Threat Landscape

Real-time data from CISA and NIST demonstrates why continuous information security is not optional — it is a necessity.

Global threat activity

Real-time data from multiple open threat databases shows where cyber attacks originate and how they target European countries.

Attack traffic (SANS)
Malware C2 (ThreatFox)
Blocklist (Blocklist.de)
Malware distribution (URLhaus)
Compromised (ET)
Known threats (CI Army)
European targets

Threat source summary

Aggregated statistics from the six threat databases visualised on the map.

Threat sources – geographic spread

Attack traffic (SANS)
548,315,247 indicators · 30 countries
Blocklist (Blocklist.de)
93 indicators · 25 countries
Known threats (CI Army)
100 indicators · 24 countries
Malware distribution (URLhaus)
100 indicators · 20 countries
Compromised (ET)
100 indicators · 20 countries
Malware C2 (ThreatFox)
100 indicators · 19 countries

Top 5 source countries

1United States
160,379,285
2Netherlands
82,216,920
3Canada
44,958,277
4France
44,859,158
5Bulgaria
42,480,643

Total indicator count aggregated across all sources.

1,734

Actively exploited vulnerabilities

39

New in the last 30 days

2,766

New CVEs in the last 7 days

16

Critical (CVSS 9.0+)

50

High (CVSS 7.0–8.9)

Vendors with active remediation deadlines

Ransomware share

21%
Ransomware-linked
Unknown link

361 / 1,734

Critical CVEs in the last 7 days

The five most severe new vulnerabilities with a CVSS score of 9.0 or higher.

9.3
CVE-2026-13043

1 Oct 2026

A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access...

Critical
9.8
CVE-2026-56154

1 Oct 2026

Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Critical
9.8
CVE-2026-57941

1 Oct 2026

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Critical
9.8
CVE-2026-59797

1 Oct 2026

Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Critical
9.9
CVE-2026-96658

1 Oct 2026

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to impr...

Critical

Latest exploited vulnerabilities

CVE-2026-88779 Unknown

Citrix

NetScaler

4 Oct 2026

CVE-2026-102490 Unknown

Zammad GmbH

Zammad

2 Oct 2026

CVE-2026-102489 Unknown

Zammad GmbH

Zammad

2 Oct 2026

CVE-2026-104286 Unknown

Fortinet

FortiMail

1 Oct 2026

CVE-2026-76504 Unknown

Cisco

Catalyst SD-WAN Manager

30 Sept 2026

CVE-2026-86950 Unknown

Apple

Multiple Products

29 Sept 2026

CVE-2026-88772 Unknown

Citrix

NetScaler

27 Sept 2026

CVE-2026-88771 Unknown

Citrix

NetScaler

27 Sept 2026

CVE-2026-67279 Unknown

MikroTik

RouterOS

25 Sept 2026

CVE-2026-65660 Unknown

Microsoft

SharePoint

25 Sept 2026

Why it matters

The threat landscape changes daily

The data above comes directly from the US agencies CISA and NIST. It clearly shows that new threats and vulnerabilities are discovered continuously — and that attackers are actively exploiting them.

New vulnerabilities every day

Hundreds of new CVEs are published every week. Without systematic monitoring, you risk missing critical updates.

Ransomware-linked threats are growing

A significant share of actively exploited vulnerabilities have known links to ransomware campaigns.

Regulatory requirements are tightening

NIS2 and the Cybersecurity Act require organisations to work continuously on risk management and incident preparedness.

Source: CISA Known Exploited Vulnerabilities Source: NIST National Vulnerability Database Source: SANS ISC Source: ThreatFox (abuse.ch) Source: Blocklist.de Source: URLhaus (abuse.ch) Source: Emerging Threats Source: CI Army
Last updated: 8 Oct 2026

Ready to strengthen your cybersecurity?

Book a free meeting and we will discuss how we can help your organisation meet the new requirements.

Book a meeting