The Shadowserver Foundation
shadowserver.bsky.social
The Shadowserver Foundation
@shadowserver.bsky.social
Our mission is to make the Internet more secure by bringing to light vulnerabilities, malicious activity and emerging threats. Join our Alliance!
https://shadowserver.org/partner
Pinned
Using ELK & interested in automating ingestion of our threat intel for your network/constituency via our API?

We have introduced an ECS logging script for our intelligence reports. This script uses Redis to queue events for Logstash.

Check it out at github.com/The-Shadowse...
We have started reporting out (daily) MikroTik instances with exposed proprietary services, such as WinBox & Bandwidth Test server (btest): www.shadowserver.org/what-we-do/n...

Around 2.6M exposed instances shared daily. Top: Brazil, Indonesia, USA

Stats: dashboard.shadowserver.org/statistics/c...
September 13, 2026 at 4:51 PM
Still 218 instances of N-able N-central seen unpatched to CVE-2026-86218 pre-auth RCE that is exploited in the wild & on US CISA KEV. Top: US (141)

Stats - World Map view: dashboard.shadowserver.org/statistics/c...

Tracker: dashboard.shadowserver.org/statistics/c...
September 12, 2026 at 7:03 PM
We shared a one-off share of over 400 compromised PaperCut NG/MF instances (via CVE-2026-81578/CVE-2026-82078) observed by @greynoise.io. IP data in our Compromised Website reporting for 2026-09-11, tagged 'papercut-compromise'.

Dashboard Tree Map stats: dashboard.shadowserver.org/statistics/c...
September 12, 2026 at 4:03 PM
Since 2026-09-04 we are scanning/reporting daily unpatched versions of Plex Media Server in response to an advisory issued by Plex forums.plex.tv/t/important-... for v1.43.2 & earlier. Over 36K instances found still unpatched! Top affected: US

World Map: dashboard.shadowserver.org/statistics/c...
September 9, 2026 at 8:14 AM
Reposted by The Shadowserver Foundation
We added MikroTik SSH identification to our daily scans on 2026-09-04, in response to MikroTik's patches mikrotik.com/supportsec/s.... As discovered by CERT Polska cert.pl/en/posts/202... unpatched MikroTiks can be compromised, if device supports remote access using SSH protocol
September 6, 2026 at 7:16 PM
We added MikroTik SSH identification to our daily scans on 2026-09-04, in response to MikroTik's patches mikrotik.com/supportsec/s.... As discovered by CERT Polska cert.pl/en/posts/202... unpatched MikroTiks can be compromised, if device supports remote access using SSH protocol
September 6, 2026 at 7:16 PM
PaperCut MF/NG incidents: At least 204 instances found on 2026-08-31 still vulnerable to CVE-2026-82078/CVE-2026-81578 RCE that is exploited in the wild. Make sure to check for compromise & patch. Top affected: US (60).

Dashboard World Map view stats: dashboard.shadowserver.org/statistics/c...
September 1, 2026 at 8:08 PM
We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: www.shadowserver.org/what-we-do/n...

At least 21899 IPs seen unpatched 2026-08-31, top US (6.2K) & Germany (5.1K)
September 1, 2026 at 10:44 AM
Reposted by The Shadowserver Foundation
@shadowserver.bsky.social seriously helps protect us all
Alert! Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22. Top: US (41 IPs). Detection in collaboration with @CERT_Polska_en

Public Dashboard: dashboard.shadowserver.org/statistics/c...
August 24, 2026 at 11:17 AM
We are scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (code injection), with 8393 IPs found vulnerable on 2026-08-27. This vulnerability is exploited in the wild and on US CISA KEV. Top affected: China, Germany, US

Dashboard view:
dashboard.shadowserver.org/statistics/c...
August 28, 2026 at 11:54 AM
Alert! Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22. Top: US (41 IPs). Detection in collaboration with @CERT_Polska_en

Public Dashboard: dashboard.shadowserver.org/statistics/c...
August 24, 2026 at 10:42 AM
RondoDox botnet now also trying to exploit the new GeoServer 0-day, as seen in our sensors. We see over 1500 exposed instances worldwide (exposed population, not a vulnerability check). Patch info: geoserver.org/announcement...

Tree Map Dashboard stats: dashboard.shadowserver.org/statistics/i...
August 17, 2026 at 5:14 PM
We are also scanning & reporting Metabase IPs likely unpatched to CVE-2026-72898 SQLi, which is exploited in the wild & on @CISACyber KEV. 2171 unpatched (version check) instances seen 2026-08-15. Top: US (603), Germany (278)

Dashboard World Map stats: dashboard.shadowserver.org/statistics/c...
August 16, 2026 at 8:30 PM
We are scanning & reporting F5 BIG-IP APM CVE-2025-53521 instances thanks to collaboration with the NCSC-NL SRT. 10 months after vuln disclosure, we still see over 850 IPs vulnerable to potential RCE. Top affected: US with 199 & Japan 182. IP data in Vulnerable HTTP reporting.
August 14, 2026 at 1:10 PM
You can also track CVE-2026-59310 & CVE-2026-59309 vulnerable VMware vCenter instances in our daily Vulnerable HTTP reporting since July 30th: shadowserver.org/what-we-do/n...

Tracker: dashboard.shadowserver.org/statistics/c...

World Map: dashboard.shadowserver.org/statistics/c...
August 14, 2026 at 10:38 AM
Thanks to collaboration with QUIRSO GmbH we are sharing the VMware vCenter CVE-2026-59310 Exploitation Victim Special Report shadowserver.org/what-we-do/n...

Check compromised IPs for your network/constituency & remediate! File prefix: 2026-08-13-special

See: medium.com/@quirso_de/a...
August 14, 2026 at 9:39 AM
We shared a Dysphoria Botnet Special Report on 2026-08-12 with over 296,000 devices compromised globally: shadowserver.org/what-we-do/n...

Check reports with the 2026-08-12-special prefix for your network or constituency.

Dashboard stats: dashboard.shadowserver.org/statistics/c...
August 13, 2026 at 6:32 PM
Excited to announce our Central and Eastern Europe (CEE) Critical Community Infrastructure (CCI) Project, focused on improving the #cybersecurity of essential public-serving organizations (made possible with support from
Google.org)

Find out more:
www.shadowserver.org/news/shadows...
August 5, 2026 at 9:26 AM
Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to US CISA Known Exploited Vulnerability (KEV) catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23
July 24, 2026 at 4:48 PM
We’re excited to welcome Backblaze to the Shadowserver Alliance as a Bronze Tier Partner!

Backblaze is a premier, high-performance cloud storage platform. www.backblaze.com

With our Alliance Partners, we’ll make the Internet more secure and raise the bar on cybersecurity.
Home
Backblaze is a pioneer in robust, scalable low cost cloud backup and storage services. Enterprise hot storage, low cost backup and archive, and more.
www.backblaze.com
July 21, 2026 at 1:46 PM
We shared out ~2000 unique IPs exposing secrets that are known to have been harvested by a threat actor. IP data in our Compromised Website report: shadowserver.org/what-we-do/n... for your network/constituency with the 'stolen-key' tag (dated 2026-07-02). Check your reports!
July 3, 2026 at 6:35 PM
SimpleHelp CVE-2026-48558 is now confirmed exploited-in-the-wild & on US CISA KEV
www.cisa.gov/known-exploi...

We are scanning for CVE-2026-48558 vulnerable instances since 2026-06-16. We see 439 unpatched (2026-07-01 scan)

Dashboard World Map view: dashboard.shadowserver.org/statistics/c...
July 2, 2026 at 9:34 AM
We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with Validin. Around 950 exposed instances now seen globally (no vulnerability assessment). CVE-2026-46817 attempts have been observed in the wild by DefusedCyber.
July 1, 2026 at 10:41 AM
Yesterday we reported out an additional dataset found on the #Fortibleed threat actors systems in a one-off special report - www.shadowserver.org/what-we-do/n.... The data was shared with us by SpyCloud (spycloud.com) & covers 35000 new IPs not previously reported.
June 27, 2026 at 5:31 PM
More Operation Endgame #cybercrime disruption success this week, with a new one-off StealC Historical Bot Special Report run overnight (2026-06-24), continuing our support for international LE partners:

shadowserver.org/news/stealc-...
June 25, 2026 at 12:03 PM