30 days of threat data. 15 critical CVEs. 41,000+ threat events from 72 countries. This is what our sensors picked up across enterprise infrastructure worldwide.
41,184threat events
2,318unique attacker IPs
198confirmed exploit attempts
72countries
1,806credential stuffing attacks
What we observed
Exploitation of Fortinet FortiGate, Ivanti Connect Secure, Citrix NetScaler, and React/Next.js platforms
High-confidence TTPs: Iranian Go Bot login brute force and credential stuffing, SAML exploitation (CVE-2026-3055), path traversal and config file access (CVE-2023-3519), curl download attempts
3 botnets identified including two Iranian State-Sponsored campaigns (suspected APT35/Charming Kitten)
Significant geographic concentration: Canada and the United States together account for 51% of all attack traffic, with Microsoft Corporation as top threat source
4 Tor exit nodes observed conducting reconnaissance or exploitation attempts
99 ransomware victims across 27 groups, with thegentlemen leading (18 victims)
TLS fingerprint intelligence: Monitoring 97 known malware signatures including Tofsee (45 variants)
React2Shell honeypot detected active worm propagation (apache.selfrep) with C2 infrastructure