Using ELK & interested in automating ingestion of our threat intel for your network/constituency via our API?
We have introduced an ECS logging script for our intelligence reports. This script uses Redis to queue events for Logstash.
Check it out at https://t.co/feZj5D03uV
Check your network logs and endpoint telemetry for connections to benign "lighthouse" IP address 164.92.88[.]210 - any activity suggests Glassworm infections, which require immediate remediation
Very happy to support @CrowdStrike and @Google in disruption of the Glassworm botnet, which features 4x C2 channels, and targets developers via open-source supply chains:
https://t.co/oDYfav7iGw
Daily aggregated country level statistics available via our public Dashboard:
Graph
https://t.co/Y4bdSy04sB
Heatmap
https://t.co/cZPvOrMjCL
Worldmap
https://t.co/gMpJzrp2Ee
The project was launched by the ECOWAS Commission in collaboration with Germany’s G7 presidency in 2022, commissioned by the German Federal Foreign Office & the European Union Commission in 2023 & implemented by Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH.
We published a "Shadowserver-in-a-box" platform based on IntelMQ + ELK that can ingest, process and visualize our threat/vulnerability/victim data feeds. Available as a VM or Docker image for free download. Use it for training or in production!
https://t.co/nBPIbUqXGV
Development was supported by the cyber capacity building project under the ECOWAS-G7 partnership for cybersecurity, the “Joint Platform for Advancing Cyber Security” (JPAC) in West Africa.
@ecowas_cedeao@G7@EU_Commission@GermanyDiplo@giz_gmbh
IP data for your network/constituency shared in Vulnerable HTTP reporting, tagged 'cve-2026-30893: https://t.co/qxv0Gv5ELc
Public Dashboard tree map view: https://t.co/Jr7bzsyr7T
NVD entry: https://t.co/oR78XI9dgI
#CyberCivilDefense
We are scanning & reporting daily Wazuh CVE-2026-30893 (CVSS 9.9) vulnerable instances, with over 3500 IPs seen unpatched on 2026-05-10. See advisory & update to latest version: https://t.co/Frefega3U6 ...
Worth keeping your security platforms up to date!
Raw IP data in our Vulnerable HTTP reporting https://t.co/qxv0Gv5ELc tagged 'cve-2026-6973'
Public Dashboard tree map overview of vulnerable instances:
https://t.co/76q2si1uwt
CVE-2026-6973 patch tracker:
https://t.co/NzAd4AquHR
We are tagging CVE-2026-6973 Ivanti EPMM instances seen in our daily scans. 362 IPs seen unpatched on 2026-05-10, down from 562 IPs on 2026-05-08 when we first added the detection. See Ivanti advisory for details - https://t.co/GEQ6DvXFj0
CVE-2026-6973 is on @CISACyber KEV.
Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: https://t.co/z4sRvdaBwt
See Public Dashboard for stats: https://t.co/qFz265JDIK
- Honeypot Brute Force Events Report
https://t.co/Nb0MJ4Rj1b
You can also find exposed cPanel/WHM instances in our Device ID reporting with ~650K IPs seen hosting https://t.co/wqLO2F0pPc
Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: https://t.co/z4sRvdaBwt
See Public Dashboard for stats: https://t.co/qFz265JDIK
You can find likely newly compromised instances in our honeypot based reports with cPanel set in the device_vendor of the attacking device
- Darknet Events Report https://t.co/zHGkIYxGMH
- Honeypot HTTP Scanner Events Report
https://t.co/0nP5Z66SWx
IP data in Vulnerable HTTP reporting: https://t.co/qxv0Gv5ELc
See https://t.co/t8SNSOs2vr for patch info.
Dashboard World Map view: https://t.co/VwpSA7trZ3
Dashboard Tree Map view: https://t.co/LmFThJsCdM
CVE-2025-48700 Tracker: https://t.co/HLn9kNebv4
We are scanning/reporting daily Zimbra Collaboration Suite instances vulnerable to CVE-2025-48700, that can allow unauthorized access to sensitive information. This vulnerability is exploited in the wild and on @CISACyber KEV. We see over 10.5K IPs unpatched 2026-04-23.
At #iWeek2026, Andy Chadwick from @Shadowserver joined us to share how their nonprofit foundation provides world-class threat intelligence at no cost to network operators and ISPs.