, US Dashboard view: dashboard.shadowserver.org/statistics/c...
174
Reposted by Piotr Kijewski
Craig Newmark @craignewmark.bsky.social · 24/08/2026
@shadowserver.bsky.social seriously helps protect us all
0173
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
We are scanning & reporting F5 BIG-IP APM CVE-2025-53521 instances thanks to collaboration with the NCSC-NL SRT. 10 months after vuln disclosure, we still see over 850 IPs vulnerable to potential RCE. Top affected: US with 199 & Japan 182. IP data in Vulnerable HTTP reporting.
151
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
You can also track CVE-2026-59310 & CVE-2026-59309 vulnerable VMware vCenter instances in our daily Vulnerable HTTP reporting since July 30th: shadowserver.org/what-we-do/n... Tracker: dashboard.shadowserver.org/statistics/c... World Map: dashboard.shadowserver.org/statistics/c...
063
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
Thanks to collaboration with QUIRSO GmbH we are sharing the VMware vCenter CVE-2026-59310 Exploitation Victim Special Report shadowserver.org/what-we-do/n... Check compromised IPs for your network/constituency & remediate! File prefix: 2026-08-13-special See: medium.com/@quirso_de/a...
142
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 13/08/2026
We shared a Dysphoria Botnet Special Report on 2026-08-12 with over 296,000 devices compromised globally: shadowserver.org/what-we-do/n... Check reports with the 2026-08-12-special prefix for your network or constituency. Dashboard stats: dashboard.shadowserver.org/statistics/c...
163
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 24/07/2026
Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to US CISA Known Exploited Vulnerability (KEV) catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23
142
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 05/08/2026
Excited to announce our Central and Eastern Europe (CEE) Critical Community Infrastructure (CCI) Project, focused on improving the #cybersecurity of essential public-serving organizations (made possible with support from Google.org) Find out more: www.shadowserver.org/news/shadows...
052
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 21/07/2026
We’re excited to welcome Backblaze to the Shadowserver Alliance as a Bronze Tier Partner! Backblaze is a premier, high-performance cloud storage platform. www.backblaze.com With our Alliance Partners, we’ll make the Internet more secure and raise the bar on cybersecurity.
backblaze.com
Home
Backblaze is a pioneer in robust, scalable low cost cloud backup and storage services. Enterprise hot storage, low cost backup and archive, and more.
182
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 03/07/2026
We shared out ~2000 unique IPs exposing secrets that are known to have been harvested by a threat actor. IP data in our Compromised Website report: shadowserver.org/what-we-do/n... for your network/constituency with the 'stolen-key' tag (dated 2026-07-02). Check your reports!
152
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 02/07/2026
SimpleHelp CVE-2026-48558 is now confirmed exploited-in-the-wild & on US CISA KEV www.cisa.gov/known-exploi... We are scanning for CVE-2026-48558 vulnerable instances since 2026-06-16. We see 439 unpatched (2026-07-01 scan) Dashboard World Map view: dashboard.shadowserver.org/statistics/c...
153
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 01/07/2026
We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with Validin. Around 950 exposed instances now seen globally (no vulnerability assessment). CVE-2026-46817 attempts have been observed in the wild by DefusedCyber.
142
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 27/06/2026
Yesterday we reported out an additional dataset found on the #Fortibleed threat actors systems in a one-off special report - www.shadowserver.org/what-we-do/n.... The data was shared with us by SpyCloud (spycloud.com) & covers 35000 new IPs not previously reported.
173
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 19/06/2026
We shared a one-off "FortiBleed" dataset of compromised Fortinet devices in our Compromised Website Report www.shadowserver.org/what-we-do/n... thanks to collaboration with SOCRadar! Stats: Dashboard World map view: dashboard.shadowserver.org/statistics/c...
142
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 19/06/2026
New one-off SocGholish Compromised #WordPress Sites Special Report run today, in continued support of international LE partners in Operation Endgame #cybercrime disruption: shadowserver.org/news/socghol... Great work once again everyone involved!
144
Reposted by Piotr Kijewski
Protect.ngo @protectngo.bsky.social · 26/05/2026
Thank you Fabrice Guye (ELCASecurity), Sarah Reynolds (Dataminr), @piotrkijewski.bsky.social (@shadowserver.bsky.social ), Prerit Pathak (Google), Alison Brogan (@scvo.scot ), and @amira.bsky.social (@aspeninstitute.bsky.social). Read more about our takeaways here: shorturl.at/Hb0nX
shorturl.at
Protect.NGO’26: Protecting the Nonprofits Defending our Communities | CyberPeace Institute
At the Protect.NGO’26 event taking place on 6 May 2026 in Geneva, +100 leaders and volunteers from governments, philanthropy, civil society, and the private sector gathered around a shared ideal: […]
032
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 14/05/2026
We published a "Shadowserver-in-a-box" platform based on IntelMQ + ELK that can ingest, process and visualize our threat/vulnerability/victim data feeds. Available as a VM or Docker image for free download. Use it for training or in production! Check it out here: github.com/The-Shadowse...
152
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 11/05/2026
We are tagging CVE-2026-6973 Ivanti EPMM instances seen in our daily scans. 362 IPs seen unpatched on 2026-05-10, down from 562 IPs on 2026-05-08 when we first added the detection. See Ivanti advisory for details - hub.ivanti.com/s/article/Ma... CVE-2026-6973 is on US CISA KEV.
285
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 01/05/2026
Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: support.cpanel.net/hc/en-us/art... Public Dashboard stats: dashboard.shadowserver.org/statistics/h...
1178
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 24/04/2026
We are scanning/reporting daily Zimbra Collaboration Suite instances vulnerable to CVE-2025-48700, that can allow unauthorized access to sensitive information. This vulnerability is exploited in the wild and on US CISA KEV. We see over 10.5K IPs unpatched 2026-04-23.
142
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 21/04/2026
We are also scanning & reporting Microsoft SharePoint CVE-2026-32201 (Improper input validation in SharePoint allows an unauthorized attacker to perform spoofing over a network). This vulnerability is known exploited in the wild & on US CISA KEV list. 1370 IPs seen unpatched. Top: US
186
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 21/04/2026
Thank you to Precursor Security for becoming a Shadowserver Alliance Silver Tier Partner! Precursor Security delivers pen testing, 24/7 managed SOC, and more. www.precursorsecurity.com Together with our Alliance Partner community, we’ll make the Internet more secure.
032
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 20/04/2026
We are now scanning daily for CVE-2026-34197 (Apache ActiveMQ Improper Input Validation Vulnerability) which has recently been added to US CISA KEV. 6364 IPs seen vulnerable on 2026-04-19 based on a version check. Dashboard Tree Map view: dashboard.shadowserver.org/statistics/c...
173
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 20/04/2026
We added CVE-2026-35616 scans based on the vulnerability detector developed by Bishop Fox bishopfox.com/blog/api-aut.... Over 60 IPs still assessed as vulnerable: dashboard.shadowserver.org/statistics/c... Data shared daily in our Vulnerable HTTP reporting: shadowserver.org/what-we-do/n...
063
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 14/04/2026
We’re excited to announce that the Canadian Centre for Cyber Security (CCCS) has increased its annual Shadowserver Alliance Partnership tier from Gold to Diamond! Thank you CCCS for your generous support and for being a valuable and trusted partner in making the Internet more secure.
183
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 07/04/2026
We have also added CVE-2026-2699 tagging to our scans, which now detect unpatched Progress ShareFile instances. 120 seen 2026-04-06 dashboard.shadowserver.org/statistics/c... Tree Map view: dashboard.shadowserver.org/statistics/c... IP data in Vulnerable HTTP: www.shadowserver.org/what-we-do/n...
063
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 05/04/2026
Heads up FortiClient EMS users! CVE-2026-35616 (new) & CVE-2026-21643 - both unauthenticated RCE observed to be exploited in the wild! We fingerprint about 2000 instances globally, see public Dashboard: dashboard.shadowserver.org/statistics/i... Top affected: US & Germany
172
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 03/04/2026
We added Progress ShareFile fingerprinting to our scans & reports with 784 unique IPs seen exposed on 2026-04-02. watchTowr recently disclosed details behind an RCE CVE-2026-2699 & CVE-2026-2701 exploit chain affecting ShareFile. Make sure to apply the latest patch!
383
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 01/04/2026
F5 BIG-IP APM CVE-2025-53521 impact has recently been updated from a DoS to RCE (see: my.f5.com/manage/s/art...) & added to CISA KEV. We are fingerprinting & sharing F5 BIG-IP APM instances - over 17.1K IPs seen on 2026-03-31 globally. This is just a population assessment.
192
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 31/03/2026
We’re excited to welcome KPN to the Shadowserver Alliance as a bronze tier partner! KPN is a leading telecommunications and IT provider in the Netherlands. www.kpn.com/algemeen/eng... Together we will raise the bar on cybersecurity to make the Internet more secure.
162
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 23/03/2026
IIS EOL tracker: dashboard.shadowserver.org/statistics/c...
021
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 23/03/2026
Over 511 000 End-of-Life Microsoft IIS instances seen in our daily scans, out of those over 227 000 instances that are beyond the official Microsoft Extended Security Updates (ESU) period. We now tag those 'eol-iis' and 'eos-iis' respectively in our Vulnerable HTTP reports.
1136
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 15/03/2026
We added a feed of IPs/websites with ClickFix/ClearFake injected code in our Compromised Website reporting, tagged as 'clickfix'. Visitors of the website get tricked to install malware when injected JavaScript executes. If you receive an alert review for root cause of compromise!
175
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 06/03/2026
Great to support our international LE and private sector partners in Tycoon 2FA phishing-as-a-service #cybercrime disruption: shadowserver.org/news/tycoon-... New nCSIRT-only Tycoon 2FA Domains Special Report run 2026-03-04 (historical C2/panel/infra domains) www.shadowserver.org/what-we-do/n...
132
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 03/03/2026
Another Iran Internet blackout, this time due to the war, visualized on our Public Dashboard - drop to near zero on 2026-03-01: dashboard.shadowserver.org/statistics/c...
073
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 03/03/2026
We are continuing to expand our n8n RCE vulnerability scanning - most recently adding CVE-2026-27495 (CVSS 9.4) tagging as well. You can track our various n8n scan results here for the most well known critical vulns: dashboard.shadowserver.org/statistics/c... Top affected: US, Germany & France.
162
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 10/02/2026
Massive increase in sources attempting Ivanti EPMM CVE-2026-1281 exploitation, with over 28.3K source IPs seen on 2026-02-09. IP data on attackers shared in our www.shadowserver.org/what-we-do/n... (with vulnerability_id set to CVE-2026-1281). 20.4K IPs seen from US networks.
175
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 07/02/2026
We have started to report webshells (or other artifacts) found on Ivanti EPMM devices, likely compromised via CVE-2026-1281. 56 IPs found on 2026-02-06 Data in shadowserver.org/what-we-do/n... Tree Map view: dashboard.shadowserver.org/statistics/c... Thank you to the KSA NCA for the heads up!
2288
Reposted by Piotr Kijewski
Craig Newmark @craignewmark.bsky.social · 05/02/2026
These reports help people defend the country against cyber attacks and also helps people fight scammer networks #CyberCivilDefense #take9
0144
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 31/01/2026
Spike in Ivanti EPMM CVE-2026-1281 RCE exploitation attempts seen by our sensors last 24 hours from at least 13 source IPs. In our scans, we see ~1600 exposed instances worldwide (no vulnerability assessment). Top exposed: Germany (516) Ivanti hotfix guidance: forums.ivanti.com/s/article/Se...
162
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 28/01/2026
CVE-2026-24858, a Fortinet authentication bypass vulnerability affecting multiple Fortinet products with FortiCloud SSO enabled, has been added by CISA to the KEV catalog. We share exposed Fortinet instances with FortiCloud SSO enabled daily in our feeds (~10 000 seen)
144
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 26/01/2026
We added SmarterTools SmarterMail CVE-2026-23760 RCE to our daily Vulnerable HTTP scans. Around 6000 IPs globally found likely vulnerable based on our version check. We also see exploitation attempts in the wild. CVE-2026-23760 Geo Treemap View: dashboard.shadowserver.org/statistics/c...
112
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 26/01/2026
Regarding CVE-2026-24061 in GNU InetUtils telnetd: while we are not scanning for it explicitly (due to current lack of ability to check in a safe way, we do share - and have for years - data on exposed instances in our Accessible Telnet Report: www.shadowserver.org/what-we-do/n... ~800K exposed
052
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 13/01/2026
We are scanning & reporting out SmarterMail hosts vulnerable to CVE-2025-52691 RCE (CVSS 10). 8001 unique IPs likely vulnerable on 2026-01-12 (18783 exposed). Note Exploit PoCs are public. Tree Map: dashboard.shadowserver.org/statistics/c... Raw IP data: www.shadowserver.org/what-we-do/n...
122
Reposted by Piotr Kijewski
The Shadowserver Foundation @shadowserver.bsky.social · 20/12/2025
We have identified 120 Cisco Secure Email Gateway/ Cisco Secure Email and Web Manager likely vulnerable to CVE-2025-20393 (over 650 fingerprinted exposed). CVE-2025-20393 is exploited in the wild, with no patch available. Follow Cisco recommendations at sec.cloudapps.cisco.com/security/cen...
185