PANOTECH Consulting & Services Group

Science · Technology · Common Sense

Cyber Vitals

A plain-language read on current internet threat conditions — rebuilt every hour, with every source and its age shown on its face.

An instrument, not an advertisement. Every reading shows where it came from and how old it is, the page runs no JavaScript, and nothing here is for sale.

Conditions

Internet threat level

  1. GREEN
  2. YELLOW
  3. ORANGE
  4. RED

59 days at this level

SANS Internet Storm Center · current level · checked hourly · read just now · live

10.3%

of global email is malicious

Cloudflare Radar · 7-day · checked hourly · read just now · live

129,451

malicious IPs tracked

IPsum · 24h · checked daily · read 18h ago · live

For leadership

What this costs

87.6%

of malicious email impersonates a trusted brand or contact

Cloudflare Radar · 7-day · checked every 6 hours · read 4h ago · live

$2.77B

reported business email compromise losses in 2024

FBI IC3 2024 Internet Crime Report · as of 2025-04

217

ransomware victim claims posted this week

RansomLook · 7-day · checked every 6 hours · read 3h ago · live

Ransomware figures count unverified breach claims posted to leak sites; individual victim names are never published — a claim is not a confirmation.

What to ask your team

  • Brand impersonation Do we publish DMARC, and is it set to reject or only to monitor?
  • Payment fraud When a supplier asks us to change their bank details, how do we verify that request through a channel we already had?
  • Ransomware When did we last restore from a backup, rather than confirm that one exists?

Questions, not recommendations — Panotech sells nothing and takes no vendor commissions. Each one is answerable inside your own organisation.

For IT

Patch these first

  1. 01 Cisco Secure Email Gateway CVE-2026-76461 added 0d ago
  2. 02 GitLab Community Edition and Enterprise Edition CVE-2026-85706 added 3d ago
  3. 03 JFrog Artifactory CVE-2026-42018 added 3d ago
  4. 04 JFrog Artifactory CVE-2026-42016 added 3d ago
  5. 05 ConnectWise ScreenConnect CVE-2026-84869 added 3d ago

Software with vulnerabilities under active exploitation, newest first. If it's on this list and in your stack, patch it before anything else.

CISA KEV Catalog · 45-day window · checked every 6 hours · read 2h ago · live

Email authentication adoption

  1. DMARC 89%
  2. SPF 79.9%
  3. DKIM 90%

Share of observed email passing each authentication check — higher adoption makes sender spoofing harder for everyone.

Cloudflare Radar · 7-day · checked daily · read 19h ago · live

Where brute force is hitting

  1. Email (SMTP) 13,379
  2. Web servers 9,364
  3. SSH logins 5,177
  4. Email (IMAP) 4,150
  5. Website logins 935

23,756 unique attacking IPs across all services in the last 48 hours — reported by the victims' own servers, an independent measure from the aggregated IPsum count above. Services overlap, so their figures are never summed.

Blocklist.de · 48h window · checked twice daily · read 6h ago · live

Latest CISA advisories

11

advisories published by CISA in the last 7 days

Newest: CISA Adds Three Known Exploited Vulnerabilities to Catalog (11 Sep 2026).

CISA Cybersecurity Advisories · 7-day window · checked twice daily · read 4h ago · live

For everyone

What to watch for

19.5%

of login attempts screened by Cloudflare used a password already leaked in a breach — reusing one password exposes every account that shares it

Cloudflare Radar · 7-day · checked twice daily · read 4h ago · live

926

suspected phishing sites currently flagged as active

phishunt.io · live list · checked every 6 hours · read 2h ago · live

Phishing figures count sites flagged by automated heuristics — suspicion, not verified findings; a suspected site is not a confirmed one.

If you remember one thing today

Before signing in from a link, read the address bar. A fake page can be a perfect copy, so attackers rely on lookalike names instead.

Panotech Sensor Network

What our own sensors saw

Most of this is automated scanning — scripts sweeping the entire internet for common software, not an attack aimed at anyone in particular. It is the background noise every internet-connected business receives.

4,322

attacks observed in the last 7 days

547

unique sources in the last 7 days

Prior 7-day window: 3,888 attacks from 833 sources — attack volume is up 11% week-over-week; the number of sources is down 34%. Attacks per source rose from 4.7 to 7.9 — narrower, deeper scanning: fewer machines, each doing more.

Top attacking networks

Top attacking networks over the window
NetworkAttacks SourcesPer IP
OVH SAS 361 3 120.3
Oracle Svenska AB 347 3 115.7
DigitalOcean, LLC 230 28 8.2
HostRoyale Technologies Pvt Ltd 201 1 201
Google LLC 178 22 8.1
Bharti Airtel Limited 144 8 18
Tencent cloud computing (Beijing) Co., Ltd. 100 1 100
Microsoft Corporation 85 6 14.2
COGENT E-SERVICES PVT LTD 82 1 82
HOME_DSL 82 3 27.3

High attacks-per-source indicates dedicated attack infrastructure rather than compromised cloud hosts.

Attack categories

  1. WordPress Login Probe 3,680
  2. Web App Probe 104
  3. Laravel Env Probe 95
  4. API User Enum 91
  5. Git Config Probe 77
  6. API Schema Probe 53
  7. GraphQL Probe 46
  8. Spring Boot Actuator 34
  9. Confluence Exploit 30
  10. Exchange Exploit 30
  11. Webshell Recon 23
  12. WordPress Plugin Exploit 13
  13. MCP Handshake Probe 10
  14. phpMyAdmin Probe 8
  15. Other 28

Countries of origin

  1. India 1,025
  2. France 619
  3. United States 348
  4. Saudi Arabia 230
  5. Philippines 217
  6. Germany 160
  7. Pakistan 139
  8. Brazil 118
  9. South Africa 115
  10. China 108
  11. Netherlands 96
  12. United Arab Emirates 89
  13. Lithuania 85
  14. Poland 79
  15. Other 894

ATT&CK techniques observed

The same attacks, grouped by what the attacker was trying to achieve — in MITRE ATT&CK® terms, the shared vocabulary IT teams use to compare notes across vendors.

  1. Password guessing T1110.001 3,688
  2. Vulnerability scanning T1595.002 294
  3. Credentials in files T1552.001 212
  4. Exploiting public-facing apps T1190 90
  5. Active scanning T1595.003 23
  6. Command & scripting T1059 10
  7. Other 5

Attacks by hour of day (UTC)

00:00–00:59 UTC · 136 attacks01:00–01:59 UTC · 37 attacks02:00–02:59 UTC · 191 attacks03:00–03:59 UTC · 114 attacks04:00–04:59 UTC · 172 attacks05:00–05:59 UTC · 147 attacks06:00–06:59 UTC · 261 attacks07:00–07:59 UTC · 415 attacks41508:00–08:59 UTC · 190 attacks09:00–09:59 UTC · 272 attacks10:00–10:59 UTC · 235 attacks11:00–11:59 UTC · 170 attacks12:00–12:59 UTC · 165 attacks13:00–13:59 UTC · 131 attacks14:00–14:59 UTC · 148 attacks15:00–15:59 UTC · 105 attacks16:00–16:59 UTC · 122 attacks17:00–17:59 UTC · 214 attacks18:00–18:59 UTC · 111 attacks19:00–19:59 UTC · 183 attacks20:00–20:59 UTC · 301 attacks21:00–21:59 UTC · 194 attacks22:00–22:59 UTC · 189 attacks23:00–23:59 UTC · 119 attacks

Benign crawlers are excluded from every figure above. Attacker-reported tooling is not shown; it is forgeable. Counts under 5 are withheld — precision aids sensor fingerprinting. Aggregates are free to reuse with attribution for non-commercial purposes (CC BY-NC 4.0).

Panotech Sensor Network · 7-day window · checked hourly · read 12m ago · live