Welcome To Next Generation AI SOC
From Reactive to Proactive Cyber Defense
Dark web threat intelligence and threat actor activity
We watch leak sites, ransomware blogs and closed channels for the moment a company name appears. Here is what that has recorded worldwide.
Three different measures, not a series: a rolling window, a running total of logins, and the full archive.
Most targeted countries
AREA = INCIDENTSCounted across 13,891 of 23,890 incidents (58%) that name a country. Figures are what was observed, not a total.
Most targeted sectors
SHARE OF INCIDENTS- Government Administration 31.8% 2,124
- Education 15.3% 1,024
- Information Technology (IT) Services 9.1% 609
- Financial Services 6.7% 445
- Government & Public Sector 6.0% 401
- Transportation & Logistics 5.3% 355
- Everything else 25.8% 1,727
South-East Asia, 12 months
AREA = INCIDENTS-
Indonesia
2,028
-
Thailand
1,198
-
Malaysia
211
-
Philippines
205
-
Vietnam
178
-
Singapore
121
-
Brunei
2
About 72% of posts name a country, so every figure here is a floor.
What actually happened
75% of incidents involved stolen access, ransomware or exposed data, not website defacement.
89 days of activity
Each bar is one day, counted from every incident recorded in the window. A flat run is a quiet week rather than a gap in collection. 19,203 incidents across these 89 days, updated 10 hours ago.
Dated by when each incident was observed, not when it happened. Today is excluded while it is still in progress. One day carries 3,718 from a collection backfill; it is drawn off the scale so it cannot flatten the rest.
Every day, with its count
- Tue 18 Aug 2026 220
- Mon 17 Aug 2026 223
- Sun 16 Aug 2026 304
- Sat 15 Aug 2026 192
- Fri 14 Aug 2026 153
- Thu 13 Aug 2026 129
- Wed 12 Aug 2026 198
- Tue 11 Aug 2026 210
- Mon 10 Aug 2026 227
- Sun 9 Aug 2026 244
- Sat 8 Aug 2026 174
- Fri 7 Aug 2026 220
- Thu 6 Aug 2026 236
- Wed 5 Aug 2026 3,718
- Tue 4 Aug 2026 241
- Mon 3 Aug 2026 207
- Sun 2 Aug 2026 176
- Sat 1 Aug 2026 151
- Fri 31 Jul 2026 153
- Thu 30 Jul 2026 183
- Wed 29 Jul 2026 195
- Tue 28 Jul 2026 191
- Mon 27 Jul 2026 231
- Sun 26 Jul 2026 169
- Sat 25 Jul 2026 191
- Fri 24 Jul 2026 285
- Thu 23 Jul 2026 234
- Wed 22 Jul 2026 202
- Tue 21 Jul 2026 400
- Mon 20 Jul 2026 207
- Sun 19 Jul 2026 114
- Sat 18 Jul 2026 0
- Fri 17 Jul 2026 71
- Thu 16 Jul 2026 212
- Wed 15 Jul 2026 171
- Tue 14 Jul 2026 205
- Mon 13 Jul 2026 162
- Sun 12 Jul 2026 128
- Sat 11 Jul 2026 135
- Fri 10 Jul 2026 198
- Thu 9 Jul 2026 33
- Wed 8 Jul 2026 205
- Tue 7 Jul 2026 213
- Mon 6 Jul 2026 153
- Sun 5 Jul 2026 114
- Sat 4 Jul 2026 136
- Fri 3 Jul 2026 214
- Thu 2 Jul 2026 155
- Wed 1 Jul 2026 212
- Tue 30 Jun 2026 176
- Mon 29 Jun 2026 244
- Sun 28 Jun 2026 145
- Sat 27 Jun 2026 174
- Fri 26 Jun 2026 186
- Thu 25 Jun 2026 162
- Wed 24 Jun 2026 124
- Tue 23 Jun 2026 118
- Mon 22 Jun 2026 213
- Sun 21 Jun 2026 123
- Sat 20 Jun 2026 200
- Fri 19 Jun 2026 198
- Thu 18 Jun 2026 188
- Wed 17 Jun 2026 107
- Tue 16 Jun 2026 139
- Mon 15 Jun 2026 171
- Sun 14 Jun 2026 250
- Sat 13 Jun 2026 136
- Fri 12 Jun 2026 131
- Thu 11 Jun 2026 165
- Wed 10 Jun 2026 196
- Tue 9 Jun 2026 123
- Mon 8 Jun 2026 135
- Sun 7 Jun 2026 118
- Sat 6 Jun 2026 160
- Fri 5 Jun 2026 173
- Thu 4 Jun 2026 220
- Wed 3 Jun 2026 168
- Tue 2 Jun 2026 122
- Mon 1 Jun 2026 168
- Sun 31 May 2026 114
- Sat 30 May 2026 130
- Fri 29 May 2026 594
- Thu 28 May 2026 0
- Wed 27 May 2026 0
- Tue 26 May 2026 53
- Mon 25 May 2026 163
- Sun 24 May 2026 228
- Sat 23 May 2026 150
- Fri 22 May 2026 143
Check your own exposure
2,124 incidents in the last 90 days named organizations in Government Administration. 8.9% of all incidents
- Access sold 13%
- Ransomware and extortion 3%
- Data exposed 27%
- Disruption 55%
Counted from every incident in the window, not sampled.
2,148 incidents in the last 90 days named organizations in USA. 9.0% of all incidents
- Access sold 14%
- Ransomware and extortion 41%
- Data exposed 31%
- Disruption 12%
Counted from every incident in the window, not sampled.
GLOBAL THREAT VIEW
Attack Flows
Drag to rotate
Tracking 12 attack routes over the last 7d. Busiest is Brazil to Hong Kong at 3% of observed attack traffic. Each line is a country pair, and the more traffic it carries the brighter and busier it runs.
Top Network Attack Vectors
Attack Protocol Mix
Top Scanned TCP Ports
SANS ISC / DShield- 1443 · 443299,184
- 222 · 22140,327
- 323 · 23135,694
- 416767 · 16767107,109
- 5123 · 123100,065
- 680 · 8094,570
- 7853 · 85386,448
- 80 · 056,374
Top Scanned UDP Ports
SANS ISC / DShieldNo data reported
Active Malware Families
abuse.ch- 1ClearFake138
- 2IClickFix134
- 3Sliver47
- 4Vidar45
- 5Unknown malware36
Sources: Cloudflare Radar (CC BY-NC 4.0), SANS ISC / DShield, abuse.ch, CISA KEV. Updated August 21, 2026.
CODERED VTA
Emerging Threat Advisory
Our analysts publish an advisory for each vulnerability and campaign they track. Every one carries a severity, the CVE where one has been assigned, the indicators your team can hunt for, and the mitigation we recommend.

StopAndProtect Campaign Exploits Thousands of WordPress Sites for Malware Delivery
Cybersecurity researchers have uncovered a large-scale cybercrime campaign, dubbed StopAndProtect, that has compromised thousands of WordPress websites and repurposed them as infrastructure for malware delivery, command-and-control, and stolen-data storage. The campaign primarily exploits outdated…
SafePal Data Breach Impacts Thousands Of Customers
A recent data breach has affected approximately 39,798 customers of cryptocurrency hardware wallet provider SafePal. The breach occurred due to a flaw that was exploited to steal customer order information. This stolen data is…
SharePoint Authentication Bypass Vulnerability Under Active Exploitation
A critical security vulnerability in Microsoft SharePoint has been disclosed, allowing attackers to bypass authentication and perform arbitrary operations as a SharePoint site user or administrator. The vulnerability, identified as CVE-2026-55040, has a CVSS…
Cisco Firewall Zero Day Under Active Attack Enables Network Denial of Service
Cisco has released emergency patches for a zero-day vulnerability tracked as CVE-2026-20349 affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. The security flaw allows remote, unauthenticated attackers…
New DOUBLECUP Loader – as – a – Service Uses ClickFix, Steganography, and Environmental Keying to Deliver Malware
Researchers have identified a new Russian-based Loader-as-a-Service (LaaS) known as DOUBLECUP, which uses ClickFix social engineering to deploy malware on both Windows and macOS systems. The attack begins by convincing victims to execute copied…
Shai – Hulud Supply Chain Worm Compromises Over 400 npm Packages Reaching 2 Billion Monthly Downloads
On August 4, 2026, attackers successfully compromised the GitHub account of a prominent npm maintainer responsible for keyv, a widely-used key-value storage library with approximately 127 million weekly downloads. The breach extended across the…
Alibaba Developers Targeted By Malicious Npm Packages
A sophisticated software supply chain attack has been uncovered, targeting users of Alibaba developer tools with a cross-platform remote access trojan. The attack involves 18 malicious npm packages, including lib-mtop, aone-kit, and local-config-parser, which…
VMware Patches Three Critical Flaws Enabling Authentication Bypass and Virtual Machine Escape
Broadcom has released security updates to address multiple critical vulnerabilities affecting VMware products, including vCenter Server, ESX, Workstation, Fusion, Cloud Foundation, and Telco Cloud platforms. Researchers said the vulnerabilities could allow attackers to bypass…
Malware Targets Financial Institutions With Brushworm And Brushlogger
A targeted cyberattack against a South Asian financial institution leveraged two custom malware tools to establish persistence, steal sensitive data, and capture user activity. Researchers said the operation relied on a modular backdoor, BRUSHWORM,…
Autonomous AI Agent Conducts Espionage Campaign Against Thai Government Finance Ministry
Attackers breached Thailand's Ministry of Finance using Hermes, an open-source AI agent framework, to conduct autonomous reconnaissance and data collection. The Ministry, holding sensitive fiscal and economic intelligence, is a high-value target for nation-state…
Shai Hulud Supply Chain Campaign Targets Red Hat Cloud Services npm Packages
A recent campaign has targeted Red Hat Cloud Services npm packages, putting developers at risk. The campaign, known as Mini Shai-Hulud, involves compromised packages that can fetch and execute remote code. This type of…
Critical Fastjson Flaw Enables Unauthenticated Remote Code Execution
Security researchers have observed active exploitation of a critical vulnerability, CVE-2026-16723 (CVSS 9.0), affecting Fastjson 1.2.68 through 1.2.83. The flaw allows unauthenticated remote code execution in vulnerable Spring Boot executable fat-JAR applications by sending…
CODERED VTA
Get advisories as we publish them
Our analysts write these up as they track them. Join the mailing list and each one reaches you without you having to check back.
Subscribe to advisories