30 days of threat data. 15 critical CVEs. 33,000+ threat events from 74 countries. This is what our sensors picked up across enterprise infrastructure worldwide.
33,846threat events
2,530unique attacker IPs
30confirmed exploit attempts
74countries
1,806credential stuffing attacks
What we observed
Exploitation of Fortinet FortiGate, Ivanti Connect Secure, Citrix NetScaler, and React/Next.js platforms
High-confidence TTPs: Iranian Go Bot login brute force and credential stuffing, unauthorized user/group creation (CVE-2024-55591), malformed login parameter (CVE-2025-5777), curl download attempts
3 botnets identified including two Iranian State-Sponsored campaigns (suspected APT35/Charming Kitten)
Significant geographic concentration: Indonesia and the United States together account for 43% of all attack traffic, with Alibaba (US) Technology Co., Ltd. as top threat source
283 Tor exit nodes observed conducting reconnaissance or exploitation attempts
100 ransomware victims across 26 groups, with thegentlemen leading (25 victims)
TLS fingerprint intelligence: Monitoring 97 known malware signatures including Tofsee (45 variants)
React2Shell honeypot detected active worm propagation (apache, apache.selfrep) with C2 infrastructure