Skip to content

project

Shadowserver

Nonprofit that scans the internet for vulnerable and compromised systems, sharing threat data with network owners, CERTs, and law enforcement.

Known aliases

  • Shadowserver
  • Shadowserver Foundation
  • The Shadowserver Foundation

Relationships

No evidence-backed relationships are recorded.

Current stories

security5 publishers

Kiteworks clears customers to restart file-transfer servers after a weekend shutdown on a federal tip

Kiteworks lifted its worldwide shutdown advice after patching a critical flaw in a feature used by under 1% of customers. Self-hosted operators stopped and restarted on the vendor's word alone, with no CVE yet to check the fix against.

Perspective Coverage

5 publishers
Builder
Builder 23%
Operator
Operator 60%
Investor
Investor 17%

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives70
Confidence60
security5 publishers

Three days from patch to probe: SAP Commerce Cloud RCE is already being hunted

CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.

Perspective Coverage

5 publishers
Builder
Builder 26%
Operator
Operator 65%
Investor
Investor 9%

Reality

Evidence70
Adoption55
Hype gap+25
Incentives40
Confidence68
security7 publishers

Citrix called it a crash bug. It is unauthenticated RCE, and CISA gave agencies three days.

CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.

Perspective Coverage

7 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence78
Adoption50
Hype gap−40
Incentives
Insufficient
Confidence74
security6 publishers

Attackers are running code on BIG-IP APM boxes configured as OAuth authorization servers

F5 disclosed CVE-2026-94127 on September 22 with hotfixes and evidence of exploitation. It is a data plane heap overflow, so a locked-down management interface still leaves the system exploitable, and federal agencies had until September 25.

Perspective Coverage

6 publishers
Builder
Builder 19%
Operator
Operator 64%
Investor
Investor 17%

Reality

Evidence78
Adoption40
Hype gap+10
Incentives30
Confidence75