Welcome To Next Generation AI SOC
From Reactive to Proactive Cyber Defense
Dark web threat intelligence and threat actor activity
We watch leak sites, ransomware blogs and closed channels for the moment a company name appears. Here is what that has recorded worldwide.
Three different measures, not a series: a rolling window, a running total of logins, and the full archive.
Most targeted countries
AREA = INCIDENTSCounted across 13,891 of 23,890 incidents (58%) that name a country. Figures are what was observed, not a total.
Most targeted sectors
SHARE OF INCIDENTS- Government Administration 31.8% 2,124
- Education 15.3% 1,024
- Information Technology (IT) Services 9.1% 609
- Financial Services 6.7% 445
- Government & Public Sector 6.0% 401
- Transportation & Logistics 5.3% 355
- Everything else 25.8% 1,727
South-East Asia, 12 months
AREA = INCIDENTS-
Indonesia
2,028
-
Thailand
1,198
-
Malaysia
211
-
Philippines
205
-
Vietnam
178
-
Singapore
121
-
Brunei
2
About 72% of posts name a country, so every figure here is a floor.
What actually happened
75% of incidents involved stolen access, ransomware or exposed data, not website defacement.
89 days of activity
Each bar is one day, counted from every incident recorded in the window. A flat run is a quiet week rather than a gap in collection. 19,203 incidents across these 89 days, updated 10 hours ago.
Dated by when each incident was observed, not when it happened. Today is excluded while it is still in progress. One day carries 3,718 from a collection backfill; it is drawn off the scale so it cannot flatten the rest.
Every day, with its count
- Tue 18 Aug 2026 220
- Mon 17 Aug 2026 223
- Sun 16 Aug 2026 304
- Sat 15 Aug 2026 192
- Fri 14 Aug 2026 153
- Thu 13 Aug 2026 129
- Wed 12 Aug 2026 198
- Tue 11 Aug 2026 210
- Mon 10 Aug 2026 227
- Sun 9 Aug 2026 244
- Sat 8 Aug 2026 174
- Fri 7 Aug 2026 220
- Thu 6 Aug 2026 236
- Wed 5 Aug 2026 3,718
- Tue 4 Aug 2026 241
- Mon 3 Aug 2026 207
- Sun 2 Aug 2026 176
- Sat 1 Aug 2026 151
- Fri 31 Jul 2026 153
- Thu 30 Jul 2026 183
- Wed 29 Jul 2026 195
- Tue 28 Jul 2026 191
- Mon 27 Jul 2026 231
- Sun 26 Jul 2026 169
- Sat 25 Jul 2026 191
- Fri 24 Jul 2026 285
- Thu 23 Jul 2026 234
- Wed 22 Jul 2026 202
- Tue 21 Jul 2026 400
- Mon 20 Jul 2026 207
- Sun 19 Jul 2026 114
- Sat 18 Jul 2026 0
- Fri 17 Jul 2026 71
- Thu 16 Jul 2026 212
- Wed 15 Jul 2026 171
- Tue 14 Jul 2026 205
- Mon 13 Jul 2026 162
- Sun 12 Jul 2026 128
- Sat 11 Jul 2026 135
- Fri 10 Jul 2026 198
- Thu 9 Jul 2026 33
- Wed 8 Jul 2026 205
- Tue 7 Jul 2026 213
- Mon 6 Jul 2026 153
- Sun 5 Jul 2026 114
- Sat 4 Jul 2026 136
- Fri 3 Jul 2026 214
- Thu 2 Jul 2026 155
- Wed 1 Jul 2026 212
- Tue 30 Jun 2026 176
- Mon 29 Jun 2026 244
- Sun 28 Jun 2026 145
- Sat 27 Jun 2026 174
- Fri 26 Jun 2026 186
- Thu 25 Jun 2026 162
- Wed 24 Jun 2026 124
- Tue 23 Jun 2026 118
- Mon 22 Jun 2026 213
- Sun 21 Jun 2026 123
- Sat 20 Jun 2026 200
- Fri 19 Jun 2026 198
- Thu 18 Jun 2026 188
- Wed 17 Jun 2026 107
- Tue 16 Jun 2026 139
- Mon 15 Jun 2026 171
- Sun 14 Jun 2026 250
- Sat 13 Jun 2026 136
- Fri 12 Jun 2026 131
- Thu 11 Jun 2026 165
- Wed 10 Jun 2026 196
- Tue 9 Jun 2026 123
- Mon 8 Jun 2026 135
- Sun 7 Jun 2026 118
- Sat 6 Jun 2026 160
- Fri 5 Jun 2026 173
- Thu 4 Jun 2026 220
- Wed 3 Jun 2026 168
- Tue 2 Jun 2026 122
- Mon 1 Jun 2026 168
- Sun 31 May 2026 114
- Sat 30 May 2026 130
- Fri 29 May 2026 594
- Thu 28 May 2026 0
- Wed 27 May 2026 0
- Tue 26 May 2026 53
- Mon 25 May 2026 163
- Sun 24 May 2026 228
- Sat 23 May 2026 150
- Fri 22 May 2026 143
Check your own exposure
2,124 incidents in the last 90 days named organizations in Government Administration. 8.9% of all incidents
- Access sold 13%
- Ransomware and extortion 3%
- Data exposed 27%
- Disruption 55%
Counted from every incident in the window, not sampled.
2,148 incidents in the last 90 days named organizations in USA. 9.0% of all incidents
- Access sold 14%
- Ransomware and extortion 41%
- Data exposed 31%
- Disruption 12%
Counted from every incident in the window, not sampled.
GLOBAL THREAT VIEW
Attack Flows
Drag to rotate
Tracking 12 attack routes over the last 7d. Busiest is Brazil to Hong Kong at 3% of observed attack traffic. Each line is a country pair, and the more traffic it carries the brighter and busier it runs.
Top Network Attack Vectors
Attack Protocol Mix
Top Scanned TCP Ports
SANS ISC / DShield- 1443 · 443299,184
- 222 · 22140,327
- 323 · 23135,694
- 416767 · 16767107,109
- 5123 · 123100,065
- 680 · 8094,570
- 7853 · 85386,448
- 80 · 056,374
Top Scanned UDP Ports
SANS ISC / DShieldNo data reported
Active Malware Families
abuse.ch- 1ClearFake138
- 2IClickFix134
- 3Sliver47
- 4Vidar45
- 5Unknown malware36
Sources: Cloudflare Radar (CC BY-NC 4.0), SANS ISC / DShield, abuse.ch, CISA KEV. Updated August 21, 2026.
CODERED VTA
Emerging Threat Advisory
Our analysts publish an advisory for each vulnerability and campaign they track. Every one carries a severity, the CVE where one has been assigned, the indicators your team can hunt for, and the mitigation we recommend.




Mistic Backdoor Enables Stealthy In – Memory Attacks to Support Ransomware Operations
Researchers have identified a new stealthy backdoor called Mistic (also tracked as MLTBackdoor by Zscaler) used in financially motivated attacks targeting organizations across the insurance, education, IT, and professional services sectors since April 2026.…
OAuth Client ID Spoofing Enables Silent Account Enumeration in Microsoft Entra ID Environments
Researchers have identified a growing attack technique where threat actors abuse spoofed OAuth client IDs to perform large-scale account enumeration and credential validation against Microsoft Entra ID while reducing detection opportunities. The attack abuses…
Fake Maccy Clipboard Manager Delivers Rust Infostealer to macOS Users
A sophisticated macOS credential-theft campaign is targeting users through a fake version of the legitimate Maccy clipboard manager application. The threat actors registered a lookalike domain, maccyapp[.]com, to impersonate the genuine Maccy project, which…
Actively Exploited Adobe Joomla Langflow Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency has added four security flaws to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. These vulnerabilities are found in Adobe ColdFusion, Joomlack Page Builder, Langflow,…
Langflow RCE Exploited in AI – Agent – Driven Database Ransomware Activity
Security researchers have reported a ransomware and extortion incident involving a threat actor tracked as JADEPUFFER, where an artificial intelligence agent was assessed to have carried out a full attack chain with minimal or…
Malicious Npm And Go Packages Steal Sensitive Data
A recent cybersecurity threat has been discovered where hijacked npm and Go packages are being used to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. The attack avoids common npm…
Attackers Exploit Gravity SMTP Vulnerability to Expose Sensitive WordPress Data
Active exploitation of a vulnerability affecting the Gravity SMTP WordPress plugin, a widely used tool that helps websites send emails through external mail services. The flaw, tracked as CVE-2026-4020, allows unauthenticated attackers to access…
FortiBleed Vulnerability Leads to Credential Exposure on 75,000 Fortinet Devices Worldwide
A recent leak has exposed the credentials of over 73,000 Fortinet VPN devices. This vulnerability affects a wide range of organizations and individuals who use these devices to secure their remote access connections. The…
TrapDoor Crypto Stealer Hits Multiple Packages Across npm PyPI Crates
A recently discovered supply chain attack has compromised multiple packages across npm, PyPI, and Crates.io, affecting hundreds of versions. The attack, known as TrapDoor, involves a crypto stealer that targets developer secrets and cloud…
New Apache HTTP Server Vulnerability Allows DoS and Potential RCE
A critical vulnerability has been identified in Apache HTTP Server version 2.4.66 that affects the HTTP/2 module. The flaw, catalogued as CVE-2026-23918, receives a CVSS base score of 8.8, placing it firmly in the…
China Aligned Cyberespionage Campaign Targets Governments
Cybersecurity researchers have identified a China-aligned espionage campaign targeting government and defense organizations across South, East, and Southeast Asia, as well as a European NATO member. The activity cluster, tracked as SHADOW-EARTH-053, has been…
Linux Kernel Flaw Grants Root Access to Any Local User Across All Major Distributions
A critical vulnerability tracked as CVE-2026-31431 affects virtually every mainstream Linux distribution released between 2017 and April 2026, allowing any unprivileged local user to gain complete root access to the system. The flaw resides…
CODERED VTA
Get advisories as we publish them
Our analysts write these up as they track them. Join the mailing list and each one reaches you without you having to check back.
Subscribe to advisories