//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
Profile
Loading...









Loading...
We added scanning of Automatic Tank Gauge (ATG) systems to our Accessible ICS reporting with 1061 IPs seen on 2026-06-05 (on port 10001/tcp). This is after weeding out vast majority which appear to be honeypots (including ports 8001/9001). Vast majority exposed are in the US.
We are observing a large amount of Ivanti Sentry CVE-2026-10520 exploitation attempts based on the public PoC today. We see 19 vulnerable instances in our own scans, with at least 2 backdoored (thanks to Saudi NCA for the tip!). However, all remaining likely compromised too.
Map has a typo in the date, should of course be 2026-06-10
5d
10h
9h
Compromised IP data shared in our Compromised Website reporting tagged as 'ivanti-sentry,injected-code,backdoor'. See: www.shadowserver.org/what-we-do/n... Advisory/patch: hub.ivanti.com/s/article/Se...
While our detection is on the lowish side due to multiple Ivanti Sentry instances not reachable in our scans (blocklisted?), if you have not patched now you are most likely compromised. Vuln IP data shared in Vulnerable HTTP reporting tagged 'cve-2026-10520' www.shadowserver.org/what-we-do/n...
10h
10h
The Shadowserver Foundation
The Shadowserver Foundation
The Shadowserver Foundation
This report is a list of all the websites we (or our collaborative partners) have been able to identify and verify to be compromised.
www.shadowserver.org
CRITICAL: Compromised Website Report | The Shadowserver Foundation
DESCRIPTION LAST UPDATED: 2026-06-10 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnera...
www.shadowserver.org
CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
The Shadowserver Foundation
Direct links (full report) - English: www.shadowserver.org/wp-content/u... French: www.shadowserver.org/wp-content/u... Portuguese: www.shadowserver.org/wp-content/u...
Shadowserver is excited to share its cybersecurity insights and actionable recommendations in a report aimed at helping ECOWAS stakeholders make West Africa more secure! Read the report & accompanying fact sheets in English, French & Portuguese at www.shadowserver.org/news/shadows...
The Shadowserver Foundation
Direct links (fact sheet) - English: www.shadowserver.org/wp-content/u... French: www.shadowserver.org/wp-content/u... Portuguese: www.shadowserver.org/wp-content/u...
See also: www.bitsight.com/blog/critica...
P data in www.shadowserver.org/what-we-do/n... (tagged 'atg’) Dashboard World Map view: dashboard.shadowserver.org/statistics/c... These should not be publicly exposed - read why at www.cisa.gov/resources-to... from US CISA #CyberCivilDefense
1d
1d
1d
5d
5d
www.shadowserver.org
www.shadowserver.org
Critical Vulnerabilities Discovered in Automated Tank Gauge Systems | Bitsight
Recent investigation by Bitsight TRACE has discovered multiple critical 0-day vulnerabilities across six ATG systems from five different vendors.
www.bitsight.com
DESCRIPTION LAST UPDATED: 2026-06-05 DEFAULT SEVERITY LEVEL: HIGH We scan the entire IPv4 space daily to map out and report on the ICS/OT exposed attack surface on the Internet. We do this by running ...
www.shadowserver.org
HIGH: Accessible ICS Report | The Shadowserver Foundation
The Shadowserver Foundation
The Shadowserver Foundation
The Shadowserver Foundation
The Shadowserver Foundation
The Shadowserver Foundation