Threat Landscape

Real-time data from CISA and NIST demonstrates why continuous information security is not optional — it is a necessity.

Global threat activity

Real-time data from multiple open threat databases shows where cyber attacks originate and how they target European countries.

Attack traffic (SANS)
Malware C2 (ThreatFox)
Blocklist (Blocklist.de)
Malware distribution (URLhaus)
Compromised (ET)
Known threats (CI Army)
European targets

Threat source summary

Aggregated statistics from the six threat databases visualised on the map.

Threat sources – geographic spread

Attack traffic (SANS)
773,000,588 indicators · 30 countries
Blocklist (Blocklist.de)
98 indicators · 25 countries
Compromised (ET)
99 indicators · 25 countries
Known threats (CI Army)
100 indicators · 20 countries
Malware C2 (ThreatFox)
100 indicators · 19 countries
Malware distribution (URLhaus)
100 indicators · 14 countries

Top 5 source countries

1United States
238,587,669
2Netherlands
66,990,076
3Turkey
61,962,604
4Bulgaria
48,788,988
5Ukraine
45,803,209

Total indicator count aggregated across all sources.

1,590

Actively exploited vulnerabilities

31

New in the last 30 days

1,650

New CVEs in the last 7 days

26

Critical (CVSS 9.0+)

33

High (CVSS 7.0–8.9)

Vendors with active remediation deadlines

BerriAI 1 active vulnerabilities
Linux 1 active vulnerabilities
ConnectWise 1 active vulnerabilities
Microsoft 1 active vulnerabilities

Ransomware share

20%
Ransomware-linked
Unknown link

318 / 1,590

Critical CVEs in the last 7 days

The five most severe new vulnerabilities with a CVSS score of 9.0 or higher.

9.8
CVE-2025-70067

4 May 2026

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX fi...

Critical
9.3
CVE-2025-13605

4 May 2026

3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context of the root user by providing pay...

Critical
9.8
CVE-2026-24118

4 May 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox a...

Critical
9.8
CVE-2026-24120

4 May 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the ...

Critical
9.8
CVE-2026-24781

4 May 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can ...

Critical

Latest exploited vulnerabilities

CVE-2026-42208 Unknown

BerriAI

LiteLLM

8 May 2026

CVE-2026-6973 Unknown

Ivanti

Endpoint Manager Mobile (EPMM)

7 May 2026

CVE-2026-0300 Unknown

Palo Alto Networks

PAN-OS

6 May 2026

CVE-2026-31431 Unknown

Linux

Kernel

1 May 2026

CVE-2026-41940 Known

WebPros

cPanel & WHM and WP2 (WordPress Squared)

30 Apr 2026

CVE-2024-1708 Unknown

ConnectWise

ScreenConnect

28 Apr 2026

CVE-2026-32202 Unknown

Microsoft

Windows

28 Apr 2026

CVE-2025-29635 Unknown

D-Link

DIR-823X

24 Apr 2026

CVE-2024-7399 Unknown

Samsung

MagicINFO 9 Server

24 Apr 2026

CVE-2024-57728 Unknown

SimpleHelp

SimpleHelp

24 Apr 2026

Why it matters

The threat landscape changes daily

The data above comes directly from the US agencies CISA and NIST. It clearly shows that new threats and vulnerabilities are discovered continuously — and that attackers are actively exploiting them.

New vulnerabilities every day

Hundreds of new CVEs are published every week. Without systematic monitoring, you risk missing critical updates.

Ransomware-linked threats are growing

A significant share of actively exploited vulnerabilities have known links to ransomware campaigns.

Regulatory requirements are tightening

NIS2 and the Cybersecurity Act require organisations to work continuously on risk management and incident preparedness.

Source: CISA Known Exploited Vulnerabilities Source: NIST National Vulnerability Database Source: SANS ISC Source: ThreatFox (abuse.ch) Source: Blocklist.de Source: URLhaus (abuse.ch) Source: Emerging Threats Source: CI Army
Last updated: 11 May 2026

Ready to strengthen your cybersecurity?

Book a free meeting and we will discuss how we can help your organisation meet the new requirements.

Book a meeting