Conditions
Internet threat level
- GREEN
- YELLOW
- ORANGE
- RED
59 days at this level
SANS Internet Storm Center · current level · checked hourly · read just now · live
10.3%
of global email is malicious
Cloudflare Radar · 7-day · checked hourly · read just now · live
129,451
malicious IPs tracked
IPsum · 24h · checked daily · read 18h ago · live
For leadership
What this costs
87.6%
of malicious email impersonates a trusted brand or contact
Cloudflare Radar · 7-day · checked every 6 hours · read 4h ago · live
$2.77B
reported business email compromise losses in 2024
FBI IC3 2024 Internet Crime Report · as of 2025-04
217 ▲
ransomware victim claims posted this week
RansomLook · 7-day · checked every 6 hours · read 3h ago · live
Ransomware figures count unverified breach claims posted to leak sites; individual victim names are never published — a claim is not a confirmation.
What to ask your team
- Brand impersonation Do we publish DMARC, and is it set to reject or only to monitor?
- Payment fraud When a supplier asks us to change their bank details, how do we verify that request through a channel we already had?
- Ransomware When did we last restore from a backup, rather than confirm that one exists?
Questions, not recommendations — Panotech sells nothing and takes no vendor commissions. Each one is answerable inside your own organisation.
For IT
Patch these first
- 01 Cisco Secure Email Gateway CVE-2026-76461 added 0d ago
- 02 GitLab Community Edition and Enterprise Edition CVE-2026-85706 added 3d ago
- 03 JFrog Artifactory CVE-2026-42018 added 3d ago
- 04 JFrog Artifactory CVE-2026-42016 added 3d ago
- 05 ConnectWise ScreenConnect CVE-2026-84869 added 3d ago
Software with vulnerabilities under active exploitation, newest first. If it's on this list and in your stack, patch it before anything else.
CISA KEV Catalog · 45-day window · checked every 6 hours · read 2h ago · live
Email authentication adoption
- DMARC 89%
- SPF 79.9%
- DKIM 90%
Share of observed email passing each authentication check — higher adoption makes sender spoofing harder for everyone.
Cloudflare Radar · 7-day · checked daily · read 19h ago · live
Where brute force is hitting
- Email (SMTP) 13,379
- Web servers 9,364
- SSH logins 5,177
- Email (IMAP) 4,150
- Website logins 935
23,756 unique attacking IPs across all services in the last 48 hours — reported by the victims' own servers, an independent measure from the aggregated IPsum count above. Services overlap, so their figures are never summed.
Blocklist.de · 48h window · checked twice daily · read 6h ago · live
Latest CISA advisories
11
advisories published by CISA in the last 7 days
Newest: CISA Adds Three Known Exploited Vulnerabilities to Catalog (11 Sep 2026).
CISA Cybersecurity Advisories · 7-day window · checked twice daily · read 4h ago · live
For everyone
What to watch for
19.5%
of login attempts screened by Cloudflare used a password already leaked in a breach — reusing one password exposes every account that shares it
Cloudflare Radar · 7-day · checked twice daily · read 4h ago · live
926 ▲
suspected phishing sites currently flagged as active
phishunt.io · live list · checked every 6 hours · read 2h ago · live
Phishing figures count sites flagged by automated heuristics — suspicion, not verified findings; a suspected site is not a confirmed one.
If you remember one thing today
Before signing in from a link, read the address bar. A fake page can be a perfect copy, so attackers rely on lookalike names instead.
Panotech Sensor Network
What our own sensors saw
Most of this is automated scanning — scripts sweeping the entire internet for common software, not an attack aimed at anyone in particular. It is the background noise every internet-connected business receives.
4,322
attacks observed in the last 7 days
547
unique sources in the last 7 days
Prior 7-day window: 3,888 attacks from 833 sources — attack volume is up 11% week-over-week; the number of sources is down 34%. Attacks per source rose from 4.7 to 7.9 — narrower, deeper scanning: fewer machines, each doing more.
Top attacking networks
| Network | Attacks | Sources | Per IP |
|---|---|---|---|
| OVH SAS | 361 | 3 | 120.3▲ |
| Oracle Svenska AB | 347 | 3 | 115.7▲ |
| DigitalOcean, LLC | 230 | 28 | 8.2 |
| HostRoyale Technologies Pvt Ltd | 201 | 1 | 201▲ |
| Google LLC | 178 | 22 | 8.1 |
| Bharti Airtel Limited | 144 | 8 | 18▲ |
| Tencent cloud computing (Beijing) Co., Ltd. | 100 | 1 | 100▲ |
| Microsoft Corporation | 85 | 6 | 14.2▲ |
| COGENT E-SERVICES PVT LTD | 82 | 1 | 82▲ |
| HOME_DSL | 82 | 3 | 27.3▲ |
▲ High attacks-per-source indicates dedicated attack infrastructure rather than compromised cloud hosts.
Attack categories
- WordPress Login Probe 3,680
- Web App Probe 104
- Laravel Env Probe 95
- API User Enum 91
- Git Config Probe 77
- API Schema Probe 53
- GraphQL Probe 46
- Spring Boot Actuator 34
- Confluence Exploit 30
- Exchange Exploit 30
- Webshell Recon 23
- WordPress Plugin Exploit 13
- MCP Handshake Probe 10
- phpMyAdmin Probe 8
- Other 28
Countries of origin
- India 1,025
- France 619
- United States 348
- Saudi Arabia 230
- Philippines 217
- Germany 160
- Pakistan 139
- Brazil 118
- South Africa 115
- China 108
- Netherlands 96
- United Arab Emirates 89
- Lithuania 85
- Poland 79
- Other 894
ATT&CK techniques observed
The same attacks, grouped by what the attacker was trying to achieve — in MITRE ATT&CK® terms, the shared vocabulary IT teams use to compare notes across vendors.
- Password guessing T1110.001 3,688
- Vulnerability scanning T1595.002 294
- Credentials in files T1552.001 212
- Exploiting public-facing apps T1190 90
- Active scanning T1595.003 23
- Command & scripting T1059 10
- Other 5
Attacks by hour of day (UTC)
Benign crawlers are excluded from every figure above. Attacker-reported tooling is not shown; it is forgeable. Counts under 5 are withheld — precision aids sensor fingerprinting. Aggregates are free to reuse with attribution for non-commercial purposes (CC BY-NC 4.0).
Panotech Sensor Network · 7-day window · checked hourly · read 12m ago · live