Using ELK & interested in automating ingestion of our threat intel for your network/constituency via our API?
We have introduced an ECS logging script for our intelligence reports. This script uses Redis to queue events for Logstash.
Check it out at github.com/The-Shadowserver-…
We have started reporting out (daily) MikroTik instances with exposed proprietary services, such as WinBox & Bandwidth Test server (btest): shadowserver.org/what-we-do/…
Around 2.6M exposed instances shared daily. Top: Brazil, Indonesia, USA.
Tree map stats: dashboard.shadowserver.org/s…
We shared a one-off share of over 400 compromised PaperCut NG/MF instances (via CVE-2026-81578/CVE-2026-82078) observed by @GreyNoiseIO. IP data in our Compromised Website reporting for 2026-09-11, tagged 'papercut-compromise'.
Dashboard Tree Map stats: dashboard.shadowserver.org/s…
Since 2026-09-04 we are scanning/reporting daily unpatched versions of Plex Media Server in response to an advisory issued by Plex forums.plex.tv/t/important-s… for v1.43.2 & earlier. Over 36K instances found still unpatched! Top affected: US (16K)
World Map: dashboard.shadowserver.org/s…
No CVEs have been issued meaning the vulnerabilities are essentially invisible to the security community limiting an effective response.
We tag the raw IP data shared 'vulnerable-plex' in Vulnerable HTTP reporting: shadowserver.org/what-we-do/…
Tracker: dashboard.shadowserver.org/s…
At least 122,500 MikroTik devices with SSH accessible found per 24 hour scan window on 2026-09-05 (no vulnerability check).
IP data shared daily in Accessible SSH reporting shadowserver.org/what-we-do/… tagged 'mikrotik' & Device Identification reports: shadowserver.org/what-we-do/…
PaperCut MF/NG incidents: At least 204 instances found on 2026-08-31 still vulnerable to CVE-2026-82078/CVE-2026-81578 RCE that is exploited in the wild. Make sure to check for compromise & patch. Top affected: US (60).
Dashboard World Map view stats: dashboard.shadowserver.org/s…
We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: shadowserver.org/what-we-do/…
At least 21899 IPs seen unpatched 2026-08-31, top US (6.2K) & Germany (5.1K)