Welcome To Next Generation AI SOC
From Reactive to Proactive Cyber Defense
Dark web threat intelligence and threat actor activity
We watch leak sites, ransomware blogs and closed channels for the moment a company name appears. Here is what that has recorded worldwide.
Three different measures, not a series: a rolling window, a running total of logins, and the full archive.
Most targeted countries
AREA = INCIDENTSCounted across 13,891 of 23,890 incidents (58%) that name a country. Figures are what was observed, not a total.
Most targeted sectors
SHARE OF INCIDENTS- Government Administration 31.8% 2,124
- Education 15.3% 1,024
- Information Technology (IT) Services 9.1% 609
- Financial Services 6.7% 445
- Government & Public Sector 6.0% 401
- Transportation & Logistics 5.3% 355
- Everything else 25.8% 1,727
South-East Asia, 12 months
AREA = INCIDENTS-
Indonesia
2,028
-
Thailand
1,198
-
Malaysia
211
-
Philippines
205
-
Vietnam
178
-
Singapore
121
-
Brunei
2
About 72% of posts name a country, so every figure here is a floor.
What actually happened
75% of incidents involved stolen access, ransomware or exposed data, not website defacement.
89 days of activity
Each bar is one day, counted from every incident recorded in the window. A flat run is a quiet week rather than a gap in collection. 19,203 incidents across these 89 days, updated 11 hours ago.
Dated by when each incident was observed, not when it happened. Today is excluded while it is still in progress. One day carries 3,718 from a collection backfill; it is drawn off the scale so it cannot flatten the rest.
Every day, with its count
- Tue 18 Aug 2026 220
- Mon 17 Aug 2026 223
- Sun 16 Aug 2026 304
- Sat 15 Aug 2026 192
- Fri 14 Aug 2026 153
- Thu 13 Aug 2026 129
- Wed 12 Aug 2026 198
- Tue 11 Aug 2026 210
- Mon 10 Aug 2026 227
- Sun 9 Aug 2026 244
- Sat 8 Aug 2026 174
- Fri 7 Aug 2026 220
- Thu 6 Aug 2026 236
- Wed 5 Aug 2026 3,718
- Tue 4 Aug 2026 241
- Mon 3 Aug 2026 207
- Sun 2 Aug 2026 176
- Sat 1 Aug 2026 151
- Fri 31 Jul 2026 153
- Thu 30 Jul 2026 183
- Wed 29 Jul 2026 195
- Tue 28 Jul 2026 191
- Mon 27 Jul 2026 231
- Sun 26 Jul 2026 169
- Sat 25 Jul 2026 191
- Fri 24 Jul 2026 285
- Thu 23 Jul 2026 234
- Wed 22 Jul 2026 202
- Tue 21 Jul 2026 400
- Mon 20 Jul 2026 207
- Sun 19 Jul 2026 114
- Sat 18 Jul 2026 0
- Fri 17 Jul 2026 71
- Thu 16 Jul 2026 212
- Wed 15 Jul 2026 171
- Tue 14 Jul 2026 205
- Mon 13 Jul 2026 162
- Sun 12 Jul 2026 128
- Sat 11 Jul 2026 135
- Fri 10 Jul 2026 198
- Thu 9 Jul 2026 33
- Wed 8 Jul 2026 205
- Tue 7 Jul 2026 213
- Mon 6 Jul 2026 153
- Sun 5 Jul 2026 114
- Sat 4 Jul 2026 136
- Fri 3 Jul 2026 214
- Thu 2 Jul 2026 155
- Wed 1 Jul 2026 212
- Tue 30 Jun 2026 176
- Mon 29 Jun 2026 244
- Sun 28 Jun 2026 145
- Sat 27 Jun 2026 174
- Fri 26 Jun 2026 186
- Thu 25 Jun 2026 162
- Wed 24 Jun 2026 124
- Tue 23 Jun 2026 118
- Mon 22 Jun 2026 213
- Sun 21 Jun 2026 123
- Sat 20 Jun 2026 200
- Fri 19 Jun 2026 198
- Thu 18 Jun 2026 188
- Wed 17 Jun 2026 107
- Tue 16 Jun 2026 139
- Mon 15 Jun 2026 171
- Sun 14 Jun 2026 250
- Sat 13 Jun 2026 136
- Fri 12 Jun 2026 131
- Thu 11 Jun 2026 165
- Wed 10 Jun 2026 196
- Tue 9 Jun 2026 123
- Mon 8 Jun 2026 135
- Sun 7 Jun 2026 118
- Sat 6 Jun 2026 160
- Fri 5 Jun 2026 173
- Thu 4 Jun 2026 220
- Wed 3 Jun 2026 168
- Tue 2 Jun 2026 122
- Mon 1 Jun 2026 168
- Sun 31 May 2026 114
- Sat 30 May 2026 130
- Fri 29 May 2026 594
- Thu 28 May 2026 0
- Wed 27 May 2026 0
- Tue 26 May 2026 53
- Mon 25 May 2026 163
- Sun 24 May 2026 228
- Sat 23 May 2026 150
- Fri 22 May 2026 143
Check your own exposure
2,124 incidents in the last 90 days named organizations in Government Administration. 8.9% of all incidents
- Access sold 13%
- Ransomware and extortion 3%
- Data exposed 27%
- Disruption 55%
Counted from every incident in the window, not sampled.
2,148 incidents in the last 90 days named organizations in USA. 9.0% of all incidents
- Access sold 14%
- Ransomware and extortion 41%
- Data exposed 31%
- Disruption 12%
Counted from every incident in the window, not sampled.
GLOBAL THREAT VIEW
Attack Flows
Drag to rotate
Tracking 12 attack routes over the last 7d. Busiest is Brazil to Hong Kong at 3% of observed attack traffic. Each line is a country pair, and the more traffic it carries the brighter and busier it runs.
Top Network Attack Vectors
Attack Protocol Mix
Top Scanned TCP Ports
SANS ISC / DShield- 1443 · https299,184
- 222 · ssh140,327
- 323 · 23135,694
- 416767 · ---107,109
- 5123 · ntp100,065
- 680 · www94,570
- 7853 · domain-s86,448
- 80 · ---56,374
Top Scanned UDP Ports
SANS ISC / DShield- 153 · domain1,343
- 21900 · ssdp994
- 35060 · sip858
- 4500 · isakmp823
- 5123 · ntp601
- 65353 · mdns469
- 727015 · halflife315
- 8161 · snmp250
Active Malware Families
abuse.ch- 1ClearFake123
- 2Sliver47
- 3Vidar45
- 4IClickFix44
- 5Unknown malware38
Sources: Cloudflare Radar (CC BY-NC 4.0), SANS ISC / DShield, abuse.ch, CISA KEV. Updated August 21, 2026.
CODERED VTA
Emerging Threat Advisory
Our analysts publish an advisory for each vulnerability and campaign they track. Every one carries a severity, the CVE where one has been assigned, the indicators your team can hunt for, and the mitigation we recommend.




Malicious Browser Extension Crashes Browsers for ClickFix Attacks
A recently discovered malvertising campaign is utilizing a fake ad-blocking Chrome and Edge extension named NexShield to intentionally crash browsers, paving the way for ClickFix attacks. This campaign was spotted earlier this month and…
Mandiant Exposes NTLMv1 Vulnerability with Pre-Computed Rainbow Table
The NTLMv1 protocol, a legacy authentication protocol developed in the 1990s, has been found to be widely used despite its known vulnerabilities. Mandiant, a Google security division, has released a pre-computed rainbow table to…
US Supreme Court and Federal Agencies Breached by Credential Theft
A Tennessee man, Nicholas Moore, has pleaded guilty to hacking the U.S. Supreme Court's electronic filing system, as well as breaching accounts at the AmeriCorps U.S. federal agency and the Department of Veterans Affairs.…
Russian Hacktivists Increase Disruptive Cyber Attacks on UK Organizations
The UK National Cyber Security Centre (NCSC) has issued a warning about the ongoing disruptive cyber attacks against UK organizations, particularly local government bodies and operators of critical national infrastructure. These attacks are primarily…
Malicious Visual Studio Code Extensions Pose Significant Threat to Developers
A recent campaign, known as "Evelyn Stealer", has been identified as utilizing the Visual Studio Code (VSC) extension ecosystem to deliver malware to software developers. This campaign leverages what appear to be legitimate extensions,…
Emergence of SolyxImmortal Information Stealer: A New Threat to Data Security
The cybersecurity landscape has witnessed the emergence of a new information stealer, known as SolyxImmortal. This threat abuses legitimate APIs and libraries to exfiltrate sensitive data to Discord webhooks, posing a significant risk to…
Pulsar RAT Exploits Memory-Only Execution for Stealthy Windows Takeovers
The Pulsar RAT, a sophisticated evolution of the Quasar RAT, has been identified as a significant threat to Windows systems due to its advanced stealth capabilities and fileless execution techniques. This remote access trojan…
Critical Vulnerability in Cal.com Allows Attackers to Bypass Authentication
A critical vulnerability has been discovered in Cal.com, an open-source scheduling and booking platform, which could allow attackers to bypass authentication and gain full access to any user account. The vulnerability, identified by GitHub…
Palo Alto Networks Firewall Vulnerability Exposes Users to Denial of Service Attacks
A recently discovered vulnerability in Palo Alto Networks firewalls has been found to allow unauthenticated attackers to trigger a denial of service (DoS) against the affected systems. This vulnerability, tracked as CVE-2026-0227, affects both…
Iran’s Internet Blackout: A Rare Opportunity for Cybersecurity Intelligence Gathering
Iran's recent near-total internet blackout, imposed by the government, presents a unique opportunity for cybersecurity analysts to gather valuable threat intelligence. The blackout, which started on January 8, has reportedly forced Iranian state actors…
Evolving Android Banking Malware Targets Iranian Users with Ransomware
A sophisticated Android banking malware, known as deVixor, has been identified as targeting Iranian users through phishing websites masquerading as legitimate automotive businesses. This malware has evolved from a basic SMS-harvesting threat into a…
Top Vendors for AI-Enabled Security Identified by CISOs
The increasing use of artificial intelligence (AI) in cybersecurity has led to the development of AI-enabled security solutions. A recent survey of over 640 senior security executives found that the largest and most well-known…
CODERED VTA
Get advisories as we publish them
Our analysts write these up as they track them. Join the mailing list and each one reaches you without you having to check back.
Subscribe to advisories