The Shadowserver Foundation @shadowserver.bsky.social · 13/09/2026We have started reporting out (daily) MikroTik instances with exposed proprietary services, such as WinBox & Bandwidth Test server (btest): www.shadowserver.org/what-we-do/n... Around 2.6M exposed instances shared daily. Top: Brazil, Indonesia, USA Stats: dashboard.shadowserver.org/statistics/c... 183
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026Still 218 instances of N-able N-central seen unpatched to CVE-2026-86218 pre-auth RCE that is exploited in the wild & on US CISA KEV. Top: US (141) Stats - World Map view: dashboard.shadowserver.org/statistics/c... Tracker: dashboard.shadowserver.org/statistics/c... 132
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026We shared a one-off share of over 400 compromised PaperCut NG/MF instances (via CVE-2026-81578/CVE-2026-82078) observed by @greynoise.io. IP data in our Compromised Website reporting for 2026-09-11, tagged 'papercut-compromise'. Dashboard Tree Map stats: dashboard.shadowserver.org/statistics/c... 153
The Shadowserver Foundation @shadowserver.bsky.social · 09/09/2026Since 2026-09-04 we are scanning/reporting daily unpatched versions of Plex Media Server in response to an advisory issued by Plex forums.plex.tv/t/important-... for v1.43.2 & earlier. Over 36K instances found still unpatched! Top affected: US World Map: dashboard.shadowserver.org/statistics/c... 1103
Reposted by The Shadowserver FoundationThe Shadowserver Foundation @shadowserver.bsky.social · 06/09/2026We added MikroTik SSH identification to our daily scans on 2026-09-04, in response to MikroTik's patches mikrotik.com/supportsec/s.... As discovered by CERT Polska cert.pl/en/posts/202... unpatched MikroTiks can be compromised, if device supports remote access using SSH protocol 2137
The Shadowserver Foundation @shadowserver.bsky.social · 06/09/2026We added MikroTik SSH identification to our daily scans on 2026-09-04, in response to MikroTik's patches mikrotik.com/supportsec/s.... As discovered by CERT Polska cert.pl/en/posts/202... unpatched MikroTiks can be compromised, if device supports remote access using SSH protocol 2137
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026PaperCut MF/NG incidents: At least 204 instances found on 2026-08-31 still vulnerable to CVE-2026-82078/CVE-2026-81578 RCE that is exploited in the wild. Make sure to check for compromise & patch. Top affected: US (60). Dashboard World Map view stats: dashboard.shadowserver.org/statistics/c... 110
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: www.shadowserver.org/what-we-do/n... At least 21899 IPs seen unpatched 2026-08-31, top US (6.2K) & Germany (5.1K) 153
Reposted by The Shadowserver FoundationCraig Newmark @craignewmark.bsky.social · 24/08/2026@shadowserver.bsky.social seriously helps protect us all 0173
The Shadowserver Foundation @shadowserver.bsky.social · 28/08/2026We are scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (code injection), with 8393 IPs found vulnerable on 2026-08-27. This vulnerability is exploited in the wild and on US CISA KEV. Top affected: China, Germany, US Dashboard view: dashboard.shadowserver.org/statistics/c... 174
The Shadowserver Foundation @shadowserver.bsky.social · 24/08/2026Alert! Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22. Top: US (41 IPs). Detection in collaboration with @CERT_Polska_en Public Dashboard: dashboard.shadowserver.org/statistics/c... 1103
The Shadowserver Foundation @shadowserver.bsky.social · 17/08/2026RondoDox botnet now also trying to exploit the new GeoServer 0-day, as seen in our sensors. We see over 1500 exposed instances worldwide (exposed population, not a vulnerability check). Patch info: geoserver.org/announcement... Tree Map Dashboard stats: dashboard.shadowserver.org/statistics/i... 152
The Shadowserver Foundation @shadowserver.bsky.social · 16/08/2026We are also scanning & reporting Metabase IPs likely unpatched to CVE-2026-72898 SQLi, which is exploited in the wild & on @CISACyber KEV. 2171 unpatched (version check) instances seen 2026-08-15. Top: US (603), Germany (278) Dashboard World Map stats: dashboard.shadowserver.org/statistics/c... 120
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026We are scanning & reporting F5 BIG-IP APM CVE-2025-53521 instances thanks to collaboration with the NCSC-NL SRT. 10 months after vuln disclosure, we still see over 850 IPs vulnerable to potential RCE. Top affected: US with 199 & Japan 182. IP data in Vulnerable HTTP reporting. 151
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026You can also track CVE-2026-59310 & CVE-2026-59309 vulnerable VMware vCenter instances in our daily Vulnerable HTTP reporting since July 30th: shadowserver.org/what-we-do/n... Tracker: dashboard.shadowserver.org/statistics/c... World Map: dashboard.shadowserver.org/statistics/c... 063
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026Thanks to collaboration with QUIRSO GmbH we are sharing the VMware vCenter CVE-2026-59310 Exploitation Victim Special Report shadowserver.org/what-we-do/n... Check compromised IPs for your network/constituency & remediate! File prefix: 2026-08-13-special See: medium.com/@quirso_de/a... 142
The Shadowserver Foundation @shadowserver.bsky.social · 13/08/2026We shared a Dysphoria Botnet Special Report on 2026-08-12 with over 296,000 devices compromised globally: shadowserver.org/what-we-do/n... Check reports with the 2026-08-12-special prefix for your network or constituency. Dashboard stats: dashboard.shadowserver.org/statistics/c... 163
The Shadowserver Foundation @shadowserver.bsky.social · 05/08/2026Excited to announce our Central and Eastern Europe (CEE) Critical Community Infrastructure (CCI) Project, focused on improving the #cybersecurity of essential public-serving organizations (made possible with support from Google.org) Find out more: www.shadowserver.org/news/shadows... 052
The Shadowserver Foundation @shadowserver.bsky.social · 24/07/2026Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to US CISA Known Exploited Vulnerability (KEV) catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23 142
The Shadowserver Foundation @shadowserver.bsky.social · 21/07/2026We’re excited to welcome Backblaze to the Shadowserver Alliance as a Bronze Tier Partner! Backblaze is a premier, high-performance cloud storage platform. www.backblaze.com With our Alliance Partners, we’ll make the Internet more secure and raise the bar on cybersecurity.backblaze.comHomeBackblaze is a pioneer in robust, scalable low cost cloud backup and storage services. Enterprise hot storage, low cost backup and archive, and more. 182
The Shadowserver Foundation @shadowserver.bsky.social · 03/07/2026We shared out ~2000 unique IPs exposing secrets that are known to have been harvested by a threat actor. IP data in our Compromised Website report: shadowserver.org/what-we-do/n... for your network/constituency with the 'stolen-key' tag (dated 2026-07-02). Check your reports! 152
The Shadowserver Foundation @shadowserver.bsky.social · 02/07/2026SimpleHelp CVE-2026-48558 is now confirmed exploited-in-the-wild & on US CISA KEV www.cisa.gov/known-exploi... We are scanning for CVE-2026-48558 vulnerable instances since 2026-06-16. We see 439 unpatched (2026-07-01 scan) Dashboard World Map view: dashboard.shadowserver.org/statistics/c... 153
The Shadowserver Foundation @shadowserver.bsky.social · 01/07/2026We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with Validin. Around 950 exposed instances now seen globally (no vulnerability assessment). CVE-2026-46817 attempts have been observed in the wild by DefusedCyber. 142
The Shadowserver Foundation @shadowserver.bsky.social · 27/06/2026Yesterday we reported out an additional dataset found on the #Fortibleed threat actors systems in a one-off special report - www.shadowserver.org/what-we-do/n.... The data was shared with us by SpyCloud (spycloud.com) & covers 35000 new IPs not previously reported. 173
The Shadowserver Foundation @shadowserver.bsky.social · 25/06/2026More Operation Endgame #cybercrime disruption success this week, with a new one-off StealC Historical Bot Special Report run overnight (2026-06-24), continuing our support for international LE partners: shadowserver.org/news/stealc-... 142
The Shadowserver Foundation @shadowserver.bsky.social · 23/06/2026Last week we added scanning for Joomla JCE editor extension CVE-2026-48907 vulnerable instances. This RCE vulnerability is exploited in the wild & on US CISA KEV. 4840 vulnerable instances seen 2026-06-22 down from 5146 on 2026-06-19. Top affected: US dashboard.shadowserver.org/statistics/c... 144
The Shadowserver Foundation @shadowserver.bsky.social · 19/06/2026We shared a one-off "FortiBleed" dataset of compromised Fortinet devices in our Compromised Website Report www.shadowserver.org/what-we-do/n... thanks to collaboration with SOCRadar! Stats: Dashboard World map view: dashboard.shadowserver.org/statistics/c... 142
The Shadowserver Foundation @shadowserver.bsky.social · 19/06/2026New one-off SocGholish Compromised #WordPress Sites Special Report run today, in continued support of international LE partners in Operation Endgame #cybercrime disruption: shadowserver.org/news/socghol... Great work once again everyone involved! 144
The Shadowserver Foundation @shadowserver.bsky.social · 12/06/2026Happy to once again support LE partners in disruption of the AudiA6 service, allegedly responsible for $389 million USD in cryptocurrency money laundering: justice.gov/usao-edpa/pr... secretservice.gov/newsroom/rel... www.europol.europa.eu/media-press/... 074
The Shadowserver Foundation @shadowserver.bsky.social · 11/06/2026Heads up! New report going out daily: the Initial Access Broker Report shadowserver.org/what-we-do/n... on compromised hosts likely under control of IABs Data thanks to collaboration with anonymous researchers & SpyCloud - thank you! Check your free daily reports from us! 183
The Shadowserver Foundation @shadowserver.bsky.social · 10/06/2026We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today. We see 19 vulnerable instances in our own scans, with at least 2 backdoored (thanks to Saudi NCA for the tip!). However, all remaining likely compromised too. 1102
The Shadowserver Foundation @shadowserver.bsky.social · 09/06/2026Shadowserver is excited to share its cybersecurity insights and actionable recommendations in a report aimed at helping ECOWAS stakeholders make West Africa more secure! Read the report & accompanying fact sheets in English, French & Portuguese at www.shadowserver.org/news/shadows... 2115
The Shadowserver Foundation @shadowserver.bsky.social · 05/06/2026We added scanning of Automatic Tank Gauge (ATG) systems to our Accessible ICS reporting with 1061 IPs seen on 2026-06-05 (on port 10001/tcp). This is after weeding out vast majority which appear to be honeypots (including ports 8001/9001). Vast majority exposed are in the US. 160
The Shadowserver Foundation @shadowserver.bsky.social · 29/05/2026Very happy to support CrowdStrike and Google in the disruption of the Glassworm botnet, which features 4x C2 channels, and targets developers via open-source supply chains: www.crowdstrike.com/en-us/blog/i... 183
Reposted by The Shadowserver FoundationProtect.ngo @protectngo.bsky.social · 26/05/2026Thank you Fabrice Guye (ELCASecurity), Sarah Reynolds (Dataminr), @piotrkijewski.bsky.social (@shadowserver.bsky.social ), Prerit Pathak (Google), Alison Brogan (@scvo.scot ), and @amira.bsky.social (@aspeninstitute.bsky.social). Read more about our takeaways here: shorturl.at/Hb0nXshorturl.atProtect.NGO’26: Protecting the Nonprofits Defending our Communities | CyberPeace InstituteAt the Protect.NGO’26 event taking place on 6 May 2026 in Geneva, +100 leaders and volunteers from governments, philanthropy, civil society, and the private sector gathered around a shared ideal: […] 032
The Shadowserver Foundation @shadowserver.bsky.social · 14/05/2026We published a "Shadowserver-in-a-box" platform based on IntelMQ + ELK that can ingest, process and visualize our threat/vulnerability/victim data feeds. Available as a VM or Docker image for free download. Use it for training or in production! Check it out here: github.com/The-Shadowse... 152
The Shadowserver Foundation @shadowserver.bsky.social · 11/05/2026We are scanning & reporting daily Wazuh CVE-2026-30893 (CVSS 9.9) vulnerable instances, with over 3500 IPs seen unpatched on 2026-05-10. See advisory & update to latest version: github.com/wazuh/wazuh/... ... Worth keeping your security platforms up to date! 111
The Shadowserver Foundation @shadowserver.bsky.social · 11/05/2026We are tagging CVE-2026-6973 Ivanti EPMM instances seen in our daily scans. 362 IPs seen unpatched on 2026-05-10, down from 562 IPs on 2026-05-08 when we first added the detection. See Ivanti advisory for details - hub.ivanti.com/s/article/Ma... CVE-2026-6973 is on US CISA KEV. 285
Reposted by The Shadowserver FoundationThe Shadowserver Foundation @shadowserver.bsky.social · 01/05/2026Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: support.cpanel.net/hc/en-us/art... Public Dashboard stats: dashboard.shadowserver.org/statistics/h... 1178
The Shadowserver Foundation @shadowserver.bsky.social · 01/05/2026Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: support.cpanel.net/hc/en-us/art... Public Dashboard stats: dashboard.shadowserver.org/statistics/h... 1178
The Shadowserver Foundation @shadowserver.bsky.social · 24/04/2026We are scanning/reporting daily Zimbra Collaboration Suite instances vulnerable to CVE-2025-48700, that can allow unauthorized access to sensitive information. This vulnerability is exploited in the wild and on US CISA KEV. We see over 10.5K IPs unpatched 2026-04-23. 142
The Shadowserver Foundation @shadowserver.bsky.social · 21/04/2026We are also scanning & reporting Microsoft SharePoint CVE-2026-32201 (Improper input validation in SharePoint allows an unauthorized attacker to perform spoofing over a network). This vulnerability is known exploited in the wild & on US CISA KEV list. 1370 IPs seen unpatched. Top: US 186
The Shadowserver Foundation @shadowserver.bsky.social · 21/04/2026Thank you to Precursor Security for becoming a Shadowserver Alliance Silver Tier Partner! Precursor Security delivers pen testing, 24/7 managed SOC, and more. www.precursorsecurity.com Together with our Alliance Partner community, we’ll make the Internet more secure. 032
The Shadowserver Foundation @shadowserver.bsky.social · 20/04/2026We are now scanning daily for CVE-2026-34197 (Apache ActiveMQ Improper Input Validation Vulnerability) which has recently been added to US CISA KEV. 6364 IPs seen vulnerable on 2026-04-19 based on a version check. Dashboard Tree Map view: dashboard.shadowserver.org/statistics/c... 173
The Shadowserver Foundation @shadowserver.bsky.social · 20/04/2026We added CVE-2026-35616 scans based on the vulnerability detector developed by Bishop Fox bishopfox.com/blog/api-aut.... Over 60 IPs still assessed as vulnerable: dashboard.shadowserver.org/statistics/c... Data shared daily in our Vulnerable HTTP reporting: shadowserver.org/what-we-do/n... 063
The Shadowserver Foundation @shadowserver.bsky.social · 14/04/2026We’re excited to announce that the Canadian Centre for Cyber Security (CCCS) has increased its annual Shadowserver Alliance Partnership tier from Gold to Diamond! Thank you CCCS for your generous support and for being a valuable and trusted partner in making the Internet more secure. 183
The Shadowserver Foundation @shadowserver.bsky.social · 07/04/2026We have also added CVE-2026-2699 tagging to our scans, which now detect unpatched Progress ShareFile instances. 120 seen 2026-04-06 dashboard.shadowserver.org/statistics/c... Tree Map view: dashboard.shadowserver.org/statistics/c... IP data in Vulnerable HTTP: www.shadowserver.org/what-we-do/n... 063
The Shadowserver Foundation @shadowserver.bsky.social · 05/04/2026Heads up FortiClient EMS users! CVE-2026-35616 (new) & CVE-2026-21643 - both unauthenticated RCE observed to be exploited in the wild! We fingerprint about 2000 instances globally, see public Dashboard: dashboard.shadowserver.org/statistics/i... Top affected: US & Germany 172
The Shadowserver Foundation @shadowserver.bsky.social · 03/04/2026We added Progress ShareFile fingerprinting to our scans & reports with 784 unique IPs seen exposed on 2026-04-02. watchTowr recently disclosed details behind an RCE CVE-2026-2699 & CVE-2026-2701 exploit chain affecting ShareFile. Make sure to apply the latest patch! 383
The Shadowserver Foundation @shadowserver.bsky.social · 01/04/2026F5 BIG-IP APM CVE-2025-53521 impact has recently been updated from a DoS to RCE (see: my.f5.com/manage/s/art...) & added to CISA KEV. We are fingerprinting & sharing F5 BIG-IP APM instances - over 17.1K IPs seen on 2026-03-31 globally. This is just a population assessment. 192