Threat Landscape

Real-time data from CISA and NIST demonstrates why continuous information security is not optional — it is a necessity.

Global threat activity

Real-time data from multiple open threat databases shows where cyber attacks originate and how they target European countries.

Attack traffic (SANS)
Malware C2 (ThreatFox)
Blocklist (Blocklist.de)
Malware distribution (URLhaus)
Compromised (ET)
Known threats (CI Army)
European targets

Threat source summary

Aggregated statistics from the six threat databases visualised on the map.

Threat sources – geographic spread

Attack traffic (SANS)
805,824,610 indicators · 30 countries
Blocklist (Blocklist.de)
89 indicators · 25 countries
Known threats (CI Army)
100 indicators · 24 countries
Malware distribution (URLhaus)
100 indicators · 21 countries
Malware C2 (ThreatFox)
100 indicators · 19 countries
Compromised (ET)
100 indicators · 18 countries

Top 5 source countries

1United States
234,672,998
2Netherlands
111,315,828
3Bulgaria
68,648,233
4France
56,412,062
5Canada
50,414,936

Total indicator count aggregated across all sources.

1,694

Actively exploited vulnerabilities

34

New in the last 30 days

2,204

New CVEs in the last 7 days

12

Critical (CVSS 9.0+)

38

High (CVSS 7.0–8.9)

Vendors with active remediation deadlines

JFrog 2 active vulnerabilities
SonicWall 2 active vulnerabilities
PaperCut 2 active vulnerabilities
Red Hat 2 active vulnerabilities
BerriAI 1 active vulnerabilities

Ransomware share

21%
Ransomware-linked
Unknown link

352 / 1,694

Critical CVEs in the last 7 days

The five most severe new vulnerabilities with a CVSS score of 9.0 or higher.

9.3
CVE-2026-82082

28 Aug 2026

NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

Critical
9.2
CVE-2026-82090

28 Aug 2026

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.

Critical
9.0
CVE-2026-40541

28 Aug 2026

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users,...

Critical
9.8
CVE-2026-76581

28 Aug 2026

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction b...

Critical
9.3
CVE-2026-78032

28 Aug 2026

SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.

Critical

Latest exploited vulnerabilities

CVE-2026-59822 Unknown

BerriAI

LiteLLM

2 Sept 2026

CVE-2026-48710 Unknown

Kludex

Starlette

2 Sept 2026

CVE-2026-49869 Unknown

Kestra

Kestra OSS

2 Sept 2026

CVE-2026-82329 Unknown

JFrog

Artifactory

2 Sept 2026

CVE-2026-9586 Unknown

Sangoma

Switchvox

2 Sept 2026

CVE-2026-83548 Unknown

SonicWall

SMA1000 Appliances

2 Sept 2026

CVE-2026-83549 Unknown

SonicWall

SMA1000 Appliances

2 Sept 2026

CVE-2026-82078 Unknown

PaperCut

NG/MF

31 Aug 2026

CVE-2026-81578 Unknown

PaperCut

NG/MF

31 Aug 2026

CVE-2023-49105 Unknown

ownCloud

ownCloud

27 Aug 2026

Why it matters

The threat landscape changes daily

The data above comes directly from the US agencies CISA and NIST. It clearly shows that new threats and vulnerabilities are discovered continuously — and that attackers are actively exploiting them.

New vulnerabilities every day

Hundreds of new CVEs are published every week. Without systematic monitoring, you risk missing critical updates.

Ransomware-linked threats are growing

A significant share of actively exploited vulnerabilities have known links to ransomware campaigns.

Regulatory requirements are tightening

NIS2 and the Cybersecurity Act require organisations to work continuously on risk management and incident preparedness.

Source: CISA Known Exploited Vulnerabilities Source: NIST National Vulnerability Database Source: SANS ISC Source: ThreatFox (abuse.ch) Source: Blocklist.de Source: URLhaus (abuse.ch) Source: Emerging Threats Source: CI Army
Last updated: 4 Sept 2026

Ready to strengthen your cybersecurity?

Book a free meeting and we will discuss how we can help your organisation meet the new requirements.

Book a meeting