Our mission is to make the Internet more secure by bringing to light vulnerabilities, malicious activity and emerging threats. Join our Alliance!shadowserver.org/partner GlobalJoined March 2009
We have started reporting out (daily) MikroTik instances with exposed proprietary services, such as WinBox & Bandwidth Test server (btest): shadowserver.org/what-we-do/net…
Around 2.6M exposed instances shared daily. Top: Brazil, Indonesia, USA.
Tree map stats: dashboard.shadowserver.org/statistics/com…
We shared a one-off share of over 400 compromised PaperCut NG/MF instances (via CVE-2026-81578/CVE-2026-82078) observed by @GreyNoiseIO. IP data in our Compromised Website reporting for 2026-09-11, tagged 'papercut-compromise'.
Dashboard Tree Map stats: dashboard.shadowserver.org/statistics/com…
@onyphe@BleepinComputer Yes, looks like we undercounted due to a bug - we already shared out more complete results for the day and will have full results going forwards which will be similar to the numbers you mentioned
No CVEs have been issued meaning the vulnerabilities are essentially invisible to the security community limiting an effective response.
We tag the raw IP data shared 'vulnerable-plex' in Vulnerable HTTP reporting: shadowserver.org/what-we-do/net…
Tracker: dashboard.shadowserver.org/statistics/com…
Since 2026-09-04 we are scanning/reporting daily unpatched versions of Plex Media Server in response to an advisory issued by Plex forums.plex.tv/t/important-se… for v1.43.2 & earlier. Over 36K instances found still unpatched! Top affected: US (16K)
World Map: dashboard.shadowserver.org/statistics/com…
At least 122,500 MikroTik devices with SSH accessible found per 24 hour scan window on 2026-09-05 (no vulnerability check).
IP data shared daily in Accessible SSH reporting shadowserver.org/what-we-do/net… tagged 'mikrotik' & Device Identification reports: shadowserver.org/what-we-do/net…
We added MikroTik SSH identification to our daily scans on 2026-09-04, in response to MikroTik's patches mikrotik.com/supportsec/sep…. As discovered by @CERT_Polska_encert.pl/en/posts/2026/… unpatched MikroTiks can be compromised, if device supports remote access using SSH protocol
PaperCut MF/NG incidents: At least 204 instances found on 2026-08-31 still vulnerable to CVE-2026-82078/CVE-2026-81578 RCE that is exploited in the wild. Make sure to check for compromise & patch. Top affected: US (60).
Dashboard World Map view stats: dashboard.shadowserver.org/statistics/com…
We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: shadowserver.org/what-we-do/net…
At least 21899 IPs seen unpatched 2026-08-31, top US (6.2K) & Germany (5.1K)
55K Followers 3K FollowingDirector of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
62K Followers 1K FollowingSecurity information portal, testing and certification body.
Organisers of the annual Virus Bulletin conference. @[email protected]
37K Followers 3K FollowingSituational Awareness | Threat Intelligence | cybertracker | Hacktivism | Meme Farmer
Digital Owl of the Cyber Realm
Posts and Opinions are my own
39K Followers 3K FollowingPartner / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
3 Followers 19 Following@officiallyiru Security Research team's space for sharing intelligence and observations about what we see in the technology and cyber industries.
371 Followers 686 FollowingWeb3 Dev & Tech Analyst. Daily breakdowns on AI, Crypto & On-Chain trends. Specializing in Solidity & Verifiable AI. Based in 🇰🇪. Let's decode the future.