THREATWATCH

Dashboard / Overview

Unified security intelligence

Threats, at a glance.

Live intelligence on threat actors, ransomware, vulnerabilities, weaknesses, and honeypot activity.

CISA exploitation signals

Emerging CVEs

Official CVE List V5Loading…

Loading recent CISA assessments…

Open CVE feed →

Active exploitation and public proof-of-concept signals are not, by themselves, confirmation that a vulnerability was exploited as a zero-day.

Near-live network telemetry

Observed activity

Cloudflare Radar · 24-hour viewLoading…

Attack paths

Leading origin-to-target flows

Animated snapshot

Loading observed attack geography…

Flows use Cloudflare-observed origin and target country pairs. Loading the latest aggregate snapshot…

Ranked paths

Top observed flows

Replaying

Loading attack paths…

Origin snapshot · DShield

Top source countries

Loading country totals…

Service targeting

Top targeted ports

Loading port totals…

Source telemetry provided by SANS Technology Institute, Internet Storm Center ↗. Target and flow views use aggregated Cloudflare Radar ↗ layer 7 mitigated-request data; target geography reflects the attacked zone’s billing country.

Loading dashboard snapshots…

Public threat-actor intelligence

APT groups,
mapped.

Explore country-attributed and suspected state-linked actors, their aliases, targets, and primary research references.

Attributed profiles

Country or sponsor metadata

Countries represented

Structured country codes

Suspected sponsors

Explicit sponsor claims

Last refreshed

Cached for 24 hours

Open source · MISP Galaxy

Actor catalog

Loading threat-actor profiles…

Actor data provided by MISP Galaxy ↗. Follow each profile’s references before making attribution or response decisions.

Threat-actor intelligence · Visual analysis

Actor catalog
charts.

Explore attribution concentration, reported target sectors, catalog coverage, and the naming and research depth behind public actor profiles.

Loading actor chart data…

Actor data provided by MISP Galaxy ↗. Country and sponsor fields are attribution claims and may be disputed.

Live weakness intelligence

CWE threats,
in focus.

The software weakness patterns most connected to active exploitation, ransomware, and near-term exploit probability.

Catalog version

Loading…Fetching current release

Total weaknesses

Defined software weaknesses

Categories

Organized CWE groupings

Views

Catalog perspectives

Top ten · CISA KEV + EPSS

Watchlist

Loading live CWE records…

CWE record lookup

Inspect a
weakness.

Enter the numeric part of a CWE ID. Try or .

Weakness intelligence · Visual analysis

CWE data
charts.

Compare the signals driving the current top-ten weakness ranking.

Loading CWE chart data…

Active vulnerability intelligence

CVE threats,
right now.

Recently exploited vulnerabilities ranked by real-world activity, ransomware use, exploit probability, recency, and technical severity.

Tracking window

Recent KEV additions

Active candidates

CVEs evaluated

Ransomware linked

Within the top ten

Catalog release

CISA KEV snapshot

Top ten · KEV + EPSS + NVD

Watchlist

Loading live CVE records…

CVE record lookup

Inspect a
vulnerability.

Enter a complete CVE identifier, with or without the CVE prefix.

Vulnerability intelligence · Visual analysis

CVE data
charts.

See why each actively exploited vulnerability is rising to the top.

Loading CVE chart data…

Near-live CISA assessments

Emerging exploits,
without the hype.

Recent CVEs with active-exploitation, public proof-of-concept, or high-risk automatable/total-impact signals from CISA ADP Vulnrichment.

Active exploitation

Recent CISA assessments

Public PoC

Proof-of-concept available

High-risk candidates

Automatable + total impact

Last source update

Official CVE List release

CISA ADP · 14-day window

CVE feed

Loading CISA exploitation assessments…

CISA enrichment is consumed from the official CVE List V5 ↗. The source updates approximately hourly; Threat Watch caches the filtered feed for one hour.

CISA exploitation signals · Visual analysis

Emerging threat
charts.

Explore when priority assessments appear, how readily vulnerabilities can be exploited, and which vendors are most represented.

Loading exploitation charts…

CISA enrichment is consumed from the official CVE List V5 ↗. Active exploitation does not by itself prove zero-day use.

Community honeypot telemetry

Attacks,
as observed.

Current attacker, port, SSH, and web-scanning signals collected by the global DShield sensor community.

Honeypot indicators

SSH and web scanner IPs

SSH attackers

DShield Cowrie indicators

Web scanners

Web honeypot indicators

Last refreshed

Cached for one hour

Public telemetry · SANS ISC

Live activity

Loading DShield telemetry…

DShield reputation lookup

Inspect an
address.

Returns DShield report volume, observed targets, dates, network, and ASN metadata.

Data provided by SANS Technology Institute, Internet Storm Center ↗. DShield data may not be resold.

Community honeypot telemetry · Visual analysis

Honeypot data
charts.

Compare the sources, services, and credentials appearing across the current DShield community snapshot.

Loading DShield chart data…

Data provided by SANS Technology Institute, Internet Storm Center ↗. DShield data may not be resold.

Public leak-site intelligence

Ransomware groups,
most active.

Groups ranked by unique victim claims publicly observed by RansomLook during the rolling 30-day window.

Observed claims

Unique claims in 30 days

Active groups

Groups with observed claims

Leading share

Share held by the top group

Last refreshed

Cached for one hour

Top ten · 30-day public claims

Watchlist

Loading ransomware activity…

Activity data provided by RansomLook ↗. Victim claims are observational intelligence and may be incomplete, duplicated at the source, or incorrectly attributed.

Ransomware leak-site intelligence · Visual analysis

Ransomware data
charts.

Compare 30-day claim volume, current seven-day activity, group share, and the daily discovery timeline.

Loading ransomware chart data…

Activity data provided by RansomLook ↗. Counts represent publicly observed victim claims, not independently confirmed attacks.