Sign in

The Shadowserver Foundation

@shadowserver.bsky.social
5K followers 0 following 928 posts

Our mission is to make the Internet more secure by bringing to light vulnerabilities, malicious activity and emerging threats. Join our Alliance! shadowserver.org/partner

PostsRepliesMedia
The Shadowserver Foundation @shadowserver.bsky.social · 13/09/2026
For MikroTik with SSH enabled, check out our Accessible SSH reporting (shadowserver.org/what-we-do/n...), with the tag 'mikrotik' dashboard.shadowserver.org/statistics/c... - just over 119K seen daily currently
shadowserver.org
INFO: Accessible SSH Report | The Shadowserver Foundation
This report identifies hosts that have the Secure Shell (SSH) service running and accessible on the Internet.
021
The Shadowserver Foundation @shadowserver.bsky.social · 13/09/2026
Background: cert.pl/en/posts/202... #CyberCivilDefense
cert.pl
Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended
The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to...
110
The Shadowserver Foundation @shadowserver.bsky.social · 13/09/2026
These should not be publicly accessible on the Internet due to potential vulnerabilities, like CVE-2026-67277 nvd.nist.gov/vuln/detail/... You can find all our MikroTik detections in Device ID report www.shadowserver.org/what-we-do/n... (around 3M daily): dashboard.shadowserver.org/statistics/i...
nvd.nist.gov
NVD - Home
110
The Shadowserver Foundation @shadowserver.bsky.social · 13/09/2026
We have started reporting out (daily) MikroTik instances with exposed proprietary services, such as WinBox & Bandwidth Test server (btest): www.shadowserver.org/what-we-do/n... Around 2.6M exposed instances shared daily. Top: Brazil, Indonesia, USA Stats: dashboard.shadowserver.org/statistics/c...
183
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026
Background on incidents: www.huntress.com/blog/n-able-... #CyberCivilDefense
huntress.com
Critical N-able N-central Vulnerability and Active Exploitation | Huntress
UPDATE: Critical vulnerability in N-able N-central gives attackers unauthenticated, "god-mode" access to the RMM console.
000
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026
IP data in Vulnerable HTTP reporting tagged 'cve-2026-86218': www.shadowserver.org/what-we-do/n... 218 out of 1399 seen in total. This is one week after exploitation activity was first reported publicly. Patch info: documentation.n-able.com/N-central/Re...
shadowserver.org
CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
DESCRIPTION LAST UPDATED: 2026-09-11 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnera...
100
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026
Still 218 instances of N-able N-central seen unpatched to CVE-2026-86218 pre-auth RCE that is exploited in the wild & on US CISA KEV. Top: US (141) Stats - World Map view: dashboard.shadowserver.org/statistics/c... Tracker: dashboard.shadowserver.org/statistics/c...
132
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026
Compromised Website Report: www.shadowserver.org/what-we-do/n... Thank you to @greynoise.io for the share! Background with info about the AI-orchestrated campaign behind the compromises (includes IOCs): www.greynoise.io/blog/ai-orch...
shadowserver.org
CRITICAL: Compromised Website Report | The Shadowserver Foundation
This report is a list of all the websites we (or our collaborative partners) have been able to identify and verify to be compromised.
010
The Shadowserver Foundation @shadowserver.bsky.social · 12/09/2026
We shared a one-off share of over 400 compromised PaperCut NG/MF instances (via CVE-2026-81578/CVE-2026-82078) observed by @greynoise.io. IP data in our Compromised Website reporting for 2026-09-11, tagged 'papercut-compromise'. Dashboard Tree Map stats: dashboard.shadowserver.org/statistics/c...
153
The Shadowserver Foundation @shadowserver.bsky.social · 09/09/2026
Running an outdated Plex Media Server? Patch! Dashboard Tree Map view: dashboard.shadowserver.org/statistics/c...
dashboard.shadowserver.org
Tree map · General statistics · The Shadowserver Foundation
Development of the Shadowserver Dashboard was funded by the UK FCDO. IoT device fingerprinting statistics and honeypot attack statistics co-financed by the Connecting Europe Facility of the European Union (EU CEF VARIoT project).
000
The Shadowserver Foundation @shadowserver.bsky.social · 09/09/2026
No CVEs have been issued meaning the vulnerabilities are invisible to the security community limiting an effective response. We tag the raw IP data shared 'vulnerable-plex' in Vulnerable HTTP reporting: www.shadowserver.org/what-we-do/n... Tracker: dashboard.shadowserver.org/statistics/c...
shadowserver.org
CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
DESCRIPTION LAST UPDATED: 2026-09-09 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnera...
101
The Shadowserver Foundation @shadowserver.bsky.social · 09/09/2026
Since 2026-09-04 we are scanning/reporting daily unpatched versions of Plex Media Server in response to an advisory issued by Plex forums.plex.tv/t/important-... for v1.43.2 & earlier. Over 36K instances found still unpatched! Top affected: US World Map: dashboard.shadowserver.org/statistics/c...
1103
Reposted by The Shadowserver Foundation
The Shadowserver Foundation @shadowserver.bsky.social · 06/09/2026
We added MikroTik SSH identification to our daily scans on 2026-09-04, in response to MikroTik's patches mikrotik.com/supportsec/s.... As discovered by CERT Polska cert.pl/en/posts/202... unpatched MikroTiks can be compromised, if device supports remote access using SSH protocol
2137
The Shadowserver Foundation @shadowserver.bsky.social · 06/09/2026
Exploitation is reported in the wild. Review for compromise and patch!
000
The Shadowserver Foundation @shadowserver.bsky.social · 06/09/2026
At least 122,500 MikroTik devices with SSH accessible found per 24 hour scan window on 2026-09-05 (no vulnerability check). IP data shared daily in Accessible SSH reporting www.shadowserver.org/what-we-do/n... tagged 'mikrotik' & Device Identification reports: www.shadowserver.org/what-we-do/n...
shadowserver.org
INFO: Accessible SSH Report | The Shadowserver Foundation
This report identifies hosts that have the Secure Shell (SSH) service running and accessible on the Internet.
130
The Shadowserver Foundation @shadowserver.bsky.social · 06/09/2026
We added MikroTik SSH identification to our daily scans on 2026-09-04, in response to MikroTik's patches mikrotik.com/supportsec/s.... As discovered by CERT Polska cert.pl/en/posts/202... unpatched MikroTiks can be compromised, if device supports remote access using SSH protocol
2137
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026
Patch info: www.papercut.com/kb/Main/secu... Make sure to install Emergency Patch (Release 3) - but assume compromise. Background on PaperCut incidents: www.huntress.com/blog/papercu... Detection based on Nuclei template by darses - github.com/projectdisco... #CyberCivilDefense
papercut.com
URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)
Short description of what is in the security bulletin
000
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026
Daily IP data now in our Vulnerable HTTP reporting, tagged 'cve-2026-82078' & 'cve-2026-81578': www.shadowserver.org/what-we-do/n... Tree map view: dashboard.shadowserver.org/statistics/c... NVD entry: nvd.nist.gov/vuln/detail/... nvd.nist.gov/vuln/detail/...
shadowserver.org
CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
DESCRIPTION LAST UPDATED: 2026-08-31 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnera...
100
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026
PaperCut MF/NG incidents: At least 204 instances found on 2026-08-31 still vulnerable to CVE-2026-82078/CVE-2026-81578 RCE that is exploited in the wild. Make sure to check for compromise & patch. Top affected: US (60). Dashboard World Map view stats: dashboard.shadowserver.org/statistics/c...
110
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026
See also NCSC NL advisory: www.ncsc.nl/alerts/ernst...
ncsc.nl
Ernstige kwetsbaarheden in Microsoft Exchange Server | NCSC
Er zijn meerdere ernstige kwetsbaarheden gevonden in Microsoft Exchange Server. Een van deze kwetsbaarheden is CVE-2026-62911, met een CVSS-score van 8.0. Voor deze kwetsbaarheid is exploitcode online...
000
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026
Dashboard World Map view stats: dashboard.shadowserver.org/statistics/c... Dashboard Tree Map stats: dashboard.shadowserver.org/statistics/c... NVD entry: nvd.nist.gov/vuln/detail/... MS advisory: msrc.microsoft.com/update-guide... Daily IP data tagged 'cve-2026-62911'
dashboard.shadowserver.org
World map · General statistics · The Shadowserver Foundation
Development of the Shadowserver Dashboard was funded by the UK FCDO. IoT device fingerprinting statistics and honeypot attack statistics co-financed by the Connecting Europe Facility of the European Union (EU CEF VARIoT project).
100
The Shadowserver Foundation @shadowserver.bsky.social · 01/09/2026
We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: www.shadowserver.org/what-we-do/n... At least 21899 IPs seen unpatched 2026-08-31, top US (6.2K) & Germany (5.1K)
153
Reposted by The Shadowserver Foundation
Craig Newmark @craignewmark.bsky.social · 24/08/2026
@shadowserver.bsky.social seriously helps protect us all
0173
The Shadowserver Foundation @shadowserver.bsky.social · 28/08/2026
IP data shared in Vulnerable HTTP reporting tagged 'cve-2026-60004': www.shadowserver.org/what-we-do/n... Patch Tracker: dashboard.shadowserver.org/statistics/c... Exploit code is public. Gitea advisory: blog.gitea.com/release-of-1... NVD entry: nvd.nist.gov/vuln/detail/... #CyberCivilDefense
shadowserver.org
CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
DESCRIPTION LAST UPDATED: 2026-08-26 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnera...
010
The Shadowserver Foundation @shadowserver.bsky.social · 28/08/2026
We are scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (code injection), with 8393 IPs found vulnerable on 2026-08-27. This vulnerability is exploited in the wild and on US CISA KEV. Top affected: China, Germany, US Dashboard view: dashboard.shadowserver.org/statistics/c...
174
The Shadowserver Foundation @shadowserver.bsky.social · 24/08/2026
#CyberCivilDefense
020
The Shadowserver Foundation @shadowserver.bsky.social · 24/08/2026
We also see at least 8200 CVE-2026-73570 unpatched instances (this does not mean exploitable as the vuln is in a non default config) dashboard.shadowserver.org/statistics/c... Check for compromise & update: wiki.zimbra.com/wiki/Zimbra_... CVE-2026-73570 is on CISA KEV www.cisa.gov/known-exploi...
dashboard.shadowserver.org
Tree map · General statistics · The Shadowserver Foundation
Development of the Shadowserver Dashboard was funded by the UK FCDO. IoT device fingerprinting statistics and honeypot attack statistics co-financed by the Connecting Europe Facility of the European Union (EU CEF VARIoT project).
120
The Shadowserver Foundation @shadowserver.bsky.social · 24/08/2026
Data in Compromised Website reporting tagged 'zimbra-compromised' with detail set to 'Artifact from probable CVE-2026-73570 compromise' www.shadowserver.org/what-we-do/n... Compromised Zimbra tracker: dashboard.shadowserver.org/statistics/c...
shadowserver.org
CRITICAL: Compromised Website Report | The Shadowserver Foundation
This report is a list of all the websites we (or our collaborative partners) have been able to identify and verify to be compromised.
110
The Shadowserver Foundation @shadowserver.bsky.social · 24/08/2026
Alert! Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22. Top: US (41 IPs). Detection in collaboration with @CERT_Polska_en Public Dashboard: dashboard.shadowserver.org/statistics/c...
1103
The Shadowserver Foundation @shadowserver.bsky.social · 17/08/2026
IP data in our Device ID reporting (exposure, not vulnerability check): www.shadowserver.org/what-we-do/n... Public POC available and being used. Check for compromise and patch.
shadowserver.org
INFO: Device Identification Report | The Shadowserver Foundation
DESCRIPTION LAST UPDATED: 2023-12-06 DEFAULT SEVERITY LEVEL: INFO This report contains a list of devices we have identified in our daily Internet scans. The assessment is made based on all our Interne...
000
The Shadowserver Foundation @shadowserver.bsky.social · 17/08/2026
RondoDox botnet now also trying to exploit the new GeoServer 0-day, as seen in our sensors. We see over 1500 exposed instances worldwide (exposed population, not a vulnerability check). Patch info: geoserver.org/announcement... Tree Map Dashboard stats: dashboard.shadowserver.org/statistics/i...
152
The Shadowserver Foundation @shadowserver.bsky.social · 16/08/2026
IP Data in our Vulnerable HTTP reporting tagged 'cve-2026-72898' : www.shadowserver.org/what-we-do/n... (since 2026-08-11) NVD entry: nvd.nist.gov/vuln/detail/... Metabase advisory & patch info: github.com/metabase/met...
shadowserver.org
CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
DESCRIPTION LAST UPDATED: 2026-08-14 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnera...
000
The Shadowserver Foundation @shadowserver.bsky.social · 16/08/2026
We are also scanning & reporting Metabase IPs likely unpatched to CVE-2026-72898 SQLi, which is exploited in the wild & on @CISACyber KEV. 2171 unpatched (version check) instances seen 2026-08-15. Top: US (603), Germany (278) Dashboard World Map stats: dashboard.shadowserver.org/statistics/c...
120
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
Vulnerable HTTP Report: www.shadowserver.org/what-we-do/n...
shadowserver.org
CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
DESCRIPTION LAST UPDATED: 2026-08-14 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnera...
000
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
This vulnerability is known to be exploited in the wild and on CISACyber KEV www.cisa.gov/known-exploi... F5 Advisory: my.f5.com/manage/s/art... Check your reports for IPs tagged 'cve-2025-53521'! Public Dashboard World Map: dashboard.shadowserver.org/statistics/c...
cisa.gov
Known Exploited Vulnerabilities Catalog | CISA
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative so...
100
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
We are scanning & reporting F5 BIG-IP APM CVE-2025-53521 instances thanks to collaboration with the NCSC-NL SRT. 10 months after vuln disclosure, we still see over 850 IPs vulnerable to potential RCE. Top affected: US with 199 & Japan 182. IP data in Vulnerable HTTP reporting.
151
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
You can also track CVE-2026-59310 & CVE-2026-59309 vulnerable VMware vCenter instances in our daily Vulnerable HTTP reporting since July 30th: shadowserver.org/what-we-do/n... Tracker: dashboard.shadowserver.org/statistics/c... World Map: dashboard.shadowserver.org/statistics/c...
063
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
#CyberCivilDefense
010
The Shadowserver Foundation @shadowserver.bsky.social · 14/08/2026
Thanks to collaboration with QUIRSO GmbH we are sharing the VMware vCenter CVE-2026-59310 Exploitation Victim Special Report shadowserver.org/what-we-do/n... Check compromised IPs for your network/constituency & remediate! File prefix: 2026-08-13-special See: medium.com/@quirso_de/a...
142
The Shadowserver Foundation @shadowserver.bsky.social · 13/08/2026
#CyberCivilDefense
000
The Shadowserver Foundation @shadowserver.bsky.social · 13/08/2026
Dysphoria targets IoT devices and its primary function appears to be for use in DDoS-attacks. Recently the botnet has gotten residential proxy functionality. More details on Dysphoria at blog.xlab.qianxin.com/dysphoria/
blog.xlab.qianxin.com
僵尸网络新秀:Dysphoria 演进与深度技术分析
本报告由国家互联网应急中心(CNCERT)与奇安信网神信息技术(北京)股份有限公司共同发布 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。该家族在短短几个月内经历了频繁的变种更新与技术迭代,展现出极强的生命力。其演进路径不仅横跨了 jackskid、fbot变种,更在近期引入了基于区块链 ENS/SNS 域名的 C2 ...
100
The Shadowserver Foundation @shadowserver.bsky.social · 13/08/2026
We shared a Dysphoria Botnet Special Report on 2026-08-12 with over 296,000 devices compromised globally: shadowserver.org/what-we-do/n... Check reports with the 2026-08-12-special prefix for your network or constituency. Dashboard stats: dashboard.shadowserver.org/statistics/c...
163
The Shadowserver Foundation @shadowserver.bsky.social · 05/08/2026
Excited to announce our Central and Eastern Europe (CEE) Critical Community Infrastructure (CCI) Project, focused on improving the #cybersecurity of essential public-serving organizations (made possible with support from Google.org) Find out more: www.shadowserver.org/news/shadows...
052
The Shadowserver Foundation @shadowserver.bsky.social · 24/07/2026
MS Advisories: msrc.microsoft.com/update-guide... msrc.microsoft.com/update-guide... msrc.microsoft.com/update-guide... #CyberCivilDefense
msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
000
The Shadowserver Foundation @shadowserver.bsky.social · 24/07/2026
Data for these is shared in Vulnerable HTTP reporting with appropriate CVE tags: shadowserver.org/what-we-do/n... Dashboard World Map: dashboard.shadowserver.org/statistics/c... Dashboard Tree Map: dashboard.shadowserver.org/statistics/c... Tracker: dashboard.shadowserver.org/statistics/c...
shadowserver.org
CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
DESCRIPTION LAST UPDATED: 2026-07-23 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnera...
100
The Shadowserver Foundation @shadowserver.bsky.social · 24/07/2026
Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to US CISA Known Exploited Vulnerability (KEV) catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23
142
The Shadowserver Foundation @shadowserver.bsky.social · 21/07/2026
Join the Alliance and become part of the community: www.shadowserver.org/partner/
shadowserver.org
Become a Partner | The Shadowserver Foundation
Shadowserver doesn’t sell data or services. We’re a team of altruists, funded entirely by those who share our vision of a more secure Internet. Join us.
010
The Shadowserver Foundation @shadowserver.bsky.social · 21/07/2026
We’re excited to welcome Backblaze to the Shadowserver Alliance as a Bronze Tier Partner! Backblaze is a premier, high-performance cloud storage platform. www.backblaze.com With our Alliance Partners, we’ll make the Internet more secure and raise the bar on cybersecurity.
backblaze.com
Home
Backblaze is a pioneer in robust, scalable low cost cloud backup and storage services. Enterprise hot storage, low cost backup and archive, and more.
182
The Shadowserver Foundation @shadowserver.bsky.social · 21/07/2026
oin the Alliance and become part of the community: www.shadowserver.org/partner/
shadowserver.org
Become a Partner | The Shadowserver Foundation
Shadowserver doesn’t sell data or services. We’re a team of altruists, funded entirely by those who share our vision of a more secure Internet. Join us.
000
The Shadowserver Foundation @shadowserver.bsky.social · 03/07/2026
Thank you to our anonymous partner for the contribution!
010