#Shadowserver
CrowdStrike, Google, and the Shadowserver Foundation have dismantled the Glassworm botnet. The operation targeted a network specifically focused on compromising software developers globally rather than just end-user products.
June 20, 2026 at 5:51 PM
oh god what year is it has this all been a dream
Nearly 800,000 Telnet servers exposed to remote attacks
Internet security watchdog Shadowserver tracks nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical authentication bypass vulnerability in the GNU InetUtils ...
www.bleepingcomputer.com
January 26, 2026 at 10:57 PM
We’re excited to announce that CERT.LV (National CSIRT of Latvia) has joined the Shadowserver Alliance as a Bronze Tier Partner!

Together we will raise the bar on cybersecurity.
Read more about CERT.LV: cert.lv/en/

Become a Shadowserver Alliance partner today: www.shadowserver.org/partner/
May 12, 2025 at 1:00 PM
@piotrkijewski.bsky.social on Shadowserver & our unique non-profit approach to raising the bar on cybersecurity worldwide by sharing free threat intelligence, supporting LE in disrupting cybercrime & cybersecurity capacity building all around the planet!

www.helpnetsecurity.com/2024/12/05/p...
How the Shadowserver Foundation helps network defenders with free intelligence feeds - Help Net Security
The Shadowserver Foundation’s mission is to make the internet secure by exposing vulnerabilities, malicious activity, and emerging threats.
www.helpnetsecurity.com
December 6, 2024 at 8:30 AM
The folks at @Shadowserver seriously help #CyberCivilDefense #cybersecurity
Happy to collaborate with CIRCL on new EU ISF funded MISP-LEA project to establish a MISP instance dedicated to law enforcement agencies! Shadowserver will contribute ransomware & C2 infrastructure tracking to support LEA investigations.

More: https://www.misp-lea.org
Information Sharing for Law Enforcement
Empowering Law Enforcement Agencies with MISP: Enhancing Information Sharing and Investigation
www.misp-lea.org
July 11, 2023 at 11:38 AM
Shadowserver is a really big deal regarding #CyberCivilDefense #cybersecurity
We continue to report out daily lists of Citrix ADC/Gateway IPs that are known to be compromised with webshells installed (CVE-2023-3519 attacks). We now see 1486 instances on 2023-08-17. Big thank you to DIVD.nl and Fox-IT for the collaboration. Data in our Compromised Website report.
August 18, 2023 at 1:54 PM
Google, CrowdStrike, and Shadowserver take down the Glassworm C&C servers

www.crowdstrike.com/en-us/blog/i...
May 26, 2026 at 6:19 PM
Nonprofit security organization Shadowserver found that over 6,400 Apache ActiveMQ servers exposed online are vulnerable to ongoing attacks exploiting a high-severity code injection vulnerability.
Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
Nonprofit security organization Shadowserver found that over 6,400 Apache ActiveMQ servers exposed online are vulnerable to ongoing attacks exploiting a high-severity code injection vulnerability.
www.bleepingcomputer.com
April 21, 2026 at 11:18 AM
Shadowserver is excited to share its cybersecurity insights and actionable recommendations in a report aimed at helping ECOWAS stakeholders make West Africa more secure!

Read the report & accompanying fact sheets in English, French & Portuguese at www.shadowserver.org/news/shadows...
June 9, 2026 at 8:51 AM
New: About 100 victims of the Microsoft SharePoint hack so far, according to Eye Security and the Shadowserver Foundation:
www.reuters.com/sustainabili...
Microsoft server hack has hit about 100 victims, researcher says
A sweeping cyberespionage operation targeting Microsoft server software compromised about 100 different organizations as of the weekend, one of the researchers who helped uncover the campaign said Monday.
www.reuters.com
July 21, 2025 at 4:44 PM
This is a serious issue re #cybersecurity and #CyberCivilDefense, and the @Shadowserver folks really do help
Around 394 000 IPs with accessible BGP service on port 179/TCP found worldwide in our daily scans. These should have ACLs put in place to allow connections only from their BGP neighbors. Most found in China (109.3K) and the US (74.4K).
July 2, 2023 at 5:45 PM
Shadowserver tracks nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical authentication bypass vulnerability in the GNU InetUtils telnetd server.
Nearly 800,000 Telnet servers exposed to remote attacks
Shadowserver tracks nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical authentication bypass vulnerability in the GNU InetUtils telnetd server.
www.bleepingcomputer.com
January 26, 2026 at 3:19 PM
Interested in the Shadowserver Alliance? Details here - shadowserver.org/partner/
August 3, 2023 at 12:53 PM
Over 14,000 BIG-IP APM instances are exposed to ongoing attacks exploiting a critical-severity remote code execution (RCE) vulnerability, according to Internet security watchdog Shadowserver.
Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
Over 14,000 BIG-IP APM instances are exposed to ongoing attacks exploiting a critical-severity remote code execution (RCE) vulnerability, according to Internet security watchdog Shadowserver.
www.bleepingcomputer.com
April 2, 2026 at 8:26 AM
Nonprofit security organization Shadowserver has found over 6,000 SmarterMail servers exposed online and likely vulnerable to attacks exploiting a critical authentication bypass vulnerability.
Over 6,000 SmarterMail servers exposed to automated hijacking attacks
Nonprofit security organization Shadowserver has found over 6,000 SmarterMail servers exposed online and likely vulnerable to attacks exploiting a critical authentication bypass vulnerability.
www.bleepingcomputer.com
January 27, 2026 at 2:10 PM
The @Shadowserver folks set up traps to capture bad actors looking for easy targets
We are expanding our honeypot sensor feeds to include reporting of IPs scanning/exploiting Android Debug Bridge (ADB) services, a common target for botnets & other threat actors: shadowserver.org/what-we-do/n...

ADB attack tracker (~700 src IPs daily): dashboard.shadowserver.org/statistics/c...
January 4, 2024 at 11:25 AM
We apparently can't write stories like this fast enough
cyberscoop.com/ivanti-zero-...
February 10, 2026 at 6:44 PM
Shadowserver, a member of the Common Good Cyber secretariat, is proud to help launch the Common Good Cyber Fund announced today. Special thanks to the UK and Canada for investing in the Fund and continuing to provide their steadfast support.

commongoodcyber.org/news/common-...
June 24, 2025 at 6:31 AM
La policía europea ha desmantelado una red a gran escala de cibercriminales que tenían 50 millones de cuentas falsas para fraudes. Han detenido a 7 personas y se han incautado de 1.200 cajas de SIMs y 40.000 tarjetas, además de 5 servidores y 2 sitios web www.itnews.com.au/news/euro-co...
Euro cops take down cybercrime network with 49 million fake accounts
Collaboration between Europol and the Shadowserver Foundation.
www.itnews.com.au
October 25, 2025 at 2:51 PM
Shadowserver scans have identified 86 compromised instances, and researchers warn multiple threat groups are involved. via @mattkapko.com cyberscoop.com/ivanti-zero-...
Fallout from latest Ivanti zero-days spreads to nearly 100 victims
Shadowserver scans have identified 86 compromised instances, and researchers warn multiple threat groups are involved.
cyberscoop.com
February 10, 2026 at 12:35 AM
Interested in joining the Shadowserver Alliance? Read more here - shadowserver.org/partner/
October 16, 2023 at 7:46 AM
We’re excited to announce that the Canadian Centre for Cyber Security (CCCS) has increased its annual Shadowserver Alliance Partnership tier from Gold to Diamond! Thank you CCCS for your generous support and for being a valuable and trusted partner in making the Internet more secure.
April 14, 2026 at 3:05 PM
We’re excited to welcome KPN to the Shadowserver Alliance as a bronze tier partner!

KPN is a leading telecommunications and IT provider in the Netherlands. www.kpn.com/algemeen/eng...

Together we will raise the bar on cybersecurity to make the Internet more secure.
March 31, 2026 at 1:37 PM