
The Shadowserver Foundation
@Shadowserver
Followers
21K
Following
319
Media
533
Statuses
2K
Our mission is to make the Internet more secure by bringing to light vulnerabilities, malicious activity and emerging threats. Join our Alliance!
Global
Joined March 2009
Using ELK & interested in automating ingestion of our threat intel for your network/constituency? . We have added support for Elasticsearch Custom Logs integration for our free daily reports API. Check it out at
2
17
67
Citrix NetScaler CVE-2025-7775 patch rate as seen in our scans: . Now down from 28.2K to 12.4K. Europe patching at a faster rate than North America . (you can toggle overlapping/stacked time series on our Dashboard to compare)
ALERT: On 2025-08-26 over 28.2K Citrix instances were unpatched to CVE-2025-7775 RCE. There is exploitation in the wild confirmed by @CISACyber KEV. Patch info from Citrix: Top affected: US, Germany. Dashboard geo breakdown:
0
6
13
Caught in the middle of a political battle, @BlackRock reaffirmed its focus is helping millions of Americans save for retirement. They warned that injecting politics from either side risks undermining financial performance.
prosperityretirementalliance.com
Millions of Ameircans depend on the security of their retirement savings to live with dignity after a lifetime of hard work. That’s why the Alliance for Prosperity and a Secure Retirement (APSR)...
1
0
4
ALERT: On 2025-08-26 over 28.2K Citrix instances were unpatched to CVE-2025-7775 RCE. There is exploitation in the wild confirmed by @CISACyber KEV. Patch info from Citrix: Top affected: US, Germany. Dashboard geo breakdown:
2
40
72
Breakdown by GTP type (2025-08-19):.GTP-C-v2 with ~255K IPs seen: GTP-C-v1 with ~14K IPs seen:. GTP-U with ~18K IPs seen:. These services should not be exposed to the public Internet. #CyberCivilDefense
0
1
2
Relevant Dashboard Attacking Devices trends, with device model breakdown:. Cisco: Linksys:. https://dashboard.shado–– Araknis:.
1
0
1
We added version based N-able N-central RMM CVE-2025-8875 & CVE-2025-8876 detection to our daily scans. 1077 IPs unpatched IPs seen on 2025-08-15. Both CVEs recently added to @CISACyber KEV. Top affected: US, Canada, Netherlands, UK. Dashboard map view:
1
17
32
Still a large number of unpatched Citrix NetScaler devices likely vulnerable to CVE-2025-5777 (3312 seen) & CVE-2025-6543 (4142 seen). Both vulns are on @CISACyber KEV. The Dutch @ncsc_nl has recently released an update related to CVE-2025-6543 activity:
1
10
25
Data in Vulnerable HTTP reporting tagged 'cve-2025-41236'. Dashboard tree map: Dashboard world map: CVE-2025-41236 tracker:. Broadcom advisory: NVD entry:
support.broadcom.com
0
2
5