Threat Landscape

Real-time data from CISA and NIST demonstrates why continuous information security is not optional — it is a necessity.

Global threat activity

Real-time data from multiple open threat databases shows where cyber attacks originate and how they target European countries.

Attack traffic (SANS)
Malware C2 (ThreatFox)
Blocklist (Blocklist.de)
Malware distribution (URLhaus)
Compromised (ET)
Known threats (CI Army)
European targets

Threat source summary

Aggregated statistics from the six threat databases visualised on the map.

Threat sources – geographic spread

Attack traffic (SANS)
897,027,767 indicators · 30 countries
Blocklist (Blocklist.de)
100 indicators · 25 countries
Known threats (CI Army)
98 indicators · 25 countries
Compromised (ET)
100 indicators · 22 countries
Malware C2 (ThreatFox)
100 indicators · 19 countries
Malware distribution (URLhaus)
100 indicators · 14 countries

Top 5 source countries

1United States
274,569,721
2Netherlands
102,545,516
3Bulgaria
90,873,389
4France
54,979,340
5Germany
41,769,284

Total indicator count aggregated across all sources.

1,647

Actively exploited vulnerabilities

24

New in the last 30 days

2,642

New CVEs in the last 7 days

17

Critical (CVSS 9.0+)

37

High (CVSS 7.0–8.9)

Vendors with active remediation deadlines

KNX Association 1 active vulnerabilities
Microsoft 1 active vulnerabilities

Ransomware share

20%
Ransomware-linked
Unknown link

329 / 1,647

Critical CVEs in the last 7 days

The five most severe new vulnerabilities with a CVSS score of 9.0 or higher.

9.6
CVE-2026-11563

14 Jul 2026

The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authent...

Critical
9.2
CVE-2026-15183

14 Jul 2026

Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQ...

Critical
9.0
CVE-2026-57898

14 Jul 2026

In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS t...

Critical
9.1
CVE-2026-59083

14 Jul 2026

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 1...

Critical
9.1
CVE-2026-59084

14 Jul 2026

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomca...

Critical

Latest exploited vulnerabilities

CVE-2026-58644 Unknown

Microsoft

SharePoint

16 Jul 2026

CVE-2026-25089 Unknown

Fortinet

FortiSandbox

16 Jul 2026

CVE-2026-39808 Unknown

Fortinet

FortiSandbox

16 Jul 2026

CVE-2026-46817 Unknown

Oracle

E-Business Suite

15 Jul 2026

CVE-2023-4346 Unknown

KNX Association

KNX Protocol Connection Authorization Option 1

15 Jul 2026

CVE-2026-56155 Unknown

Microsoft

Active Directory Federation Services

14 Jul 2026

CVE-2026-56164 Unknown

Microsoft

SharePoint Server

14 Jul 2026

CVE-2026-15409 Unknown

SonicWall

SMA1000 Appliances

14 Jul 2026

CVE-2026-15410 Unknown

SonicWall

SMA1000 Appliances

14 Jul 2026

CVE-2008-4128 Unknown

Cisco

IOS

13 Jul 2026

Why it matters

The threat landscape changes daily

The data above comes directly from the US agencies CISA and NIST. It clearly shows that new threats and vulnerabilities are discovered continuously — and that attackers are actively exploiting them.

New vulnerabilities every day

Hundreds of new CVEs are published every week. Without systematic monitoring, you risk missing critical updates.

Ransomware-linked threats are growing

A significant share of actively exploited vulnerabilities have known links to ransomware campaigns.

Regulatory requirements are tightening

NIS2 and the Cybersecurity Act require organisations to work continuously on risk management and incident preparedness.

Source: CISA Known Exploited Vulnerabilities Source: NIST National Vulnerability Database Source: SANS ISC Source: ThreatFox (abuse.ch) Source: Blocklist.de Source: URLhaus (abuse.ch) Source: Emerging Threats Source: CI Army
Last updated: 21 Jul 2026

Ready to strengthen your cybersecurity?

Book a free meeting and we will discuss how we can help your organisation meet the new requirements.

Book a meeting