LiveLoading

Threat Intelligence Hub

A daily view of what attackers are exploiting, who ransomware groups are hitting and where malware is being hosted, drawn from open-source threat intelligence feeds.

Actively exploited vulnerabilities

CISA KEV

CVEAffectedAdded

Critical vulnerabilities this week

NVD
CVECVSSDetailsPublished

Ransomware activity

ransomware.live

By group

Who is being targeted

ransomware.live

By sector

By country

Malware distribution

abuse.ch URLhaus

By threat type

Most common tags

Newest malware hosts

abuse.ch URLhaus

Shown defanged for safety. Do not visit these hosts.

HostThreatSeen

Botnet command and control

Latest government advisories

CISA

    Want this intelligence applied to your organisation?

    Our threat intelligence and managed SOC services turn these signals into detections, hunts and actions specific to your environment.

    Explore threat intelligence services

    Sources and methodology

    Data is collected automatically from public sources: the CISA Known Exploited Vulnerabilities catalogue, the NIST National Vulnerability Database, CISA advisories, abuse.ch URLhaus and Feodo Tracker, and ransomware.live. Ransomware figures reflect claims published by criminal groups and are not verified; victim names are deliberately not shown. Information is provided as is, for awareness only. This product uses data from the NVD API but is not endorsed or certified by the NVD.

    Get in touch

    Tell us what your regulator, auditor or board is asking for.

    We will come back to you with how we would approach it, who would work on it and what it would take.