https://shadowserver.org/partner
86M stolen data items from 525K victim IPs across 226 countries included in our new Rhadamanthys Historic Bot Victims Special Report, run overnight 2025-11-12
More details:
shadowserver.org/news/rhadama...
86M stolen data items from 525K victim IPs across 226 countries included in our new Rhadamanthys Historic Bot Victims Special Report, run overnight 2025-11-12
More details:
shadowserver.org/news/rhadama...
The Australian Signals Directorate (ASD) recently published an advisory on the BadCandy implant still present in many Cisco IOS XE devices: www.cyber.gov.au/about-us/vie...
We still see around 15 000 Cisco IOS XE devices with the implant
The Australian Signals Directorate (ASD) recently published an advisory on the BadCandy implant still present in many Cisco IOS XE devices: www.cyber.gov.au/about-us/vie...
We still see around 15 000 Cisco IOS XE devices with the implant
We found nearly 8898 unpatched DNS open resolvers on 2025-10-30, down to 6653 on 2025-11-01: dashboard.shadowserver.org/statistics/c...
We found nearly 8898 unpatched DNS open resolvers on 2025-10-30, down to 6653 on 2025-11-01: dashboard.shadowserver.org/statistics/c...
Top affected: US with 23.2K instances
Top affected: US with 23.2K instances
Operation SIMCARTEL
Great work everyone involved 👏
europol.europa.eu/media-press/...
Operation SIMCARTEL
Great work everyone involved 👏
europol.europa.eu/media-press/...
We are sharing daily IP data on F5 exposures in our Device ID www.shadowserver.org/what-we-do/n... (device_vendor set to F5).
~269K IPs seen daily, nearly half in US.
Geo breakdown: dashboard.shadowserver.org/statistics/i...
We are sharing daily IP data on F5 exposures in our Device ID www.shadowserver.org/what-we-do/n... (device_vendor set to F5).
~269K IPs seen daily, nearly half in US.
Geo breakdown: dashboard.shadowserver.org/statistics/i...
IP data in www.shadowserver.org/what-we-do/n...
World map view of likely vulnerable instances: dashboard.shadowserver.org/statistics/c...
IP data in www.shadowserver.org/what-we-do/n...
World map view of likely vulnerable instances: dashboard.shadowserver.org/statistics/c...
Around ~45K vulnerable seen on 2025-10-04
Around ~45K vulnerable seen on 2025-10-04
Cisco advisories with patch info:
CVE-2025-20333: sec.cloudapps.cisco.com/security/cen...
CVE-2025-20362:
sec.cloudapps.cisco.com/security/cen...
Cisco advisories with patch info:
CVE-2025-20333: sec.cloudapps.cisco.com/security/cen...
CVE-2025-20362:
sec.cloudapps.cisco.com/security/cen...
Cisco ASA/FTD CVE-2025-20333 & CVE-2025-20362 incidents: we are now sharing daily vulnerable Cisco ASA/FTD instances in Vulnerable HTTP reports: www.shadowserver.org/what-we-do/n...
Over 48.8K unpatched IPs found 2025-09-29. Top affected: US
dashboard.shadowserver.org/statistics/c...
Cisco ASA/FTD CVE-2025-20333 & CVE-2025-20362 incidents: we are now sharing daily vulnerable Cisco ASA/FTD instances in Vulnerable HTTP reports: www.shadowserver.org/what-we-do/n...
Over 48.8K unpatched IPs found 2025-09-29. Top affected: US
dashboard.shadowserver.org/statistics/c...
World map distribution of IPs:
dashboard.shadowserver.org/statistics/c...
Tree map view: dashboard.shadowserver.org/statistics/c...
Tracker:
dashboard.shadowserver.org/statistics/c...
#CyberCivilDefense
World map distribution of IPs:
dashboard.shadowserver.org/statistics/c...
Tree map view: dashboard.shadowserver.org/statistics/c...
Tracker:
dashboard.shadowserver.org/statistics/c...
#CyberCivilDefense
It identifies the use of known or very weak cryptographic secrets across a variety of web frameworks/platforms. 12168 IPs seen (2025-09-14) using "bad" secrets!
It identifies the use of known or very weak cryptographic secrets across a variety of web frameworks/platforms. 12168 IPs seen (2025-09-14) using "bad" secrets!
Dashboard links:
Vulnerable (unpatched): dashboard.shadowserver.org/statistics/c...
Compromised:
dashboard.shadowserver.org/statistics/c...
Dashboard links:
Vulnerable (unpatched): dashboard.shadowserver.org/statistics/c...
Compromised:
dashboard.shadowserver.org/statistics/c...
dashboard.shadowserver.org/statistics/c...
dashboard.shadowserver.org/statistics/c...
Down from 28.2K to 12.4K. Europe patching at faster rate than North America
(toggle overlapping/stacked time series on our Dashboard to compare)
dashboard.shadowserver.org/statistics/c...
dashboard.shadowserver.org/statistics/c...
Down from 28.2K to 12.4K. Europe patching at faster rate than North America
(toggle overlapping/stacked time series on our Dashboard to compare)
Patch info: support.citrix.com/support-home...
Top affected: US, Germany
Dashboard geo breakdown: dashboard.shadowserver.org/statistics/c...
Patch info: support.citrix.com/support-home...
Top affected: US, Germany
Dashboard geo breakdown: dashboard.shadowserver.org/statistics/c...
Report format: www.shadowserver.org/what-we-do/n...
Dashboard World map: dashboard.shadowserver.org/statistics/c...
Report format: www.shadowserver.org/what-we-do/n...
Dashboard World map: dashboard.shadowserver.org/statistics/c...
IP data on these scans shared in www.shadowserver.org/what-we-do/n...
IP data on these scans shared in www.shadowserver.org/what-we-do/n...
Dashboard tree map: dashboard.shadowserver.org/statistics/c...
If you receive an alert from us review for signs of compromise & patch
Dashboard tree map: dashboard.shadowserver.org/statistics/c...
If you receive an alert from us review for signs of compromise & patch
Top affected: US, Canada, Netherlands, UK
Dashboard map view: dashboard.shadowserver.org/statistics/c...
Top affected: US, Canada, Netherlands, UK
Dashboard map view: dashboard.shadowserver.org/statistics/c...
The Dutch NCSC has recently released an update related to CVE-2025-6543 activity: www.ncsc.nl/actueel/nieu...
The Dutch NCSC has recently released an update related to CVE-2025-6543 activity: www.ncsc.nl/actueel/nieu...
Top affected: France, China, US, Germany
Top affected: France, China, US, Germany
Over 28K IPs unpatched (2025-08-07). Top affected: US, Germany, Russia
Dashboard world map: dashboard.shadowserver.org/statistics/c...
Over 28K IPs unpatched (2025-08-07). Top affected: US, Germany, Russia
Dashboard world map: dashboard.shadowserver.org/statistics/c...
Top affected: US, Japan, Germany
Dashboard map: dashboard.shadowserver.org/statistics/c...
NVD entry: nvd.nist.gov/vuln/detail/...
Top affected: US, Japan, Germany
Dashboard map: dashboard.shadowserver.org/statistics/c...
NVD entry: nvd.nist.gov/vuln/detail/...