75% of incidents involved stolen access, ransomware or exposed data, not website defacement.
89 days of activity
Each bar is one day, counted from every incident recorded in the window. A flat run is a quiet week rather than a gap in collection. 19,203 incidents across these 89 days, updated 8 hours ago.
Dated by when each incident was observed, not when it happened. Today is excluded while it is still in progress. One day carries 3,718 from a collection backfill; it is drawn off the scale so it cannot flatten the rest.
Wed 5 Aug 2026696busiest day — point at a bar for any other
22 May
29 May
5 Jun
12 Jun
19 Jun
26 Jun
3 Jul
10 Jul
17 Jul
24 Jul
31 Jul
7 Aug
14 Aug
18 Aug
Every day, with its count
Tue 18 Aug 2026220
Mon 17 Aug 2026223
Sun 16 Aug 2026304
Sat 15 Aug 2026192
Fri 14 Aug 2026153
Thu 13 Aug 2026129
Wed 12 Aug 2026198
Tue 11 Aug 2026210
Mon 10 Aug 2026227
Sun 9 Aug 2026244
Sat 8 Aug 2026174
Fri 7 Aug 2026220
Thu 6 Aug 2026236
Wed 5 Aug 20263,718
Tue 4 Aug 2026241
Mon 3 Aug 2026207
Sun 2 Aug 2026176
Sat 1 Aug 2026151
Fri 31 Jul 2026153
Thu 30 Jul 2026183
Wed 29 Jul 2026195
Tue 28 Jul 2026191
Mon 27 Jul 2026231
Sun 26 Jul 2026169
Sat 25 Jul 2026191
Fri 24 Jul 2026285
Thu 23 Jul 2026234
Wed 22 Jul 2026202
Tue 21 Jul 2026400
Mon 20 Jul 2026207
Sun 19 Jul 2026114
Sat 18 Jul 20260
Fri 17 Jul 202671
Thu 16 Jul 2026212
Wed 15 Jul 2026171
Tue 14 Jul 2026205
Mon 13 Jul 2026162
Sun 12 Jul 2026128
Sat 11 Jul 2026135
Fri 10 Jul 2026198
Thu 9 Jul 202633
Wed 8 Jul 2026205
Tue 7 Jul 2026213
Mon 6 Jul 2026153
Sun 5 Jul 2026114
Sat 4 Jul 2026136
Fri 3 Jul 2026214
Thu 2 Jul 2026155
Wed 1 Jul 2026212
Tue 30 Jun 2026176
Mon 29 Jun 2026244
Sun 28 Jun 2026145
Sat 27 Jun 2026174
Fri 26 Jun 2026186
Thu 25 Jun 2026162
Wed 24 Jun 2026124
Tue 23 Jun 2026118
Mon 22 Jun 2026213
Sun 21 Jun 2026123
Sat 20 Jun 2026200
Fri 19 Jun 2026198
Thu 18 Jun 2026188
Wed 17 Jun 2026107
Tue 16 Jun 2026139
Mon 15 Jun 2026171
Sun 14 Jun 2026250
Sat 13 Jun 2026136
Fri 12 Jun 2026131
Thu 11 Jun 2026165
Wed 10 Jun 2026196
Tue 9 Jun 2026123
Mon 8 Jun 2026135
Sun 7 Jun 2026118
Sat 6 Jun 2026160
Fri 5 Jun 2026173
Thu 4 Jun 2026220
Wed 3 Jun 2026168
Tue 2 Jun 2026122
Mon 1 Jun 2026168
Sun 31 May 2026114
Sat 30 May 2026130
Fri 29 May 2026594
Thu 28 May 20260
Wed 27 May 20260
Tue 26 May 202653
Mon 25 May 2026163
Sun 24 May 2026228
Sat 23 May 2026150
Fri 22 May 2026143
Check your own exposure
2,124 incidents in the last 90 days named organizations in Government Administration. 8.9% of all incidents
Access sold 13%
Ransomware and extortion 3%
Data exposed 27%
Disruption 55%
Counted from every incident in the window, not sampled.
Counted from every incident in the window, not sampled.
2,148 incidents in the last 90 days named organizations in USA. 9.0% of all incidents
Access sold 14%
Ransomware and extortion 41%
Data exposed 31%
Disruption 12%
Counted from every incident in the window, not sampled.
Counted from every incident in the window, not sampled.
Tracking 12 attack routes over the last 7d. Busiest is Brazil to Hong Kong at 2.5% of observed attack traffic. Each line is a country pair, and the more traffic it carries the brighter and busier it runs.
Top Network Attack Vectors
Mirai (UDP) Flood68.3%
UDP Flood18.3%
SYN Flood6.5%
DNS Flood2.5%
SFU Flood1.1%
ACK Flood0.9%
Attack Protocol Mix
UDP91.9%
TCP8%
GRE0%
ICMP0%
Top Scanned TCP Ports
SANS ISC / DShield
122 · ssh507,762
280 · www473,015
323 · telnet209,862
48000 · irdmi140,211
58080 · http-alt137,214
6443 · https120,563
72222 · ssh79,442
8853 · domain-s73,747
Top Scanned UDP Ports
SANS ISC / DShield
1137 · netbios-ns2,499
253 · domain1,017
3123 · ntp631
45060 · sip624
51900 · ssdp458
6500 · isakmp373
75353 · mdns311
827015 · halflife215
Active Malware Families
abuse.ch
1Unknown malware149
2ClearFake117
3IClickFix94
4Unknown Stealer75
5PureRAT51
41Malware families
5C2 servers
354Malicious domains
155Malicious URLs
1,671Known exploited CVEs
Sources: Cloudflare Radar (CC BY-NC 4.0), SANS ISC / DShield, abuse.ch, CISA KEV. Updated August 20, 2026.
CODERED VTA
Emerging Threat Advisory
Our analysts publish an advisory for each vulnerability and campaign they track. Every one carries a severity, the CVE where one has been assigned, the indicators your team can hunt for, and the mitigation we recommend.