Excited to announce our Central and Eastern Europe (CEE) Critical Community Infrastructure (CCI) Project, focused on improving the #cybersecurity of essential public-serving organizations (made possible with support from Google.org) Find out more: www.shadowserver.org/news/shadows...
The Shadowserver Foundation
@shadowserver.bsky.social
Our mission is to make the Internet more secure by bringing to light vulnerabilities, malicious activity and emerging threats. Join our Alliance! https://shadowserver.org/partner
Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to US CISA Known Exploited Vulnerability (KEV) catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23
We’re excited to welcome Backblaze to the Shadowserver Alliance as a Bronze Tier Partner! Backblaze is a premier, high-performance cloud storage platform. www.backblaze.com With our Alliance Partners, we’ll make the Internet more secure and raise the bar on cybersecurity.
Home
Backblaze is a pioneer in robust, scalable low cost cloud backup and storage services. Enterprise hot storage, low cost backup and archive, and more.
backblaze.com
We shared out ~2000 unique IPs exposing secrets that are known to have been harvested by a threat actor. IP data in our Compromised Website report: shadowserver.org/what-we-do/n... for your network/constituency with the 'stolen-key' tag (dated 2026-07-02). Check your reports!
SimpleHelp CVE-2026-48558 is now confirmed exploited-in-the-wild & on US CISA KEV www.cisa.gov/known-exploi... We are scanning for CVE-2026-48558 vulnerable instances since 2026-06-16. We see 439 unpatched (2026-07-01 scan) Dashboard World Map view: dashboard.shadowserver.org/statistics/c...
We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with Validin. Around 950 exposed instances now seen globally (no vulnerability assessment). CVE-2026-46817 attempts have been observed in the wild by DefusedCyber.
Yesterday we reported out an additional dataset found on the #Fortibleed threat actors systems in a one-off special report - www.shadowserver.org/what-we-do/n.... The data was shared with us by SpyCloud (spycloud.com) & covers 35000 new IPs not previously reported.
More Operation Endgame #cybercrime disruption success this week, with a new one-off StealC Historical Bot Special Report run overnight (2026-06-24), continuing our support for international LE partners: shadowserver.org/news/stealc-...
Last week we added scanning for Joomla JCE editor extension CVE-2026-48907 vulnerable instances. This RCE vulnerability is exploited in the wild & on US CISA KEV. 4840 vulnerable instances seen 2026-06-22 down from 5146 on 2026-06-19. Top affected: US dashboard.shadowserver.org/statistics/c...
We shared a one-off "FortiBleed" dataset of compromised Fortinet devices in our Compromised Website Report www.shadowserver.org/what-we-do/n... thanks to collaboration with SOCRadar! Stats: Dashboard World map view: dashboard.shadowserver.org/statistics/c...
New one-off SocGholish Compromised #WordPress Sites Special Report run today, in continued support of international LE partners in Operation Endgame #cybercrime disruption: shadowserver.org/news/socghol... Great work once again everyone involved!
Happy to once again support LE partners in disruption of the AudiA6 service, allegedly responsible for $389 million USD in cryptocurrency money laundering: justice.gov/usao-edpa/pr... secretservice.gov/newsroom/rel... www.europol.europa.eu/media-press/...
Heads up! New report going out daily: the Initial Access Broker Report shadowserver.org/what-we-do/n... on compromised hosts likely under control of IABs Data thanks to collaboration with anonymous researchers & SpyCloud - thank you! Check your free daily reports from us!
We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today. We see 19 vulnerable instances in our own scans, with at least 2 backdoored (thanks to Saudi NCA for the tip!). However, all remaining likely compromised too.
Shadowserver is excited to share its cybersecurity insights and actionable recommendations in a report aimed at helping ECOWAS stakeholders make West Africa more secure! Read the report & accompanying fact sheets in English, French & Portuguese at www.shadowserver.org/news/shadows...
We added scanning of Automatic Tank Gauge (ATG) systems to our Accessible ICS reporting with 1061 IPs seen on 2026-06-05 (on port 10001/tcp). This is after weeding out vast majority which appear to be honeypots (including ports 8001/9001). Vast majority exposed are in the US.
Very happy to support CrowdStrike and Google in the disruption of the Glassworm botnet, which features 4x C2 channels, and targets developers via open-source supply chains: www.crowdstrike.com/en-us/blog/i...
Thank you Fabrice Guye (ELCASecurity), Sarah Reynolds (Dataminr), @piotrkijewski.bsky.social (@shadowserver.bsky.social ), Prerit Pathak (Google), Alison Brogan (@scvo.scot ), and @amira.bsky.social (@aspeninstitute.bsky.social). Read more about our takeaways here: shorturl.at/Hb0nX
Protect.NGO’26: Protecting the Nonprofits Defending our Communities | CyberPeace Institute
At the Protect.NGO’26 event taking place on 6 May 2026 in Geneva, +100 leaders and volunteers from governments, philanthropy, civil society, and the private sector gathered around a shared ideal: […]
shorturl.at
We published a "Shadowserver-in-a-box" platform based on IntelMQ + ELK that can ingest, process and visualize our threat/vulnerability/victim data feeds. Available as a VM or Docker image for free download. Use it for training or in production! Check it out here: github.com/The-Shadowse...
We are scanning & reporting daily Wazuh CVE-2026-30893 (CVSS 9.9) vulnerable instances, with over 3500 IPs seen unpatched on 2026-05-10. See advisory & update to latest version: github.com/wazuh/wazuh/... ... Worth keeping your security platforms up to date!
We are tagging CVE-2026-6973 Ivanti EPMM instances seen in our daily scans. 362 IPs seen unpatched on 2026-05-10, down from 562 IPs on 2026-05-08 when we first added the detection. See Ivanti advisory for details - hub.ivanti.com/s/article/Ma... CVE-2026-6973 is on US CISA KEV.
Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: support.cpanel.net/hc/en-us/art... Public Dashboard stats: dashboard.shadowserver.org/statistics/h...
Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: support.cpanel.net/hc/en-us/art... Public Dashboard stats: dashboard.shadowserver.org/statistics/h...
We are scanning/reporting daily Zimbra Collaboration Suite instances vulnerable to CVE-2025-48700, that can allow unauthorized access to sensitive information. This vulnerability is exploited in the wild and on US CISA KEV. We see over 10.5K IPs unpatched 2026-04-23.
We are also scanning & reporting Microsoft SharePoint CVE-2026-32201 (Improper input validation in SharePoint allows an unauthorized attacker to perform spoofing over a network). This vulnerability is known exploited in the wild & on US CISA KEV list. 1370 IPs seen unpatched. Top: US
Thank you to Precursor Security for becoming a Shadowserver Alliance Silver Tier Partner! Precursor Security delivers pen testing, 24/7 managed SOC, and more. www.precursorsecurity.com Together with our Alliance Partner community, we’ll make the Internet more secure.
We are now scanning daily for CVE-2026-34197 (Apache ActiveMQ Improper Input Validation Vulnerability) which has recently been added to US CISA KEV. 6364 IPs seen vulnerable on 2026-04-19 based on a version check. Dashboard Tree Map view: dashboard.shadowserver.org/statistics/c...
We added CVE-2026-35616 scans based on the vulnerability detector developed by Bishop Fox bishopfox.com/blog/api-aut.... Over 60 IPs still assessed as vulnerable: dashboard.shadowserver.org/statistics/c... Data shared daily in our Vulnerable HTTP reporting: shadowserver.org/what-we-do/n...
Heads up FortiClient EMS users! CVE-2026-35616 (new) & CVE-2026-21643 - both unauthenticated RCE observed to be exploited in the wild! We fingerprint about 2000 instances globally, see public Dashboard: dashboard.shadowserver.org/statistics/i... Top affected: US & Germany
We’re excited to announce that the Canadian Centre for Cyber Security (CCCS) has increased its annual Shadowserver Alliance Partnership tier from Gold to Diamond! Thank you CCCS for your generous support and for being a valuable and trusted partner in making the Internet more secure.
We have also added CVE-2026-2699 tagging to our scans, which now detect unpatched Progress ShareFile instances. 120 seen 2026-04-06 dashboard.shadowserver.org/statistics/c... Tree Map view: dashboard.shadowserver.org/statistics/c... IP data in Vulnerable HTTP: www.shadowserver.org/what-we-do/n...
We added Progress ShareFile fingerprinting to our scans & reports with 784 unique IPs seen exposed on 2026-04-02. watchTowr recently disclosed details behind an RCE CVE-2026-2699 & CVE-2026-2701 exploit chain affecting ShareFile. Make sure to apply the latest patch!