Sign in

The Shadowserver Foundation

@shadowserver.bsky.social
5K followers 0 following 928 posts

Our mission is to make the Internet more secure by bringing to light vulnerabilities, malicious activity and emerging threats. Join our Alliance! shadowserver.org/partner

PostsRepliesMedia
The Shadowserver Foundation @shadowserver.bsky.social · 13/09/2026
We have started reporting out (daily) MikroTik instances with exposed proprietary services, such as WinBox & Bandwidth Test server (btest): www.shadowserver.org/what-we-do/n... Around 2.6M exposed instances shared daily. Top: Brazil, Indonesia, USA Stats: dashboard.shadowserver.org/statistics/c...
183
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026
Still 218 instances of N-able N-central seen unpatched to CVE-2026-86218 pre-auth RCE that is exploited in the wild & on US CISA KEV. Top: US (141) Stats - World Map view: dashboard.shadowserver.org/statistics/c... Tracker: dashboard.shadowserver.org/statistics/c...
132
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026
We shared a one-off share of over 400 compromised PaperCut NG/MF instances (via CVE-2026-81578/CVE-2026-82078) observed by @greynoise.io. IP data in our Compromised Website reporting for 2026-09-11, tagged 'papercut-compromise'. Dashboard Tree Map stats: dashboard.shadowserver.org/statistics/c...
153
The Shadowserver Foundation @shadowserver.bsky.social · 09/09/2026
Since 2026-09-04 we are scanning/reporting daily unpatched versions of Plex Media Server in response to an advisory issued by Plex forums.plex.tv/t/important-... for v1.43.2 & earlier. Over 36K instances found still unpatched! Top affected: US World Map: dashboard.shadowserver.org/statistics/c...
1103
Reposted by The Shadowserver Foundation
The Shadowserver Foundation @shadowserver.bsky.social · 06/09/2026
We added MikroTik SSH identification to our daily scans on 2026-09-04, in response to MikroTik's patches mikrotik.com/supportsec/s.... As discovered by CERT Polska cert.pl/en/posts/202... unpatched MikroTiks can be compromised, if device supports remote access using SSH protocol
2137
The Shadowserver Foundation @shadowserver.bsky.social · 06/09/2026
We added MikroTik SSH identification to our daily scans on 2026-09-04, in response to MikroTik's patches mikrotik.com/supportsec/s.... As discovered by CERT Polska cert.pl/en/posts/202... unpatched MikroTiks can be compromised, if device supports remote access using SSH protocol
2137
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026
PaperCut MF/NG incidents: At least 204 instances found on 2026-08-31 still vulnerable to CVE-2026-82078/CVE-2026-81578 RCE that is exploited in the wild. Make sure to check for compromise & patch. Top affected: US (60). Dashboard World Map view stats: dashboard.shadowserver.org/statistics/c...
110
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026
We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: www.shadowserver.org/what-we-do/n... At least 21899 IPs seen unpatched 2026-08-31, top US (6.2K) & Germany (5.1K)
153
Reposted by The Shadowserver Foundation
Craig Newmark @craignewmark.bsky.social · 24/08/2026
@shadowserver.bsky.social seriously helps protect us all
0173
The Shadowserver Foundation @shadowserver.bsky.social · 28/08/2026
We are scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (code injection), with 8393 IPs found vulnerable on 2026-08-27. This vulnerability is exploited in the wild and on US CISA KEV. Top affected: China, Germany, US Dashboard view: dashboard.shadowserver.org/statistics/c...
174
The Shadowserver Foundation @shadowserver.bsky.social · 24/08/2026
Alert! Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22. Top: US (41 IPs). Detection in collaboration with @CERT_Polska_en Public Dashboard: dashboard.shadowserver.org/statistics/c...
1103
The Shadowserver Foundation @shadowserver.bsky.social · 17/08/2026
RondoDox botnet now also trying to exploit the new GeoServer 0-day, as seen in our sensors. We see over 1500 exposed instances worldwide (exposed population, not a vulnerability check). Patch info: geoserver.org/announcement... Tree Map Dashboard stats: dashboard.shadowserver.org/statistics/i...
152
The Shadowserver Foundation @shadowserver.bsky.social · 16/08/2026
We are also scanning & reporting Metabase IPs likely unpatched to CVE-2026-72898 SQLi, which is exploited in the wild & on @CISACyber KEV. 2171 unpatched (version check) instances seen 2026-08-15. Top: US (603), Germany (278) Dashboard World Map stats: dashboard.shadowserver.org/statistics/c...
120
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
We are scanning & reporting F5 BIG-IP APM CVE-2025-53521 instances thanks to collaboration with the NCSC-NL SRT. 10 months after vuln disclosure, we still see over 850 IPs vulnerable to potential RCE. Top affected: US with 199 & Japan 182. IP data in Vulnerable HTTP reporting.
151
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
You can also track CVE-2026-59310 & CVE-2026-59309 vulnerable VMware vCenter instances in our daily Vulnerable HTTP reporting since July 30th: shadowserver.org/what-we-do/n... Tracker: dashboard.shadowserver.org/statistics/c... World Map: dashboard.shadowserver.org/statistics/c...
063
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
Thanks to collaboration with QUIRSO GmbH we are sharing the VMware vCenter CVE-2026-59310 Exploitation Victim Special Report shadowserver.org/what-we-do/n... Check compromised IPs for your network/constituency & remediate! File prefix: 2026-08-13-special See: medium.com/@quirso_de/a...
142
The Shadowserver Foundation @shadowserver.bsky.social · 13/08/2026
We shared a Dysphoria Botnet Special Report on 2026-08-12 with over 296,000 devices compromised globally: shadowserver.org/what-we-do/n... Check reports with the 2026-08-12-special prefix for your network or constituency. Dashboard stats: dashboard.shadowserver.org/statistics/c...
163
The Shadowserver Foundation @shadowserver.bsky.social · 05/08/2026
Excited to announce our Central and Eastern Europe (CEE) Critical Community Infrastructure (CCI) Project, focused on improving the #cybersecurity of essential public-serving organizations (made possible with support from Google.org) Find out more: www.shadowserver.org/news/shadows...
052
The Shadowserver Foundation @shadowserver.bsky.social · 24/07/2026
Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to US CISA Known Exploited Vulnerability (KEV) catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23
142
The Shadowserver Foundation @shadowserver.bsky.social · 21/07/2026
We’re excited to welcome Backblaze to the Shadowserver Alliance as a Bronze Tier Partner! Backblaze is a premier, high-performance cloud storage platform. www.backblaze.com With our Alliance Partners, we’ll make the Internet more secure and raise the bar on cybersecurity.
backblaze.com
Home
Backblaze is a pioneer in robust, scalable low cost cloud backup and storage services. Enterprise hot storage, low cost backup and archive, and more.
182
The Shadowserver Foundation @shadowserver.bsky.social · 03/07/2026
We shared out ~2000 unique IPs exposing secrets that are known to have been harvested by a threat actor. IP data in our Compromised Website report: shadowserver.org/what-we-do/n... for your network/constituency with the 'stolen-key' tag (dated 2026-07-02). Check your reports!
152
The Shadowserver Foundation @shadowserver.bsky.social · 02/07/2026
SimpleHelp CVE-2026-48558 is now confirmed exploited-in-the-wild & on US CISA KEV www.cisa.gov/known-exploi... We are scanning for CVE-2026-48558 vulnerable instances since 2026-06-16. We see 439 unpatched (2026-07-01 scan) Dashboard World Map view: dashboard.shadowserver.org/statistics/c...
153
The Shadowserver Foundation @shadowserver.bsky.social · 01/07/2026
We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with Validin. Around 950 exposed instances now seen globally (no vulnerability assessment). CVE-2026-46817 attempts have been observed in the wild by DefusedCyber.
142
The Shadowserver Foundation @shadowserver.bsky.social · 27/06/2026
Yesterday we reported out an additional dataset found on the #Fortibleed threat actors systems in a one-off special report - www.shadowserver.org/what-we-do/n.... The data was shared with us by SpyCloud (spycloud.com) & covers 35000 new IPs not previously reported.
173
The Shadowserver Foundation @shadowserver.bsky.social · 25/06/2026
More Operation Endgame #cybercrime disruption success this week, with a new one-off StealC Historical Bot Special Report run overnight (2026-06-24), continuing our support for international LE partners: shadowserver.org/news/stealc-...
142
The Shadowserver Foundation @shadowserver.bsky.social · 23/06/2026
Last week we added scanning for Joomla JCE editor extension CVE-2026-48907 vulnerable instances. This RCE vulnerability is exploited in the wild & on US CISA KEV. 4840 vulnerable instances seen 2026-06-22 down from 5146 on 2026-06-19. Top affected: US dashboard.shadowserver.org/statistics/c...
144
The Shadowserver Foundation @shadowserver.bsky.social · 19/06/2026
We shared a one-off "FortiBleed" dataset of compromised Fortinet devices in our Compromised Website Report www.shadowserver.org/what-we-do/n... thanks to collaboration with SOCRadar! Stats: Dashboard World map view: dashboard.shadowserver.org/statistics/c...
142
The Shadowserver Foundation @shadowserver.bsky.social · 19/06/2026
New one-off SocGholish Compromised #WordPress Sites Special Report run today, in continued support of international LE partners in Operation Endgame #cybercrime disruption: shadowserver.org/news/socghol... Great work once again everyone involved!
144
The Shadowserver Foundation @shadowserver.bsky.social · 12/06/2026
Happy to once again support LE partners in disruption of the AudiA6 service, allegedly responsible for $389 million USD in cryptocurrency money laundering: justice.gov/usao-edpa/pr... secretservice.gov/newsroom/rel... www.europol.europa.eu/media-press/...
074
The Shadowserver Foundation @shadowserver.bsky.social · 11/06/2026
Heads up! New report going out daily: the Initial Access Broker Report shadowserver.org/what-we-do/n... on compromised hosts likely under control of IABs Data thanks to collaboration with anonymous researchers & SpyCloud - thank you! Check your free daily reports from us!
183
The Shadowserver Foundation @shadowserver.bsky.social · 10/06/2026
We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today. We see 19 vulnerable instances in our own scans, with at least 2 backdoored (thanks to Saudi NCA for the tip!). However, all remaining likely compromised too.
1102
The Shadowserver Foundation @shadowserver.bsky.social · 09/06/2026
Shadowserver is excited to share its cybersecurity insights and actionable recommendations in a report aimed at helping ECOWAS stakeholders make West Africa more secure! Read the report & accompanying fact sheets in English, French & Portuguese at www.shadowserver.org/news/shadows...
2115
The Shadowserver Foundation @shadowserver.bsky.social · 05/06/2026
We added scanning of Automatic Tank Gauge (ATG) systems to our Accessible ICS reporting with 1061 IPs seen on 2026-06-05 (on port 10001/tcp). This is after weeding out vast majority which appear to be honeypots (including ports 8001/9001). Vast majority exposed are in the US.
160
The Shadowserver Foundation @shadowserver.bsky.social · 29/05/2026
Very happy to support CrowdStrike and Google in the disruption of the Glassworm botnet, which features 4x C2 channels, and targets developers via open-source supply chains: www.crowdstrike.com/en-us/blog/i...
183
Reposted by The Shadowserver Foundation
Protect.ngo @protectngo.bsky.social · 26/05/2026
Thank you Fabrice Guye (ELCASecurity), Sarah Reynolds (Dataminr), @piotrkijewski.bsky.social (@shadowserver.bsky.social ), Prerit Pathak (Google), Alison Brogan (@scvo.scot ), and @amira.bsky.social (@aspeninstitute.bsky.social). Read more about our takeaways here: shorturl.at/Hb0nX
shorturl.at
Protect.NGO’26: Protecting the Nonprofits Defending our Communities | CyberPeace Institute
At the Protect.NGO’26 event taking place on 6 May 2026 in Geneva, +100 leaders and volunteers from governments, philanthropy, civil society, and the private sector gathered around a shared ideal: […]
032
The Shadowserver Foundation @shadowserver.bsky.social · 14/05/2026
We published a "Shadowserver-in-a-box" platform based on IntelMQ + ELK that can ingest, process and visualize our threat/vulnerability/victim data feeds. Available as a VM or Docker image for free download. Use it for training or in production! Check it out here: github.com/The-Shadowse...
152
The Shadowserver Foundation @shadowserver.bsky.social · 11/05/2026
We are scanning & reporting daily Wazuh CVE-2026-30893 (CVSS 9.9) vulnerable instances, with over 3500 IPs seen unpatched on 2026-05-10. See advisory & update to latest version: github.com/wazuh/wazuh/... ... Worth keeping your security platforms up to date!
111
The Shadowserver Foundation @shadowserver.bsky.social · 11/05/2026
We are tagging CVE-2026-6973 Ivanti EPMM instances seen in our daily scans. 362 IPs seen unpatched on 2026-05-10, down from 562 IPs on 2026-05-08 when we first added the detection. See Ivanti advisory for details - hub.ivanti.com/s/article/Ma... CVE-2026-6973 is on US CISA KEV.
285
Reposted by The Shadowserver Foundation
The Shadowserver Foundation @shadowserver.bsky.social · 01/05/2026
Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: support.cpanel.net/hc/en-us/art... Public Dashboard stats: dashboard.shadowserver.org/statistics/h...
1178
The Shadowserver Foundation @shadowserver.bsky.social · 01/05/2026
Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: support.cpanel.net/hc/en-us/art... Public Dashboard stats: dashboard.shadowserver.org/statistics/h...
1178
The Shadowserver Foundation @shadowserver.bsky.social · 24/04/2026
We are scanning/reporting daily Zimbra Collaboration Suite instances vulnerable to CVE-2025-48700, that can allow unauthorized access to sensitive information. This vulnerability is exploited in the wild and on US CISA KEV. We see over 10.5K IPs unpatched 2026-04-23.
142
The Shadowserver Foundation @shadowserver.bsky.social · 21/04/2026
We are also scanning & reporting Microsoft SharePoint CVE-2026-32201 (Improper input validation in SharePoint allows an unauthorized attacker to perform spoofing over a network). This vulnerability is known exploited in the wild & on US CISA KEV list. 1370 IPs seen unpatched. Top: US
186
The Shadowserver Foundation @shadowserver.bsky.social · 21/04/2026
Thank you to Precursor Security for becoming a Shadowserver Alliance Silver Tier Partner! Precursor Security delivers pen testing, 24/7 managed SOC, and more. www.precursorsecurity.com Together with our Alliance Partner community, we’ll make the Internet more secure.
032
The Shadowserver Foundation @shadowserver.bsky.social · 20/04/2026
We are now scanning daily for CVE-2026-34197 (Apache ActiveMQ Improper Input Validation Vulnerability) which has recently been added to US CISA KEV. 6364 IPs seen vulnerable on 2026-04-19 based on a version check. Dashboard Tree Map view: dashboard.shadowserver.org/statistics/c...
173
The Shadowserver Foundation @shadowserver.bsky.social · 20/04/2026
We added CVE-2026-35616 scans based on the vulnerability detector developed by Bishop Fox bishopfox.com/blog/api-aut.... Over 60 IPs still assessed as vulnerable: dashboard.shadowserver.org/statistics/c... Data shared daily in our Vulnerable HTTP reporting: shadowserver.org/what-we-do/n...
063
The Shadowserver Foundation @shadowserver.bsky.social · 14/04/2026
We’re excited to announce that the Canadian Centre for Cyber Security (CCCS) has increased its annual Shadowserver Alliance Partnership tier from Gold to Diamond! Thank you CCCS for your generous support and for being a valuable and trusted partner in making the Internet more secure.
183
The Shadowserver Foundation @shadowserver.bsky.social · 07/04/2026
We have also added CVE-2026-2699 tagging to our scans, which now detect unpatched Progress ShareFile instances. 120 seen 2026-04-06 dashboard.shadowserver.org/statistics/c... Tree Map view: dashboard.shadowserver.org/statistics/c... IP data in Vulnerable HTTP: www.shadowserver.org/what-we-do/n...
063
The Shadowserver Foundation @shadowserver.bsky.social · 05/04/2026
Heads up FortiClient EMS users! CVE-2026-35616 (new) & CVE-2026-21643 - both unauthenticated RCE observed to be exploited in the wild! We fingerprint about 2000 instances globally, see public Dashboard: dashboard.shadowserver.org/statistics/i... Top affected: US & Germany
172
The Shadowserver Foundation @shadowserver.bsky.social · 03/04/2026
We added Progress ShareFile fingerprinting to our scans & reports with 784 unique IPs seen exposed on 2026-04-02. watchTowr recently disclosed details behind an RCE CVE-2026-2699 & CVE-2026-2701 exploit chain affecting ShareFile. Make sure to apply the latest patch!
383
The Shadowserver Foundation @shadowserver.bsky.social · 01/04/2026
F5 BIG-IP APM CVE-2025-53521 impact has recently been updated from a DoS to RCE (see: my.f5.com/manage/s/art...) & added to CISA KEV. We are fingerprinting & sharing F5 BIG-IP APM instances - over 17.1K IPs seen on 2026-03-31 globally. This is just a population assessment.
192