Welcome To Next Generation AI SOC
From Reactive to Proactive Cyber Defense
Dark web threat intelligence and threat actor activity
We watch leak sites, ransomware blogs and closed channels for the moment a company name appears. Here is what that has recorded worldwide.
Three different measures, not a series: a rolling window, a running total of logins, and the full archive.
Most targeted countries
AREA = INCIDENTSCounted across 13,891 of 23,890 incidents (58%) that name a country. Figures are what was observed, not a total.
Most targeted sectors
SHARE OF INCIDENTS- Government Administration 31.8% 2,124
- Education 15.3% 1,024
- Information Technology (IT) Services 9.1% 609
- Financial Services 6.7% 445
- Government & Public Sector 6.0% 401
- Transportation & Logistics 5.3% 355
- Everything else 25.8% 1,727
South-East Asia, 12 months
AREA = INCIDENTS-
Indonesia
2,028
-
Thailand
1,198
-
Malaysia
211
-
Philippines
205
-
Vietnam
178
-
Singapore
121
-
Brunei
2
About 72% of posts name a country, so every figure here is a floor.
What actually happened
75% of incidents involved stolen access, ransomware or exposed data, not website defacement.
89 days of activity
Each bar is one day, counted from every incident recorded in the window. A flat run is a quiet week rather than a gap in collection. 19,203 incidents across these 89 days, updated 10 hours ago.
Dated by when each incident was observed, not when it happened. Today is excluded while it is still in progress. One day carries 3,718 from a collection backfill; it is drawn off the scale so it cannot flatten the rest.
Every day, with its count
- Tue 18 Aug 2026 220
- Mon 17 Aug 2026 223
- Sun 16 Aug 2026 304
- Sat 15 Aug 2026 192
- Fri 14 Aug 2026 153
- Thu 13 Aug 2026 129
- Wed 12 Aug 2026 198
- Tue 11 Aug 2026 210
- Mon 10 Aug 2026 227
- Sun 9 Aug 2026 244
- Sat 8 Aug 2026 174
- Fri 7 Aug 2026 220
- Thu 6 Aug 2026 236
- Wed 5 Aug 2026 3,718
- Tue 4 Aug 2026 241
- Mon 3 Aug 2026 207
- Sun 2 Aug 2026 176
- Sat 1 Aug 2026 151
- Fri 31 Jul 2026 153
- Thu 30 Jul 2026 183
- Wed 29 Jul 2026 195
- Tue 28 Jul 2026 191
- Mon 27 Jul 2026 231
- Sun 26 Jul 2026 169
- Sat 25 Jul 2026 191
- Fri 24 Jul 2026 285
- Thu 23 Jul 2026 234
- Wed 22 Jul 2026 202
- Tue 21 Jul 2026 400
- Mon 20 Jul 2026 207
- Sun 19 Jul 2026 114
- Sat 18 Jul 2026 0
- Fri 17 Jul 2026 71
- Thu 16 Jul 2026 212
- Wed 15 Jul 2026 171
- Tue 14 Jul 2026 205
- Mon 13 Jul 2026 162
- Sun 12 Jul 2026 128
- Sat 11 Jul 2026 135
- Fri 10 Jul 2026 198
- Thu 9 Jul 2026 33
- Wed 8 Jul 2026 205
- Tue 7 Jul 2026 213
- Mon 6 Jul 2026 153
- Sun 5 Jul 2026 114
- Sat 4 Jul 2026 136
- Fri 3 Jul 2026 214
- Thu 2 Jul 2026 155
- Wed 1 Jul 2026 212
- Tue 30 Jun 2026 176
- Mon 29 Jun 2026 244
- Sun 28 Jun 2026 145
- Sat 27 Jun 2026 174
- Fri 26 Jun 2026 186
- Thu 25 Jun 2026 162
- Wed 24 Jun 2026 124
- Tue 23 Jun 2026 118
- Mon 22 Jun 2026 213
- Sun 21 Jun 2026 123
- Sat 20 Jun 2026 200
- Fri 19 Jun 2026 198
- Thu 18 Jun 2026 188
- Wed 17 Jun 2026 107
- Tue 16 Jun 2026 139
- Mon 15 Jun 2026 171
- Sun 14 Jun 2026 250
- Sat 13 Jun 2026 136
- Fri 12 Jun 2026 131
- Thu 11 Jun 2026 165
- Wed 10 Jun 2026 196
- Tue 9 Jun 2026 123
- Mon 8 Jun 2026 135
- Sun 7 Jun 2026 118
- Sat 6 Jun 2026 160
- Fri 5 Jun 2026 173
- Thu 4 Jun 2026 220
- Wed 3 Jun 2026 168
- Tue 2 Jun 2026 122
- Mon 1 Jun 2026 168
- Sun 31 May 2026 114
- Sat 30 May 2026 130
- Fri 29 May 2026 594
- Thu 28 May 2026 0
- Wed 27 May 2026 0
- Tue 26 May 2026 53
- Mon 25 May 2026 163
- Sun 24 May 2026 228
- Sat 23 May 2026 150
- Fri 22 May 2026 143
Check your own exposure
2,124 incidents in the last 90 days named organizations in Government Administration. 8.9% of all incidents
- Access sold 13%
- Ransomware and extortion 3%
- Data exposed 27%
- Disruption 55%
Counted from every incident in the window, not sampled.
2,148 incidents in the last 90 days named organizations in USA. 9.0% of all incidents
- Access sold 14%
- Ransomware and extortion 41%
- Data exposed 31%
- Disruption 12%
Counted from every incident in the window, not sampled.
GLOBAL THREAT VIEW
Attack Flows
Drag to rotate
Tracking 12 attack routes over the last 7d. Busiest is Brazil to Hong Kong at 3% of observed attack traffic. Each line is a country pair, and the more traffic it carries the brighter and busier it runs.
Top Network Attack Vectors
Attack Protocol Mix
Top Scanned TCP Ports
SANS ISC / DShield- 1443 · 443299,184
- 222 · 22140,327
- 323 · 23135,694
- 416767 · 16767107,109
- 5123 · 123100,065
- 680 · 8094,570
- 7853 · 85386,448
- 80 · 056,374
Top Scanned UDP Ports
SANS ISC / DShieldNo data reported
Active Malware Families
abuse.ch- 1ClearFake138
- 2IClickFix134
- 3Sliver47
- 4Vidar45
- 5Unknown malware36
Sources: Cloudflare Radar (CC BY-NC 4.0), SANS ISC / DShield, abuse.ch, CISA KEV. Updated August 21, 2026.
CODERED VTA
Emerging Threat Advisory
Our analysts publish an advisory for each vulnerability and campaign they track. Every one carries a severity, the CVE where one has been assigned, the indicators your team can hunt for, and the mitigation we recommend.




1Password Enhances Identity Security with Agentic AI Focus
1Password has appointed former AWS executive Nancy Wang as its chief technology officer to oversee the evolution of its platforms in managing new artificial intelligence-driven workflows. This move is significant as it highlights the…
Shai-Hulud Malware: A New Era of Supply Chain Attacks
The recent discovery of the Shai-Hulud malware has marked a significant shift in the landscape of supply chain attacks. This sophisticated threat has the ability to spread like a worm, compromising multiple packages and…
Cyber-fraud Surpasses Ransomware as Top Cybersecurity Concern
The World Economic Forum (WEF) has issued a warning regarding the pervasive threat of cyber-enabled fraud, which includes phishing and invoice scams, now at record highs. This threat is affecting businesses worldwide, with the…
Iran-Linked APT Group Deploys Rust-Based Implant in Ongoing Espionage Campaign
A recently discovered campaign by the Iran-linked advanced persistent threat (APT) group MuddyWater has been targeting organizations in Israel and other Middle Eastern countries. The campaign involves the use of spear-phishing emails that contain…
Exploiting AWS Cloud Service Misconfigurations for Privilege Escalation
A persistent challenge in cloud security involves the exploitation of misconfigurations within Amazon Web Services (AWS) environments, enabling attackers to bypass security controls and gain unauthorized access. These flaws are often not inherent vulnerabilities…
VMware VM Escape Vulnerability Exploited by MAESTRO Toolkit
A significant cybersecurity threat has been uncovered, where hackers utilized a secret toolkit known as MAESTRO to exploit VMware VM escape vulnerabilities. This vulnerability allows attackers to break out of a virtual machine and…
VTA – Ni8mare Flaw Exposes n8n Automation Servers to Unauthenticated Takeover
A critical vulnerability in n8n, a widely used open-source workflow automation platform that connects applications, APIs and internal services to streamline business processes. Tracked as CVE-2026-21858 and nicknamed “Ni8mare,” this flaw has been assigned…
Intel Platform Vulnerability: Memory Corruption in punit_ipc
A recently discovered vulnerability in Intel's punit_ipc component has raised concerns among cybersecurity experts. The vulnerability, identified as CVE-2025-68303, affects Intel's platform/x86 architecture and could potentially lead to memory corruption. This issue can be…
Threat Actors Leverage AI Tools for Enhanced Malware Capabilities
The Google Threat Intelligence Group (GTIG) has identified a significant shift in the threat landscape, with adversaries increasingly utilizing artificial intelligence (AI) tools to enhance their malware capabilities. This marks a new operational phase…
CODERED VTA
Get advisories as we publish them
Our analysts write these up as they track them. Join the mailing list and each one reaches you without you having to check back.
Subscribe to advisories