Welcome To Next Generation AI SOC
From Reactive to Proactive Cyber Defense
Dark web threat intelligence and threat actor activity
We watch leak sites, ransomware blogs and closed channels for the moment a company name appears. Here is what that has recorded worldwide.
Three different measures, not a series: a rolling window, a running total of logins, and the full archive.
Most targeted countries
AREA = INCIDENTSCounted across 13,891 of 23,890 incidents (58%) that name a country. Figures are what was observed, not a total.
Most targeted sectors
SHARE OF INCIDENTS- Government Administration 31.8% 2,124
- Education 15.3% 1,024
- Information Technology (IT) Services 9.1% 609
- Financial Services 6.7% 445
- Government & Public Sector 6.0% 401
- Transportation & Logistics 5.3% 355
- Everything else 25.8% 1,727
South-East Asia, 12 months
AREA = INCIDENTS-
Indonesia
2,028
-
Thailand
1,198
-
Malaysia
211
-
Philippines
205
-
Vietnam
178
-
Singapore
121
-
Brunei
2
About 72% of posts name a country, so every figure here is a floor.
What actually happened
75% of incidents involved stolen access, ransomware or exposed data, not website defacement.
89 days of activity
Each bar is one day, counted from every incident recorded in the window. A flat run is a quiet week rather than a gap in collection. 19,203 incidents across these 89 days, updated 10 hours ago.
Dated by when each incident was observed, not when it happened. Today is excluded while it is still in progress. One day carries 3,718 from a collection backfill; it is drawn off the scale so it cannot flatten the rest.
Every day, with its count
- Tue 18 Aug 2026 220
- Mon 17 Aug 2026 223
- Sun 16 Aug 2026 304
- Sat 15 Aug 2026 192
- Fri 14 Aug 2026 153
- Thu 13 Aug 2026 129
- Wed 12 Aug 2026 198
- Tue 11 Aug 2026 210
- Mon 10 Aug 2026 227
- Sun 9 Aug 2026 244
- Sat 8 Aug 2026 174
- Fri 7 Aug 2026 220
- Thu 6 Aug 2026 236
- Wed 5 Aug 2026 3,718
- Tue 4 Aug 2026 241
- Mon 3 Aug 2026 207
- Sun 2 Aug 2026 176
- Sat 1 Aug 2026 151
- Fri 31 Jul 2026 153
- Thu 30 Jul 2026 183
- Wed 29 Jul 2026 195
- Tue 28 Jul 2026 191
- Mon 27 Jul 2026 231
- Sun 26 Jul 2026 169
- Sat 25 Jul 2026 191
- Fri 24 Jul 2026 285
- Thu 23 Jul 2026 234
- Wed 22 Jul 2026 202
- Tue 21 Jul 2026 400
- Mon 20 Jul 2026 207
- Sun 19 Jul 2026 114
- Sat 18 Jul 2026 0
- Fri 17 Jul 2026 71
- Thu 16 Jul 2026 212
- Wed 15 Jul 2026 171
- Tue 14 Jul 2026 205
- Mon 13 Jul 2026 162
- Sun 12 Jul 2026 128
- Sat 11 Jul 2026 135
- Fri 10 Jul 2026 198
- Thu 9 Jul 2026 33
- Wed 8 Jul 2026 205
- Tue 7 Jul 2026 213
- Mon 6 Jul 2026 153
- Sun 5 Jul 2026 114
- Sat 4 Jul 2026 136
- Fri 3 Jul 2026 214
- Thu 2 Jul 2026 155
- Wed 1 Jul 2026 212
- Tue 30 Jun 2026 176
- Mon 29 Jun 2026 244
- Sun 28 Jun 2026 145
- Sat 27 Jun 2026 174
- Fri 26 Jun 2026 186
- Thu 25 Jun 2026 162
- Wed 24 Jun 2026 124
- Tue 23 Jun 2026 118
- Mon 22 Jun 2026 213
- Sun 21 Jun 2026 123
- Sat 20 Jun 2026 200
- Fri 19 Jun 2026 198
- Thu 18 Jun 2026 188
- Wed 17 Jun 2026 107
- Tue 16 Jun 2026 139
- Mon 15 Jun 2026 171
- Sun 14 Jun 2026 250
- Sat 13 Jun 2026 136
- Fri 12 Jun 2026 131
- Thu 11 Jun 2026 165
- Wed 10 Jun 2026 196
- Tue 9 Jun 2026 123
- Mon 8 Jun 2026 135
- Sun 7 Jun 2026 118
- Sat 6 Jun 2026 160
- Fri 5 Jun 2026 173
- Thu 4 Jun 2026 220
- Wed 3 Jun 2026 168
- Tue 2 Jun 2026 122
- Mon 1 Jun 2026 168
- Sun 31 May 2026 114
- Sat 30 May 2026 130
- Fri 29 May 2026 594
- Thu 28 May 2026 0
- Wed 27 May 2026 0
- Tue 26 May 2026 53
- Mon 25 May 2026 163
- Sun 24 May 2026 228
- Sat 23 May 2026 150
- Fri 22 May 2026 143
Check your own exposure
2,124 incidents in the last 90 days named organizations in Government Administration. 8.9% of all incidents
- Access sold 13%
- Ransomware and extortion 3%
- Data exposed 27%
- Disruption 55%
Counted from every incident in the window, not sampled.
2,148 incidents in the last 90 days named organizations in USA. 9.0% of all incidents
- Access sold 14%
- Ransomware and extortion 41%
- Data exposed 31%
- Disruption 12%
Counted from every incident in the window, not sampled.
GLOBAL THREAT VIEW
Attack Flows
Drag to rotate
Tracking 12 attack routes over the last 7d. Busiest is Brazil to Hong Kong at 3% of observed attack traffic. Each line is a country pair, and the more traffic it carries the brighter and busier it runs.
Top Network Attack Vectors
Attack Protocol Mix
Top Scanned TCP Ports
SANS ISC / DShield- 1443 · 443299,184
- 222 · 22140,327
- 323 · 23135,694
- 416767 · 16767107,109
- 5123 · 123100,065
- 680 · 8094,570
- 7853 · 85386,448
- 80 · 056,374
Top Scanned UDP Ports
SANS ISC / DShieldNo data reported
Active Malware Families
abuse.ch- 1ClearFake138
- 2IClickFix134
- 3Sliver47
- 4Vidar45
- 5Unknown malware36
Sources: Cloudflare Radar (CC BY-NC 4.0), SANS ISC / DShield, abuse.ch, CISA KEV. Updated August 21, 2026.
CODERED VTA
Emerging Threat Advisory
Our analysts publish an advisory for each vulnerability and campaign they track. Every one carries a severity, the CVE where one has been assigned, the indicators your team can hunt for, and the mitigation we recommend.




Windows Shell Flaw Becomes Zero Click Tool for Credential Theft
A newly discovered vulnerability, CVE-2026-32202, has been found to affect Windows systems due to an incomplete patch for a previously known exploit. This vulnerability allows for zero-click authentication coercion, enabling attackers to authenticate to…
Developers Targeted in Sophisticated Slack Phishing Campaign
A group focused on open source security has raised concerns about a targeted phishing campaign aimed at software developers through the Slack platform. The attackers impersonate prominent figures from the Linux Foundation to gain…
VMware ESXi Vulnerability Exploited in Ransomware Attacks
The U.S. Cybersecurity and Infrastructure Security Agency recently confirmed that ransomware groups are actively exploiting a high-severity VMware ESXi sandbox escape vulnerability, known as CVE-2025-22225. This flaw, patched by Broadcom in March 2025, enables…
Kubernetes Ingress – NGINX Controller Vulnerability Enables Arbitrary Code Execution
A high-severity vulnerability, tracked as CVE-2026-24512, has been discovered in the Kubernetes ingress-nginx controller. This vulnerability allows attackers to execute arbitrary code and potentially compromise entire clusters. The ingress-nginx controller is a widely used…
Software Supply Chain Vulnerabilities Exposed Through Inadequate Security Testing
The rise of software supply chain attacks has brought attention to the importance of secure coding practices. Recent high-profile breaches, such as the SolarWinds attack, have highlighted the need for developers to prioritize security…
GlassWorm Malware Resurgence Threatens Developer Ecosystems
The GlassWorm malware has resurfaced, this time targeting Open VSX software components with a fresh wave of infections. This self-replicating malware has the potential to spread rapidly, leaving downstream victims vulnerable to infostealer infections.…
Fortinet Blocks Exploited FortiCloud SSO Zero – Day Vulnerability
A recently discovered zero-day vulnerability in Fortinet's FortiCloud single sign-on (SSO) solution, tracked as CVE-2026-24858, has been actively exploited by attackers to gain administrative access to FortiOS, FortiManager, and FortiAnalyzer devices. This vulnerability, rated…
Telnet Authentication Bypass Vulnerability Exposes Devices to Complete Takeover
A critical vulnerability in the Telnet protocol, tracked as CVE-2026-24061, has been discovered that allows attackers to bypass authentication and gain complete control over devices. This 11-year-old vulnerability affects many devices that are no…
SmarterMail Authentication Bypass Vulnerability Exploited in the Wild
A recently discovered authentication bypass vulnerability in SmarterMail, a self-hosted Windows email server and collaboration platform, is being actively exploited by hackers to hijack admin accounts. The vulnerability, which does not have a CVE…
Critical RCE Vulnerability in Cisco Unified Communications
A critical remote code execution (RCE) vulnerability has been discovered in Cisco's Unified Communications and Webex Calling, tracked as CVE-2026-20045. This vulnerability affects several Cisco products, including Unified Communications Manager, Unified CM Session Management…
Critical Vulnerabilities in AVEVA Software Enable Remote Code Execution
The AVEVA Process Optimization software, formerly known as ROMeo, has been found to contain seven critical and high-severity vulnerabilities. These vulnerabilities could allow attackers to execute remote code with SYSTEM privileges, potentially compromising industrial…
Critical Cloudflare Zero-Day Vulnerability Allows Bypass of Security Controls
A recently discovered zero-day vulnerability in Cloudflare's Web Application Firewall (WAF) has been found to allow attackers to bypass security controls and directly access protected origin servers. This vulnerability was discovered by security researchers…
CODERED VTA
Get advisories as we publish them
Our analysts write these up as they track them. Join the mailing list and each one reaches you without you having to check back.
Subscribe to advisories