https://shadowserver.org/partner
Background on CVE-2023-20198/CVE-2023-20273 & the BadCandy implant from over 2 years ago:
blog.talosintelligence.com/active-explo...
#CyberCivilDefense
Background on CVE-2023-20198/CVE-2023-20273 & the BadCandy implant from over 2 years ago:
blog.talosintelligence.com/active-explo...
#CyberCivilDefense
Geo breakdown of implanted Cisco IOS XE: dashboard.shadowserver.org/statistics/c...
IP data shared daily with National CSIRTs worldwide & subscribed impacted network owners: www.shadowserver.org/what-we-do/n...
Geo breakdown of implanted Cisco IOS XE: dashboard.shadowserver.org/statistics/c...
IP data shared daily with National CSIRTs worldwide & subscribed impacted network owners: www.shadowserver.org/what-we-do/n...
Results are based on versions returned.
CVE-2025-40778 Public Dashboard tracker: dashboard.shadowserver.org/statistics/c...
NVD entry: nvd.nist.gov/vuln/detail/...
#CyberCivilDefense
Results are based on versions returned.
CVE-2025-40778 Public Dashboard tracker: dashboard.shadowserver.org/statistics/c...
NVD entry: nvd.nist.gov/vuln/detail/...
#CyberCivilDefense
Microsoft Advisory: msrc.microsoft.com/update-guide...
HawkTrace writeup:
hawktrace.com/blog/CVE-202...
Huntress writeup: www.huntress.com/blog/exploit...
Eye Security writeup: research.eye.security/wsus-deseria...
Microsoft Advisory: msrc.microsoft.com/update-guide...
HawkTrace writeup:
hawktrace.com/blog/CVE-202...
Huntress writeup: www.huntress.com/blog/exploit...
Eye Security writeup: research.eye.security/wsus-deseria...
dashboard.shadowserver.org/statistics/i...
This vulnerability is on US CISA KEV: www.cisa.gov/known-exploi...
dashboard.shadowserver.org/statistics/i...
This vulnerability is on US CISA KEV: www.cisa.gov/known-exploi...
Geo distribution (World Map):
dashboard.shadowserver.org/statistics/i...
Geo distribution (World Map):
dashboard.shadowserver.org/statistics/i...
dashboard.shadowserver.org/statistics/c...
For background and detection methodology, please read: labs.watchtowr.com/yikes-watchg... (thanks watchTowr!)
Patch information from WatchGuard is here: www.watchguard.com/wgrd-psirt/a...
#CyberCivilDefense
dashboard.shadowserver.org/statistics/c...
For background and detection methodology, please read: labs.watchtowr.com/yikes-watchg... (thanks watchTowr!)
Patch information from WatchGuard is here: www.watchguard.com/wgrd-psirt/a...
#CyberCivilDefense
Geo breakdown (world map):
dashboard.shadowserver.org/statistics/c...
Geo breakdown (tree map): dashboard.shadowserver.org/statistics/c...
Geo breakdown (world map):
dashboard.shadowserver.org/statistics/c...
Geo breakdown (tree map): dashboard.shadowserver.org/statistics/c...
dashboard.shadowserver.org/statistics/i...
#CyberCivilDefense
dashboard.shadowserver.org/statistics/i...
#CyberCivilDefense
www.cisa.gov/news-events/...
www.ncsc.gov.uk/news/confirm...
www.cisa.gov/news-events/...
www.ncsc.gov.uk/news/confirm...
dashboard.shadowserver.org/statistics/i...
#CyberCivilDefense
dashboard.shadowserver.org/statistics/i...
#CyberCivilDefense
www.cisa.gov/news-events/...
www.ncsc.gov.uk/news/confirm...
www.cisa.gov/news-events/...
www.ncsc.gov.uk/news/confirm...
We are also in the process of expanding Oracle E-Business Suite exposure, which you can track here: dashboard.shadowserver.org/statistics/i...
We are also in the process of expanding Oracle E-Business Suite exposure, which you can track here: dashboard.shadowserver.org/statistics/i...
Tracker: dashboard.shadowserver.org/statistics/c...
If you receive an alert from us, please assume compromise (see also US CISA KEV list)
Patch info from Oracle:
www.oracle.com/security-ale...
Background: www.ncsc.gov.uk/news/active-...
Tracker: dashboard.shadowserver.org/statistics/c...
If you receive an alert from us, please assume compromise (see also US CISA KEV list)
Patch info from Oracle:
www.oracle.com/security-ale...
Background: www.ncsc.gov.uk/news/active-...
US CISA ED-25-03 Identify and Mitigate Potential Compromise of Cisco Devices: www.cisa.gov/news-events/...
#CyberCivilDefense
US CISA ED-25-03 Identify and Mitigate Potential Compromise of Cisco Devices: www.cisa.gov/news-events/...
#CyberCivilDefense
Cisco advisories with patch info:
CVE-2025-20333: sec.cloudapps.cisco.com/security/cen...
CVE-2025-20362:
sec.cloudapps.cisco.com/security/cen...
Cisco advisories with patch info:
CVE-2025-20333: sec.cloudapps.cisco.com/security/cen...
CVE-2025-20362:
sec.cloudapps.cisco.com/security/cen...