Shadowserver 2025: Highlights of the Year in Review

September 7, 2026

Who We Are and What We Do

The Shadowserver Foundation, Inc. (Shadowserver) is a registered 501(c)(3) tax-exempt nonprofit organization in the United States and a registered nonprofit foundation (“Stichting”) with public benefit status in the Netherlands. With just 22 staff members, 10 volunteers, and annual operating costs of around USD 6 million, we are extremely proud of the global scope, scale, and impact of our cybersecurity public benefit services that help make the Internet safer and more secure. Our primary public benefit services include the following:

– Free, Daily, Actionable Cyber Threat Intelligence

Our free, daily cyber threat intelligence, in the form of network remediation reports, help National CSIRTs (nCSIRTs) and more than 10,000 network defenders around the world secure their networks. These reports provide both an Early Warning Service, identifying publicly exposed, misconfigured, and vulnerable devices on a network to be patched before a breach occurs, and a Victim Notification Service, identifying compromised devices on a network to be remediated before further exploitation, such as a ransomware attack, can occur. Each detected issue is designated with a severity level to help organizations and nCSIRTs prioritize patching and other remediation actions to be taken to achieve better network security. Our network reports include the latest high-risk vulnerabilities and unique victim data sets shared with Shadowserver by Law Enforcement, independent security researchers and trusted private sector partners.

– Global Cybersecurity Capacity Building Services

We provide extensive cybersecurity capacity building (CCB) services globally, with projects in the Indo-Pacific, Africa, the Middle East, Latin America, and Central and Eastern Europe, among others. These services help nCSIRTs, government agencies, network operators, and other system defenders improve threat detection, increase cybersecurity situational awareness, enable effective incident response, and strengthen cyber resilience. We recently enhanced our CCB capabilities by developing a complete “CCB toolkit”. This toolkit provides an essential digital pipeline that enables an entity to ingest, parse, and analyze voluminous cyber threat intelligence (CTI) data and distribute the data to affected constituent network owners through automated alert notifications. Components of the Shadowserver CCB toolkit include: free, daily CTI / data feeds; an automated platform for data ingestion, processing, analytics and sharing; one-on-one and group training sessions; joint threat / vulnerability reduction initiatives; expert analysis of the threat landscape; partnership development and collaboration opportunities; data enrichment efforts; and metrics to track progress of patching and remediation using Shadowserver’s public Dashboard.

– Support to Law Enforcement Cybercrime Disruption Operations

We provide free technical assistance to many of the world’s most significant cybercrime disruption operations. This assistance includes quarantining millions of malicious domains using our special purpose DNS registrar, the Registrar of Last Resort (RoLR). We conduct ‘sinkholing’ operations to actively protect victims from further exploitation. We then use our Victim Notification Service capabilities to help Law Enforcement and nCSIRTs notify millions of victims per day that their devices have been compromised by threat actors to encourage remediation.

Thank You to Our Supporters

Our many accomplishments in 2025 would not have been possible without the generous support of the United Kingdom’s Foreign, Commonwealth and Development Office (UK FCDO), our Shadowserver Alliance Partners, and those organizations who supported us through donations, voluntary invoicing, and funded projects. To all of you, the entire Shadowserver team extends a sincere and heartfelt thank you.

We would also like to thank our many partners and collaborators – the nCSIRT community, our trusted Law Enforcement partners, and those who shared data, intelligence, and insights with us that helped make our services more timely, relevant, and effective. Without your support, we would not be able to provide free public benefit services that help secure networks and raise the baseline of cybersecurity across the globe.

In The Spotlight: Impact Stories of 2025

In this section, we chose a selection of stories to spotlight the impact that Shadowserver and its many partners had on making the Internet more secure in 2025.

Shadowserver / watchTowr Protect Victims by Hijacking Webshells on Compromised Servers

In early January, we teamed with watchTowr, a Shadowserver Alliance Partner, to protect victims whose servers were compromised by threat actors using webshell backdoors. We sinkholed the webshell command and control (C2) domain names that threat actors had accidentally or deliberately allowed to expire, despite victim systems still being infected.

The effort identified over 4,000 devices compromised with ~30 different webshell types, including multiple government systems in a number of countries. Data was shared with nCSIRTs and victim network owners for remediation globally. Following the publication of watchTowr’s report, this effort became one of the first major cyber security stories of 2025, generating more than 100 media articles. Bleeping Computer reported, “Together with The Shadowserver Foundation, researchers at offensive security outfit watchTowr Labs prevented these domains and the corresponding victims from falling into the hands of malicious actors.

Shadowserver Partners with nCSIRTs on INFINITT Zero-Day Research that Leads to 3 New CVEs

In late 2024, Shadowserver conducted research into remotely exploitable zero-day vulnerabilities in South Korean INFINITT Picture Archiving and Communication System (PACS) medical imaging devices. These were detected by observing attacks against our Global Honeypot Sensor Network. In 2025, our research led to 3 CVE numbers eventually being assigned to these newly discovered vulnerabilities: CVE-2025-27714 (CVSS severity score 6.3 rated MEDIUM); CVE-2025-24489 (CVSS severity score 6.3 rated MEDIUM), and CVE-2025-27721 (CVSS severity score 7.5 rated HIGH).

Following Shadowserver’s active engagement on this matter with nCSIRTs from the Republic of Korea (KrCERT/CC), the United States (DHS-CISA), and Germany (CERT.Bund), CISA released a public advisory about these new threats on April 10th which publicly credited Shadowserver for their discovery.

Shadowserver Detects Brute Force Attacks Against Leading Edge Devices

Beginning in January 2025, our Global Honeypot Sensor Network detected a large increase in the number of unique IP addresses attacking emulated VPN edge devices, including from leading vendors Palo Alto Networks (PAN-OS), Ivanti and SonicWall. We observed millions of unique IP addresses attacking only our US-based honeypot sensors, thereby indicating targeted activities to find potentially vulnerable US infrastructure. In response to this threat, we quickly took the following actions:

  • We raised awareness of this threat through social media announcements.
  • Attack data was reported out daily to nCSIRTs and subscribing network owners globally via our Honeypot HTTP Scanner Events Report.
  • Statistics were published on our public Dashboard.
  • We collaborated with certain nCSIRTs whose countries were among the top sources of the attacking devices at various times as shown on our public Dashboard, including Saudi Arabia (KSA NCA), Malaysia (MyCERT), South Africa (DCDT), and later Brazil (CERT.BR).

This brute force attack threat, first discovered by Shadowserver, became a major news story in early February 2025 with almost 300 articles citing Shadowserver’s discovery. In Cybersecurity Dive, a CISA spokesperson stated, “CISA is engaged with Shadowserver and other relevant partners on edge device attack paths.”

Collaboration in Actions Against Ivanti Vulnerability

A critical vulnerability in Ivanti Connect Secure edge devices was a major news story in January 2025. CVE-2025-0282 was a stack buffer overflow that allowed a remote unauthenticated attacker to achieve Remote Code Execution (RCE). Known to be actively exploited in the wild by threat actors, this vulnerability was given a CVSS severity score of 9.0 rated CRITICAL.

Thanks to insights shared by watchTowr, a Shadowserver Alliance Partner, we quickly added scan-based detection for this vulnerability and reported 2,048 likely vulnerable instances worldwide on 2025-01-09, with the highest numbers in the US, France and Spain. Patching progress for this CVE can be tracked on our public Dashboard.

Shadowserver Contributes to Android Vo1d and BADBOX 2.0 Botnet Disruptions

Shadowserver partnered with Google, HUMAN Security, and Trend Micro to disrupt the Android Vo1d and BADBOX 2.0 botnets in 2025. The BADBOX 2.0 botnet was made up of millions of compromised off-brand, non-Google Play Protect certified Android Internet of Things (IoT) devices manufactured in China, including low-cost smart TV boxes, digital projectors, vehicle infotainment units, and digital picture frames. These supply chain compromised devices provided threat actors with unauthorized access to home networks and were used to facilitate various types of criminal activity, including programmatic ad fraud, click fraud, and a host of crimes associated with residential proxy services. Many compromised devices were infected with malware pre-installed on the device prior to the user’s purchase, while others were infected through the downloading of required applications.

In March, HUMAN’s Satori Threat Intelligence Team released its technical report and blog update on the BADBOX 2.0 disruption, followed by the FBI’s public service announcement in June, and Google’s civil court action unsealed in July. At peak, 8 million infected unique IP addresses per day were observed by Shadowserver’s sinkholes and reported out to nCSIRTs and network owners globally, with over 2 million in Brazil.

Shadowserver Supports “Operation Endgame” International Law Enforcement Disruption

Operation Endgame 2.0: In May, Shadowserver continued its support of Operation Endgame, a joint effort coordinated by Europol and Eurojust between Law Enforcement and judicial authorities of nearly a dozen countries, with support from more than 30 national and international public and private sector parties, to combat ransomware enablers such as malware loaders/droppers and information stealers at scale. This “second season” of the ongoing disruption operation saw 300 servers taken down, 650 domains neutralized, EUR 3.5 million in cryptocurrency seized, and arrest warrants issued for 20 criminal targets. As part of the operation, the following malware families were disrupted: Bumblebee; Danabot; Hijackloader; Lactrodectus; Lumma Stealer; Qakbot; Trickbot; and Warmcookie. Our pre-existing Operation Endgame 1.0 Smokeloader sinkholing was also extended. As part of its contributions to the effort, Shadowserver announced a one-time Special Report issued to nCSIRTs and subscribing network owners containing information on IP addresses and computer systems believed to have been infected with Lactrodectus information stealing malware (with three iterations run, as more seized media was analyzed).

Operation Endgame 3.0: In November, the “third season” of the ongoing operation disrupted the Rhadamanthys infostealer, the Remote Access Trojan VenomRAT, and the Elysium botnet, all of which played a key role in facilitating international cybercrime activities. This phase of the operation saw over 1,025 servers taken down, 20 domains seized, and a main suspect arrested.

As part of this third phase of Operation Endgame, Law Enforcement shared with Shadowserver sensitive victim information such as the IP addresses of computer systems believed to have been infected with Rhadamanthys information stealing malware. Shadowserver used this information to announce and issue two Rhadamanthys Historical Bot Infections Special Reports (on 2025-11-12 and again on 2025-12-15) to notify 201 nCSIRTs in 175 countries and 10,000+ network owners globally about historical bot infections responsible for 91,937,512 different information stealing events recorded on victim computers, corresponding to 567,215 unique IP addresses located in 18,276 different ASNs, across 228 different countries, thereby enabling system identification for potential victim remediation.

Shadowserver Shares Sinkhole Infection Data Following Support to FBI Operation to Disrupt Flax Typhoon’s Raptor Train Botnet

Following Shadowserver’s support of the FBI’s 2024 disruption of the Raptor Train malware botnet controlled by state-sponsored hackers of the People’s Republic of China known as “Flax Typhoon,” in July 2025, we shared data on live Flax Typhoon Raptor Train infections reporting to our custom sinkhole servers. At the FBI’s request we issued a Raptor Train Historical Bot Infections Special Report covering 732,545 events, 179,539 IP addresses, 2750 Autonomous System Numbers (ASNs) across 143 countries during the period 2024-06-05 to 2024-09-13 and 2025-06-24 to 2025-07-01. Data on both the live sinkhole infections and the Special Report were disseminated to nCSIRTs and affected network owners globally to maximize remediation efforts. Shadowserver also shared aggregated country-level statistics of Raptor Train historical bot infections on our public Dashboard.

Shadowserver and Partners Address SharePoint Zero-Day Vulnerability

In collaboration with Eye Security, watchTowr and the Dutch Institute for Vulnerability Disclosure (DIVD), we notified compromised parties of exploitation activity related to Microsoft SharePoint CVE-2025-53770 (nicknamed “ToolShell”) with a CVSS severity score of 9.8 rated CRITICAL. We initially reported approximately 9,300 publicly exposed SharePoint IP addresses. Within days, we shared SharePoint devices confirmed vulnerable to CVE-2025-53770 and CVE-2025-53771 thanks to a scan by LeakIX. In collaboration with Validin and German nCSIRT CERT-BUND/BSI, we worked to improve our detection of publicly exposed SharePoint instances and reported approximately 17,000 vulnerable publicly exposed unique IP addresses.

This zero-day vulnerability was one of the most high profile incidents of 2025, including the reported breach of the US National Nuclear Security Administration (NNSA)’s Kansas City National Security Campus (KCNSC). Microsoft attributed exploitation to Chinese nation-state threat actors Linen Typhoon and Violet Typhoon, and Chinese-linked threat actor Storm-2603 for deployment of Warlock ransomware. Over 750 media articles referenced Shadowserver and our data. Patching progress for this CVE can be tracked on our public Dashboard.

Shadowserver Partners with Infoblox to Sinkhole Threat Actor Detour Dog’s C2 Infrastructure

Infoblox, experts on DNS-based cyber threat intelligence, investigated a threat actor known as Detour Dog who had infected tens of thousands of websites worldwide with malware that utilized DNS to conditionally redirect visitors to malicious content since August 2023. After Infoblox identified command and control (C2) domains used by Detour Dog to facilitate its criminal activities, building on previous collaboration, Shadowserver and our sister nonprofit, the Registrar of Last Resort, successfully sinkholed Detour Dog’s C2 infrastructure through voluntary action of registries and registrars on the basis of terms of service violations.

Infoblox published a report on September 30th, shining the first detailed public light on Detour Dog’s previously hidden activities. Infoblox credited Shadowserver for the sinkholing and quality data it provided, and stated “This dataset surfaced compelling insights into the campaign’s global footprint”. Infoblox further noted that Shadowserver’s efforts allowed for the identification of 30,000 infected domains, enabled study of the threat actor’s ability to recover from C2 disruption, and revealed ongoing testing of malware delivery. Infoblox concluded their reporting by noting, “when security and research organizations collaborate, we are a formidable force — thanks ShadowServer and others behind the scenes”.

Shadowserver and Partners React Promptly to React2Shell Vulnerability Impacting Many Sectors

We scanned for and reported vulnerable instances of React Server Components for CVE-2025-55182. It became known as React2Shell, ‘The “Log4j Moment” for Frontend Development’ (CVSS severity score 10.0 rated CRITICAL). We initially detected 77,664 IP addresses as likely vulnerable on 2025-12-05. Through collaboration with Validin and LeakIX, we improved scan targeting and, just 3 days later, updated our reporting with over 165,000 IP addresses and 644,000 domains having code vulnerable to CVE-2025-55182. Patching progress for this CVE can be tracked on our public Dashboard. Organizations impacted included those in critical national infrastructure, government, finance, insurance, banking, technology, retail, aerospace, telecommunications, healthcare, education, travel, and cybersecurity sectors. Shadowserver was featured in 300+ media articles about the topic. Initial exploitation was attributed by GTIG to Chinese state-nexus threat groups, including Earth Lamia, Jackpot Panda and UNC5174.

Shadowserver Once Again Recognized as Earliest Reporter of Exploitation in the Wild

Continuing our 2024 top rankings, we were proud to be once again recognized by VulnCheck, a leading vulnerability intelligence vendor and Shadowserver Alliance Partner, as the “Earliest Reporter of Exploitation in the Wild” in both the first half of 2025 and for the full year. Using our extensive Global Honeypot Sensor Network, our non-profit team of Shadowserver experts led the way in timely identification and reporting when vulnerabilities were actively exploited in the wild by threat actors.

Other Highlights of 2025

Although we selected several “Impact Stories of 2025” to spotlight in the preceding section, the year was filled with numerous additional highlights. In the following sections, we provide those highlights across the various areas of our work, to include detection and reporting of vulnerabilities and other emerging cyber threats, global cybersecurity capacity building, support to law enforcement’s cybercrime disruption operations, participation in cybersecurity community initiatives and conferences, and the growth of our Shadowserver Alliance.

– Timely Detection and Reporting on the Latest Vulnerabilities and Other Emerging Cyber Threats

Throughout 2025, our dynamic Shadowserver team continued to prove its ability to respond quickly to the latest, most significant cyber threats, thereby ensuring that our free, daily network remediation reports remained timely, relevant, and actionable. Within one to two days of the announcement of many of the most serious new vulnerabilities in Internet-facing devices, we effectively used our Global Honeypot Sensor Network to analyze new attack data, then used that information to enhance our Internet-wide scanning to ultimately identify devices that were vulnerable and (when possible) compromised on networks around the world.

For each new vulnerability we acted on, we:

(1) Provided advanced notice to our Shadowserver Alliance Partners and publicly announced on social media our findings as to the geographic location (by country or region) of each vulnerable or compromised device.

(2) Directly reported those vulnerable or compromised devices (by specific IP addresses) to our respective 10,000+ subscribing organizations (representing 70% of North American, 67% of European, and 57% of IPv4 space by ASN globally directly) and 201 nCSIRTs covering 175 countries through our free, daily network remediation reports, so they could patch their devices and protect their networks before the threats were exploited (or further exploited) by threat actors.

(3)  Used our free public Dashboard – funded by the UK FCDO – to provide daily, aggregated, country-level statistics on a wide range of data sets concerning the number and location of publicly exposed, misconfigured, vulnerable or compromised devices on networks globally, for use as an independent resource for the media, public, and cyber policy makers to illustrate the size and scale of many cybersecurity threats.

To keep up with all the latest insights, alerts, and information from Shadowserver, please also consider signing up to our public mailing list where we make service announcements. Send a message with the subject of “join” to public-request@list.shadowserver.org and follow us on social media: X / Twitter; Bluesky; Mastodon; LinkedIn.

Some of the most significant vulnerabilities and emerging cyber threats Shadowserver detected and reported on daily in 2025 include:

JANUARY 2025:
  • Through collaboration with Google, we expanded our reporting of publicly exposed rsync instances, a popular tool for transferring and synchronizing files across hosts, to include those vulnerable to CVE-2024-12084 (CVSS severity score 9.8 rated CRITICAL). We reported 17,475 vulnerable instances on 2025-01-16 with the US being the most affected with 5,000. Patching progress for rsync vulnerable instances can be tracked on our public Dashboard.
  • We shared instances of SimpleHelp, a widely used Remote Monitoring and Management (RMM) support software solution, that were vulnerable to CVE-2024-57727 (CVSS severity score 9.1 rated CRITICAL). We reported 580 vulnerable instances with the majority of those seen in the US. CISA subsequently reported that the vulnerability was used in ransomware double extortion incidents. Patching progress for this CVE can be tracked on our public Dashboard.
FEBRUARY 2025:
  • We reported daily GFI Kerio Control Firewall instances vulnerable to CVE-2024-52875, (CVSS severity score 8.8 rated HIGH), which could possibly be leveraged for RCE. We identified 12,229 unpatched instances worldwide on 2025-02-09. Patching progress for this CVE can be tracked on our public Dashboard.
  • We scanned for and reported Ivanti Connect Secure unpatched instances vulnerable to CVE-2025-22467 (CVSS severity score 9.9 rated CRITICAL), detecting 2,850 unpatched instances worldwide in our daily scans. Patching progress for this CVE can be tracked on our public Dashboard.
  • We scanned for and reported Nakivo Backup & Replication instances vulnerable to CVE-2024-48248 (CVSS severity score 8.6 rated HIGH), observing 208 vulnerable instances on 2025-02-26. watchTowr, a Shadowserver Alliance Partner, provided in-depth analysis of the vulnerability on its watchTowr blog page. Patching progress for this CVE can be tracked on our public Dashboard.
MARCH 2025:
  • We scanned for and reported IoT devices compromised by the Eleven11bot botnet, (which was mainly comprised of security cameras and network video recorders, and was used to launch distributed denial-of-service (DDoS) attacks against telecommunications service providers and online gaming servers), with 86,400 compromises worldwide discovered on 2025-03-02. The most affected countries were the US (24,700) and the UK (10,800).
  • We scanned for and reported VMware ESXi instances vulnerable to CVE-2025-22224 (CVSS severity score 9.3 rated CRITICAL) and added to CISA’s Known Exploited Vulnerability (KEV) List. We reported nearly 41,500 vulnerable instances on 2025-03-04. Patching progress for this CVE can be tracked on our public Dashboard. In early January 2026, Huntress attributed exploitation of this vulnerability in the wild to a suspected Chinese threat actor.

  • We reported unpatched CrushFTP file transfer software likely vulnerable to CVE-2025-2825 (later rejected and determined to be a reservation duplicate of CVE-2025-31161) (CVSS severity score 9.8 rated CRITICAL). We reported approximately 1,800 unpatched instances worldwide with 900 of those in the US. Patching progress for this CVE can be tracked on our public Dashboard. Exploitation of the vulnerability was subsequently claimed by the pro-Russian/anti-Western hacktivist Kill or KillSec ransomware group in another potential mass file transfer software compromise.
APRIL 2025:
  • We scanned for and reported another serious Ivanti Connect Secure RCE vulnerability – this time CVE-2025-22457, a known exploited vulnerability on CISA’s KEV List (CVSS severity score 9.8 rated CRITICAL). GTIG attributed exploitation to the suspected China-nexus espionage actor UNC5221. We observed over 5,113 vulnerable unpatched instances in our scans on 2025-04-06. Patching progress for this CVE can be tracked on our public Dashboard.
  • After Fortinet reported that a threat actor had been observed using known vulnerabilities (e.g. FG-IR-22-398, FG-IR-23-097, FG-IR-24-015) to gain access to Fortinet devices, which generated multiple nCSIRT advisories, we reported over 17,000 compromised publicly exposed Fortinet devices in our Compromised Website Report. Statistics about compromised Fortinet devices are available on our public Dashboard.
  • Thanks to the Kingdom of Saudi Arabia’s nCSIRT (KSA NCA), Shadowserver was notified of a newly discovered vulnerability in SAP NetWeaver identified as CVE-2025-31324 (CVSS severity score 10.0 rated CRITICAL). Our agile team quickly developed SAP device identification signatures, added publicly exposed population detection to our free daily network reports and public Dashboard statistics, and developed vulnerability detection. We shared our findings of 454 vulnerable IP addresses on 2025-04-26. Patching progress for this CVE can be tracked on our public Dashboard. Exploitation was attributed by ReliaQuest to Russian-linked ransomware threat actors (BianLian) and China-linked threat actors (RansomEXX), and possibly the “Scattered Lapsus$ Hunters” group.

MAY 2025:
  • SysAid is a popular IT Service Management (ITSM) solution which makes it an attractive target for attackers. We collaborated again with vulnerability researchers and Shadowserver Alliance Partner watchTowr to develop detection mechanisms to identify and report publicly exposed SysAid instances that were likely vulnerable to CVE-2025-2775, CVE-2025-2776, CVE-2025-2777 XML external inject vulnerabilities (XXEs), any of which combined with CVE-2025-2778 enables RCE. As a result of this collaboration, 77 IP addresses were initially determined to be unpatched (based on a version check). Data was initially shared in our Accessible HTTP & Accessible SSL reports tagged as ‘sysaid-vulnerable’, then moved to our Vulnerable HTTP report as the process was improved.
  • We shared instances of ScreenConnect, a popular remote desktop application, likely vulnerable to CVE-2025-3935 (CVSS severity score 8.1 rated HIGH). We reported 685 unpatched instances on 2025-05-07. Patching progress for this CVE can be tracked on our public Dashboard.
  • We scanned for and reported Ivanti EPMM unpatched instances likely vulnerable to CVE-2025-4427 (CVSS severity score 7.5 rated HIGH), which can be chained with CVE-2025-4428 (CVSS severity score 8.8 rated HIGH) to achieve RCE. First scans found 940 vulnerable instances on 2025-05-15, reducing to 798 vulnerable instances on 2025-05-18. Detection was provided by Shadowserver Alliance Partner watchTowr, who also provided the public with helpful background information on the vulnerabilities. Patching progress for this CVE can be tracked on our public Dashboard. Exploitation was subsequently attributed by EclecticIQ to China-nexus espionage group UNC5221, with targets potentially including compromises of two UK National Health Service (NHS) Trusts.
JUNE 2025:
  • We reported Roundcube Webmail instances vulnerable to CVE-2025-49113 (CVSS severity score 9.9 rated CRITICAL) which allows RCE by authenticated users. We observed approximately 84,000 unpatched vulnerable instances worldwide. We also noted that Roundcube vulnerabilities have been frequently exploited for targeted attacks by possible nation-state threat actors. Initial exploitation was later attributed by TeamT5 to China-nexus Advanced Persistent Threat (APT) group CamoFei.
  • We scanned for and reported Citrix NetScaler instances vulnerable to CVE-2025-5777 (CVSS severity score 9.3 rated CRITICAL, sometimes referred to as “Citrix Bleed 2”) and CVE-2025-6543 (CVSS severity score 9.8 rated CRITICAL), observing 1,289 and 2,100 unpatched IP addresses, respectively, at the time of reporting. Patching progress for these CVEs can be tracked on our public Dashboard. Zero-day exploitation in the wild was later attributed by Amazon AWS Security to an unknown APT actor.
JULY 2025:
  • In collaboration with the Saudi Arabian National Cyber Authority (KSA NCA) and Canadian Center for Cyber Security (CCCS), we shared Fortinet FortiWeb edge devices compromised with webshells by an unknown threat actor, likely as a result of CVE-2025-25257 (CVSS severity score 9.8 rated CRITICAL. We observed 77 compromised instances on 2025-07-15 with exploitation activity seen since 2025-07-11, and credited both of our nCSIRT partners for their assistance in improving global incident response. Patching progress for this CVE can be tracked on our public Dashboard.

  • We scanned for and reported unpatched CrushFTP instances vulnerable to CVE-2025-54309 (CVSS severity score 9.8 rated CRITICAL). We detected 1,040 unpatched instances on 2025-07-20 with the top countries affected being the US, Germany, and Canada. Patching progress for this CVE can be tracked on our public Dashboard.
AUGUST 2025:
  • We scanned for and reported version based detection of unpatched IP addresses vulnerable to CVE-2023-2533 associated with PaperCut print management software. Shortly after, this CVE was added to US CISA’s Known Exploited Vulnerability (KEV) catalog. We observed 129 unpatched instances on 2025-08-03. Patching progress for this CVE can be tracked on our public Dashboard.
  • We scanned for and reported version based SonicWall SMA100 unpatched instances for CVE-2025-40596 (CVSS severity score 7.3 rated HIGH) with at least 3,200 IP addresses determined to be likely unpatched. Patching progress for this CVE can be tracked on our public Dashboard. Bitsight later attributed exploitation of the vulnerability to the Akira ransomware group, with CISA and other national entities issuing a joint Akira advisory in November.

*NOTE: Ransomware groups often gain initial access to victims’ networks by exploiting vulnerable devices they identify through their own scanning activities or through publicly available scan data. Shadowserver’s scan data found in its free, daily network remediation reports tells network owners about vulnerable (and sometimes compromised) devices on their networks. Shadowserver’s data will only be shared with the affected network owner and its nCSIRT. Our raw data will never be shared publicly. It is therefore critical that network owners of all sizes and across all sectors subscribe to Shadowserver’s free, daily network reports.

  • We scanned for and reported unpatched instances of Microsoft Exchange Server CVE-2025-53786 (CVSS severity score 8.0 rated HIGH) with over 28,000 IP addresses unpatched as of 2025-08-07. CISA issued Emergency Directive ED 25-02 that gave all Federal Civilian Executive Branch (FCEB) agencies 48 hours to implement required mitigations for any hybrid Microsoft Exchange Server instances on their networks (the first CVE-focused ED of 2025), indicating the severity of the potential threat. Patching progress for this CVE can be tracked on our public Dashboard.

  • We scanned for and reported unpatched instances of VMware ESXi CVE-2025-41236 (CVSS severity score 9.3 rated CRITICAL) with 16,330 unpatched IP addresses detected on 2025-08-10. Patching progress for this CVE can be tracked on our public Dashboard.
  • We scanned for and reported N-able N-central Remote Monitoring and Management (RMM) solution CVE-2025-8875 (CVSS severity score 9.4 rated CRITICAL) and CVE-2025-8876 (CVSS severity score 9.4 rated CRITICAL), with 1,077 unpatched IP addresses identified on 2025-08-15. Patching progress for both CVEs can be tracked on our public Dashboard.
  • We scanned for and reported Citrix NetScaler instances unpatched to CVE-2025-7775 (CVSS severity score 9.2 rated CRITICAL), with over 28,000 unpatched IP addresses observed on 2025-08-26, then down to over 12,000 unpatched IP addresses by 2025-08-28. Patching progress for this CVE can be tracked on our public Dashboard. The zero-day vulnerability was used by an unknown threat actor to drop webshells on compromised devices to gain persistent access.

  • We scanned for and reported vulnerable unpatched and compromised instances of FreePBX (a web-based, open-source graphical user interface for managing Asterisk open-source VoIP servers) CVE-2025-57819 (CVSS severity score 10.0 rated CRITICAL) with 6,620 unpatched and at least 366 compromised IP addresses detected on 2025-08-29. Patching progress for this CVE can be tracked on our public Dashboard in addition to compromised instances. Vulnerable telephony systems have been attractive targets for nation state threat actors.
SEPTEMBER 2025:
  • We scanned for and reported Cisco Secure Firewall Adaptive Security Appliance (ASA) software and Firewall Threat Defense (ASA/FTD) instances vulnerable to CVE-2025-20333 (CVSS severity score 9.9 rated CRITICAL) and CVE-2025-20362 (CVSS severity score 8.6 rated HIGH), with more than 48,000 unpatched IP addresses identified on 2025-09-29. CISA issued Emergency Directive ED 25-03 that gave all Federal Civilian Executive Branch (FCEB) agencies 24 hours to identify any compromised Cisco ASA and FTD instances on their networks (the second CVE-focused ED of 2025). In April 2026, exploitation activity was attributed by Cisco Talos to a campaign by state-sponsored threat actor UAT-4356 (China-linked STORM-1849) to deploy their “FIRESTARTER” back door, supported by joint advisories from CISA and the UK Nation Computer Security Centre (NCSC) highlighting the links to previous ArcaneDoor RayInitiator/LINE VIPER network edge device post-exploitation framework espionage activity. Patching progress for this CVE can be tracked on our public Dashboard.

OCTOBER 2025:
  • We scanned for and reported Oracle E-Business Suite (EBS) instances vulnerable to CVE-2025-61882 (CVSS severity score 9.8 rated CRITICAL), with 576 potentially vulnerable IP addresses identified on 2025-10-06. EBS is used for managing critical functions including finance, human resources, procurement, supply chain operations, and customer relationship management. GTIG attributed a large-scale data exfiltration and extortion campaign exploiting this vulnerability to the Russian-speaking Cl0p ransomware group. Patching progress for this CVE can be tracked on our public Dashboard.
  • After Shadowserver Alliance Partner watchTowr published a blog post about an Out-of-Bounds Write vulnerability identified as CVE-2025-9242 (CVSS severity score 9.3 rated CRITICAL) in WatchGuard’s Fireware OS IKEv2, we scanned for and reported more than 71,000 vulnerable IP addresses on 2025-10-18. Patching progress for this CVE can be tracked on our public Dashboard.
  • In response to CVE-2025-59287 (CVSS severity score 9.8 rated CRITICAL), we quickly scanned for and reported publicly exposed Microsoft Windows Server Update Service (WSUS) instances, with 2,800 observed on 2025-10-25 (not necessarily vulnerable). This flaw turns what should be a trusted security component into a potential pathway for ransomware or malware. It was later reported that this vulnerability was actively exploited by Chinese-linked advanced persistent threat (APT) groups. Statistics were shared on our public Dashboard.
  • After network security product vendor F5 disclosed a cybersecurity incident involving a (reportedly Chinese) nation-state actor that gained access to internal systems, including the BIG-IP product development environment, we scanned for and reported publicly exposed F5 instances, with more than 269,000 IP addresses identified on 2025-10-16. This helped system defenders to follow US CISA & NCSC UK guidance to identify and harden F5 assets. Statistics were shared on our public Dashboard.
NOVEMBER 2025:
  • We shared 10,449 entries (email addresses) affected by leaks in developer formatting platforms JSONFormatter and CodeBeautifier discovered by our Shadowserver Alliance Partner, watchTowr, and explained in their report. The data, shared in our Compromised Account Report and designated as CRITICAL, contained a list of compromised accounts for which we believe attackers obtained credentials through a malware infection, site breach, phishing, or other type of malicious activity.
DECEMBER 2025:
  • We identified 120 Cisco Secure Email Gateway / Cisco Secure Email and Web Manager likely vulnerable to CVE-2025-20393 with a CVSS severity score 10.0 rated CRITICAL. CVE-2025-20393 was exploited in the wild with no patch available at the time of reporting. Zero-day exploitation was attributed by Cisco Talos to Chinese-nexus threat actor UAT-9686, which potentially overlapped with APT41 (Brass Typhoon) and UNC5174. Patching progress for this CVE can be tracked on our public Dashboard.

  • We scanned for and reported WatchGuard Firebox devices unpatched for CVE-2025-14733 with a CVSS severity score 9.8 rated CRITICAL. We observed 125,000 vulnerable IP addresses on 2025-12-20. Patching progress for this CVE can be tracked on our public Dashboard.
  • After Arctic Wolf reported observing intrusions involving malicious Single Single On (SSO) logins on Fortinet FortiGate appliances, to help system defenders respond to CVE-2025-59718 (CVSS severity score 9.8 rated CRITICAL) and CVE-2025-59719 (CVSS severity score 9.8 rated CRITICAL), we added fingerprinting of Fortinet devices with FortiCloud SSO enabled to our Device Identification reporting, identifying over 25,000 publicly exposed devices and encouraging remediation. Statistics are available on our public Dashboard.

  • In response to the “MongoBleed” vulnerability CVE-2025–14847 (CVSS severity score 7.5 rated HIGH) becoming public, we added version based detection of likely unpatched MongoDB instances to our existing publicly exposed instance reporting, revealing 74,854 possibly unpatched versions out of 78,725 publicly exposed on December 29th). Statistics are available on our public Dashboard.

The media routinely used Shadowserver’s awareness raising social media output and independent public Dashboard statistics to illustrate the risk and impact of new and emerging threats, resulting in thousands of media and social media articles referencing our activities. You can find a curated set of some of those highlights that demonstrate the engagement and global impact in the media coverage section of our website.

– Shadowserver’s Global Cybersecurity Capacity Building

We expanded and enhanced our Global Cybersecurity Capacity Building (CCB) efforts in 2025, due in significant part to the support of the United Kingdom’s Foreign Commonwealth and Development Office (UK FCDO), as well as the support of the German Federal Foreign Office, German GIZ, the European Union, and the Economic Community of West African States (ECOWAS) Commission.

Since 2021, we have provided extensive CCB services globally, with projects in the Indo-Pacific, Africa, the Middle East, Latin America, and Central and Eastern Europe, among others.

Our CCB services help nCSIRTs, government agencies, network operators, and system defenders improve threat detection, increase cybersecurity situational awareness, enable effective incident response, and strengthen cyber resilience.

We recently enhanced our CCB capabilities by developing a complete “CCB toolkit”. This toolkit provides an essential digital pipeline that enables an entity to ingest, parse, and analyze voluminous cyber threat intelligence (CTI) data, and distribute the data to affected constituent network owners through automated alert notifications. Components of the Shadowserver CCB toolkit include the following:

UK FCDO CCB Projects

In 2025, the primary focus of Shadowserver’s CCB efforts was on delivering training workshops and community engagement in the Indo-Pacific (led by Regional Coordinator/Liaison Barry Greene) and in Africa (led by Director for Africa Andy Chadwick). This was made possible by the generous support of the UK FCDO, and expanded on previous project work already reported in March 2021, December 2021, April 2022, September 2022, April 2023, May 2023, May 2023, and February 2025.

Barry worked closely with nCSIRT teams in the Indo-Pacific to improve our working relationships and encourage more effective use of Shadowserver’s free data feeds, with a particular focus on Indonesia, Malaysia, the Philippines and Thailand. Single/multi-day workshops were held with nCSIRTs, such as the Philippines’ NCERT (under the Department of Information and Communications Technology (DICT)) and CERT.PH in April, Indonesia’s BSSN/ID-SIRTII/CC in May, and Thailand’s ThaiCERT in August.

Updated cybersecurity legislation in some ASEAN countries establishes multiple new Sectoral CSIRTs, each covering a Critical Infrastructure sector. Barry worked with the nCSIRT and new Sectoral CSIRTs in Thailand and the Philippines to help them begin their journey into the community. Several online workshops were held with the Thai Banking CERT (TB-CERT) and the Philippines Ministry of Finance CSIRT. The progressive regional cybersecurity legislation, regulations, growth of sectoral CSIRTs, and industry requirements throughout the Indo-Pacific region provide opportunities to utilize Shadowserver’s services to deliver cost-effective, community-driven threat intelligence.

Regional events were attended where Barry presented, participated in panel discussions, and met with stakeholders. These included presenting at Division Zero (Div0) in Singapore in April and meetings with IMDA, ISG-CERT and Globe Telecom in April; New Zealand Internet Task Force (NZITF) annual conference in July; Thai Banking Sector CERT conference in Bangkok in August; Singapore International Cybersecurity Week (SICW) conference, Global Forum for Cybersecurity Experts (GFCE) Southeast Asia regional meeting, IMDA ISG-CERT, GITSIR and GovTech, and Ensign InfoSecurity meetings in October; DICT Cybersecurity Bureau’s 3rd Annual Philippine CERT conference (CERTCON) in November in Quezon City, where he presented under the theme “From Innovation to Protection: Innovating Security, Empowering Progress”; and, also in November, Asia Pacific CERT (APCERT) 2025 annual conference in Sydney. As part of our partnership with the Forum of Incident Response and Security Teams (FIRST), Barry also helped support the FIRST Multi-Stakeholder Ransomware SIG. Shadowserver CEO Piotr Kijewski presented on “Collaborative Response to Emerging Critical RCE Vulnerabilities in Exposed Assets” at the APNIC60 conference in Vietnam in September and also attended the SICW conference in October.

Andy participated in nearly two dozen Africa-focused events in 2025 which included training workshops, conference presentations, and panel discussions. These events included a training workshop at the Nigeria National Conference in July titled “Cyber Threat Intelligence – A Hands-On Approach to Threat Hunting” in which Andy provided practical insights and tools for identifying, tracking, and mitigating cyber threats in real-time.

Shadowserver often partnered with FIRST to deliver joint regional CCB sessions. This included a cybersecurity workshop with FIRST in Mangochi, Malawi, with mwCERT and stakeholders (February); Operators Technical Cybersecurity training with FIRST and UCC in Kampala, Uganda (August); Cyberdrill Workshop & IntelMQ training with CSA/GH-CERT and FIRST in Accra, Ghana (October); and a presentation and workshop with FIRST at Cyber THREAT 2025 in Durban, South Africa (November).

Other major events and training sessions attended in the Africa region where Andy presented, participated in panel discussions, and met with stakeholders included: Commonwealth Cyber Fellowship meeting in the Seychelles (March); Aspen Digital event in the UK (representing African themes and topics, April); presentation at GISEC Middle East & Africa in Dubai, UAE and ETEX – Addis Ababa, Ethiopia (May); presentation at ITWeb in Sandton, South Africa (June) and  presentation and workshops at Cyber Carnival in Nairobi, Kenya (June); presentation at ACDF Africa Cyber Defense Forum, Kigali, Rwanda; and a presentation at Cyber Week Africa conference, Nairobi, Kenya (October).

ECOWAS / WACREN CCB Project in West Africa

In 2025, Shadowserver joined a CCB project under the “Joint Platform for Advancing Cybersecurity” in West Africa, launched by the Economic Community of West African States (ECOWAS) Commission in collaboration with Germany’s G7 presidency in 2022. Funded by the German Federal Foreign Office and the European Union, and implemented by Germany’s Corporation for International Cooperation (Gesellschaft für Internationale Zusammenarbeit or  GIZ), this project supported the ECOWAS Commission in increasing cyber diplomacy capacities of diplomats; strengthening operational response capabilities of technical teams; and increasing the overall cyber awareness and coordination in the region.

As part of the project, Shadowserver created a cyber threat intelligence platform for West and Central Research and Education Networks (WACREN) and its constituents using Shadowserver’s free, daily threat intelligence data feeds that identify publicly exposed, vulnerable, misconfigured, and compromised assets in the networks of WACREN’s constituency. This enabled WACREN to operate as a regional cyber threat intelligence gateway for the research and education community with increased awareness of existing and emerging cyber threats in the region. It further provided WACREN with a daily snapshot of the region’s cyber threat landscape, along with actionable data to issue alert notifications to constituents to aid vulnerability patching and remediation efforts.

An important component of the WACREN / ECOWAS CCB project involved participating in training programs and cybersecurity events in the region. In April, Shadowserver CEO Piotr Kijewski participated in a panel discussion titled “Bridging the Gap: Strengthening Cooperation Between National CSIRTs and NREN Communities” at the WACREN 2025 Conference held in Dakar, Senegal as well as training for the ECOWAS Information Sharing and Analysis Center (ISAC) on Shadowserver data.

In June, Shadowserver CEO Piotr Kijewski and Shadowserver Director for Africa Andy Chadwick led a workshop training for universities, National Research and Education Networks (NRENs), and nCSIRTs in West Africa at WACREN offices in Accra, Ghana. The workshop focused on how to effectively ingest, parse, analyze and distribute Shadowserver’s cyber threat data using a set of open source tools (including IntelMQ, Elasticsearch, and Kibana) to better serve constituents. As part of the project, we assembled these open source tools to create a “Shadowserver-in-a-box” system to help reduce the technical challenges often associated with managing large data sets.

Piotr’s training efforts continued at a UK FCDO-sponsored event in December when he presented on “Interpreting and Visualizing Shadowserver Threat Data Using IntelMQ + ELK Dashboard” at the 2025 FIRST & AfricaCERT Symposium: Africa and Arab Regions held in Mauritius.

– Shadowserver’s Free Support to Law Enforcement in the Fight Against Cybercrime

Shadowserver’s free support to some of the most significant international Law Enforcement cyber threat disruption operations continued throughout 2025. As long-time trusted partners of Law Enforcement Agencies (LEAs) around the world, we provide free, valuable and timely technical assistance and expertise to Law Enforcement cybercrime investigations and disruption operations.

Shadowserver’s support included: sinkholing services (in which threat actors’ control over infected victim computers is severed and botnet traffic is redirected to sinkhole servers operated by Law Enforcement or Shadowserver, typically pursuant to a lawful court order); quarantining malicious domains (used by threat actors to facilitate their crimes) using the Registrar of Last Resort (RoLR), Shadowserver’s sister nonprofit organization and ICANN-accredited special purpose DNS registrar; and using Shadowserver’s existing daily network remediation report channels to effectively deliver victim notifications to 10,000+ subscribing organizations globally and 201 nCSIRTs covering 175 countries and territories around the world.

In addition to Operation Endgame featured in the preceding section “In the Spotlight: Impact Stories of 2025”, Shadowserver’s 2025 support to Law Enforcement disruptions included:

  • BidenCash Marketplace: In June, the US Department of Justice (DoJ) and the United States Secret Service expressed their thanks to Shadowserver and its partners for assistance in the seizure of approximately 145 darknet and traditional Internet domains, as well as cryptocurrency funds, associated with the BidenCash criminal marketplace. The BidenCash marketplace was used to simplify the process of buying and selling stolen credit cards and related personal information. It had more than 117,000 customers, facilitated the trafficking of over 15 million payment card numbers and personally identifiable information, and generated over $17 million in illicit revenue. The investigation was led by the US Secret Service (USSS) and the US Federal Bureau of Investigation (FBI).

  • Operation Eastwood: In July, Shadowserver was credited for its support of Operation Eastwood, a joint international Law Enforcement disruption operation coordinated by Europol and Eurojust against “noName057(16),” a pro-Russian cybercrime network that conducted Distributed Denial of Service (DDoS) attacks on Ukraine and countries that support Ukraine.

  • Operation Serengeti 2.0: In August, INTERPOL announced the results of Operation Serengeti 2.0, which targeted high-impact cybercrimes including ransomware, online scams, and Business Email Compromise (BEC). This operation was coordinated by INTERPOL and involved Law Enforcement from 18 African countries and the United Kingdom, and was supported by Shadowserver and eight private sector partners. Highlights of the operation included 1,200 cybercriminals arrested, USD 97.4 million recovered, and 11,432 malicious infrastructures dismantled. The operation included a training week for international Law Enforcement partners in the Seychelles in June, where Shadowserver Law Enforcement Liaison Stewart Garrick presented on Shadowserver’s operational support work.

  • Operation SIMCARTEL: Shadowserver supported Operation SIMCARTEL, announced by Europol in October. The operation involved searches, arrests, seizures, and the dismantling of infrastructure against a criminal network that offered an online SIM-box service to cybercriminals around the world. This service enabled the criminals to conduct a wide array of crimes using telephone numbers registered to people from over 80 countries, including to set up millions of fake online accounts for social media and communications platforms subsequently used in various cybercrimes while obscuring the perpetrators’ true identity and location. The financial losses to victims amounted to several million euros. Operation SIMCARTEL was led by Law Enforcement from Austria, Estonia, Latvia and Finland, with coordination and operational support provided by Europol and Eurojust.
  • Operation Sentinel: Shadowserver supported Operation Sentinel, announced in December. Coordinated by INTERPOL, Law Enforcement in 19 countries arrested 574 suspects and recovered approximately USD 3 million in this cybercrime disruption operation conducted across Africa that targeted Business Email Compromise (BEC), digital extortion, and ransomware.

Most successful cyber threat disruption operations require extensive and long running trusted public/private partnerships. Shadowserver continued to be active members of Europol’s Advisory Group on Internet Security and an INTERPOL Gateway Partner. Jean Philippe LeCouffe, Europol Deputy Director and head of their Operations Directorate commented on our feedback about Europol’s successful approach in their new Cyber Intelligence Extension Programme (CIEP) pilot, which included Shadowserver and Microsoft during 2025, and was formally announced in February 2026. We also received positive feedback from the USSS on efforts to strengthen their digital forensic incident response in local field offices, and pro-actively engage potentially vulnerable businesses to better prevent cybercrime.

Shadowserver continued to share its hard won 15+ years of behind the scenes knowledge of cyber threat disruption with international Law Enforcement and nCSIRT partners. This included events such as presentations by Shadowserver Alliance Director Tod Eberle on ‘Practical Tips for Investigators from the Prosecutor’s Perspective‘ to the FBI’s International Task Force (ITF) at the National Cyber-Forensics and Training Alliance (NCFTA) in Pittsburgh, Pennsylvania, US in March, and Tod Eberle and Shadowserver Law Enforcement Liaison Stew Garrick to the ITF on Shadowserver’s available support to Law Enforcement investigations, botnet takedowns, and cybercrime disruption operations in April.

Shadowserver has also participated in many Law Enforcement training and disruption activities that have not been published.

Elsewhere, Shadowserver was credited as a contributor to the World Economic Forum (WEF)’s “Fighting Cyber-Enabled Fraud: A Systemic Defence Approachwhitepaper in December.

– Cybersecurity Community Initiatives and Conference Presentations

Throughout 2025, Shadowserver continued to engage with partners, cybersecurity initiatives, and conferences on a global scale, including:

  • Common Good Cyber – As original members of the secretariat, and more recently the Ecosystem Committee, we helped lead the Common Good Cyber initiative alongside six other prominent nonprofit cybersecurity organizations. Common Good Cyber is a global initiative with the goal of identifying and implementing innovative models for sustaining groups, organizations, and individuals involved in critical cybersecurity functions for the broader Internet community. More information on Common Good Cyber can be found here.
  • Cyber Civil Defense – Shadowserver remained a strong supporter of leading philanthropist Craig Newmark’s Cyber Civil Defense initiative (designed to bring together broad elements of society to work collaboratively in defending people, organizations, communities, and nations from cyber insecurity). We also continued to be a proud partner of Craig’s Take9 campaign (a public service campaign to combat cyber threats by encouraging people to take a 9-second pause and think before they click, download, or share a file while online).
  • MISP-LEA – We continued our participation in the EU Internal Security Fund (ISF) MISP-LEA project with CIRCL (the Luxembourg nCSIRT) by providing specialized free threat intelligence feeds to the European and worldwide LE community. The project funding from the EU ended in October, however both CIRCL and Shadowserver remain committed to the project and continue to support it using other funds.
  • AIPITCH – We kicked-off our collaboration and work on the EU AIPITCH, an international project led by NASK (the Polish National Research Institute) to develop AI tools that quickly detect and neutralize cyberattacks. Shadowserver contributes by operating a Global Honeypot Sensor Network that can be used for training, developing device profiles and creating signatures of observed attacks.
  • Shadowserver received a grant from the Asia Pacific Network Information Centre (APNIC) Foundation to help support the APNIC region with its threat intelligence feeds throughout the year.
  • Verizon DBIR – For many years, Shadowserver has regularly contributed data sets to the Verizon Data Breach Investigations Report (DBIR) – the leading independent, multi-data source, curated annual industry threat assessment. This year we were asked to contribute unique vulnerability statistical data (as observed by our scans throughout the year) to the 2025 DBIR.
  • VulnCheck KEVs – We started our collaboration with VulnCheck on identifying KEVs in Chinese and South East Asian devices that previously had no CVE assignments. Newly assigned CVEs included, amongst others, D-Link CVE-2018-25115 (CVSS 10.0 rated CRITICAL), Sangfor CVE-2023-7307 (CVSS 8.7 rated HIGH), SecGate CVE-2023-7308 (CVSS 8.7 rated HIGH), Dahua CVE-2023-7309 (CVSS 10.0 rated CRITICAL), Dahua CVE-2024-13985 (CVSS 10.0 rated CRITICAL), Feijiu Medical Technology CVE-2025-34162 (CVSS 9.3 rated CRITICAL), etc. – helping to raise awareness amongst system defenders and vendors about new vulnerabilities in networked devices.
  • UK Integrated Security Fund Conference – In February, Shadowserver Law Enforcement Liaison Stewart Garrick was a panelist at the Integrated Security Fund (ISF) Conference for UK Government in Whitehall, covering Shadowserver’s CCB and FCDO-funded project activities, including GESI/DEI.
  • UN OEWG – In February, Shadowserver Alliance Director Tod Eberle attended the United Nations Open Ended Working Group (OEWG) on Information and Communication Technologies 10th Substantive Session where he participated in a side event panel discussion titled “Cybersecurity for the Common Good: Strengthening Nonprofits Engagement in a Permanent UN Mechanism on ICT Security” hosted by the European Union Institute for Security Studies (EUISS). The discussion highlighted the valuable contributions of nonprofit cybersecurity organizations to global Internet security, the challenges these nonprofits face, and how such organizations can meaningfully participate in a permanent UN mechanism on ICT security.

  • NCSC.NL – We collaborated on improving the cybersecurity of the Netherlands via our threat intelligence feeds.
  • Common Good Cyber / UK FCDO Event – In February, Shadowserver Alliance Director Tod Eberle participated in a panel discussion on “Identifying Effective Support for High-Risk Actors” at Common Good Cyber’s “Bridging the Gap: Delivering Cybersecurity to High Risk Actors” event hosted by the UK’s Foreign Commonwealth and Development Office (FCDO) in London.
  • Balkan Cybersecurity Conference – In March, Shadowserver’s Industry Relations Manager Jon Flaherty presented “An Overview of Shadowserver Scan, Sinkhole, Honeypot, and Source Reports by Country” at the Balkan Cybersecurity Days 2025 Conference co-hosted by FIRST in Montenegro.
  • SECURE International Summit – In March, Shadowserver CEO Piotr Kijewski presented “Diving Into the Cyber Attack Surface of Central & Eastern Europe” at the SECURE International Summit hosted by the Polish Presidency, Council of the European Union, in Bydgoszcz, Poland.
  • OSCE Event – In March, Shadowserver CEO Piotr Kijewski also took part in a panel discussion titled “Protection and Resilience: the Evolution of Cyber Threats in the OSCE Area” hosted by the Organization for Security and Co-operation in Europe (OSCE) in Vienna, Austria.
  • Pall Mall Process – We remained an active participant in the joint UK-France led Pall Mall Process (aimed at addressing the proliferation and misuse of commercial cyber intrusion tools), including at the April meeting held in Paris where Shadowserver’s Law Enforcement Liaison Stewart Garrick took part in a panel discussion on the challenges of tracking commercial spyware and their associated technical infrastructure. Shadowserver was listed as a civil society representative in the Pall Mall Process Consultation on Good Practices Report.
  • UN Cyber NormsIn May, Shadowserver Alliance Director Tod Eberle participated in an interactive workshop in Berlin hosted by the German Federal Foreign Office titled “Strengthening Technical Capacity for Implementing UN Cyber Norms”. Tod showcased how Shadowserver’s CCB activities strengthen technical capacity for implementing UN cyber norms. The workshop resulted in a policy brief written by Interface (formerly Stiftung Neue Verantwortung, a European think tank specialising in information technology and public policy) titled, “Signals in the Noise: Building Governmental Capabilities to Detect Cybersecurity Threats.” Shadowserver was listed as a contributor to the policy brief and was cited several times throughout, including for our public Dashboard funded by the UK FCDO. In March, FIRST published an article titled ‘The role of National CERTs/CSIRTs in Implementing the UN Norms of Responsible Behaviour in Cyberspace‘. It included a section on ‘The UN 11 Norms of Responsible Behaviour in Cyberspace’, with Shadowserver included as an example in point 8: Vulnerability Management stating “Effective vulnerability management is a cornerstone of cybersecurity, and national CERTs/CSIRTs must work together to identify, mitigate, and fix vulnerabilities before they can be exploited by malicious actors. Regular vulnerability assessments and the use of services like ShadowServer can help identify threats early.
  • GC3B 2025 – In May, Shadowserver Alliance Director Tod Eberle participated in a panel discussion titled “Leveraging Network Effects: Information and Threat Intelligence Sharing for Cyber Capacity Building” at the Global Conference on Cyber Capacity Building (GC3B) 2025 in Geneva, Switzerland.
  • Cyber UK Conference – In May, Shadowserver Director David Watson presented and was a panelist in a session titled “The Threat: Seizing the Initiative from Our Adversaries – The Art of the Takedown” at the CyberUK Conference in Manchester hosted by the UK’s National Cyber Security Centre (NCSC).
  • FIRST Conference – In June, Shadowserver CEO Piotr Kijewski and Shadowserver Director for Africa Andy Chadwick attended the 37th Annual FIRST Conference in Copenhagen, Denmark. Piotr presented a session titled “Bringing Actionable Data to Internet Defenders: Threat & Vulnerability Intelligence Capacity Building Efforts Across the Planet.” Andy co-presented a session titled “Assessing CSIRT Maturity Across Africa’s Regional Economic Communities: Implications for Capacity Building.”
  • Luxembourg GRC Summit -In June, Shadowserver Alliance Director Tod Eberle participated in a panel discussion titled “Safeguarding Rights and Data: Integrating GRC and Cybersecurity into Humanitarian and Human Rights Works” at the 2025 Luxembourg GRC Summit hosted by The National Cybersecurity Competence Center (NC3) of Luxembourg. The panel included representatives of UNICEF and the International Committee of the Red Cross, and was moderated by a member of Luxembourg’s Foreign Ministry.
  • APNIC 60 Conference – In September, Shadowserver CEO Piotr Kijewski presented at the APNIC Conference in Vietnam on the topic of “Collaborative Response to Emerging Critical RCE Vulnerabilities in Exposed Assets”, detailing Shadowserver’s response to many high-profile critical vulnerabilities and how we worked on new vulnerability scans at Internet scale to quickly detect publicly exposed, vulnerable, or compromised instances on networks around the world.

  • M3AAWG Conference – In October, Shadowserver Alliance Director Tod Eberle participated in a panel discussion titled, “Crossing Borders, Breaking Barriers: Modern Strategies for Cybercrime Investigation and Disruption” at the 65th General Meeting of the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) held in Charlotte, North Carolina.
  • Brazil Cybersecure Conference – In October, Tod Eberle participated in a panel discussion titled “Information Sharing as a Mechanism for Collective Cybersecurity” at Brazil Cybersecure 2025 International Meeting hosted by the Secretary of Information Security and Cybersecurity of Brazil.

The Shadowserver Foundation also presented or co-presented with Law Enforcement and private industry trusted partners at multiple closed door, invite-only events internationally.

The Shadowserver Alliance

The Shadowserver Alliance continued to grow in 2025 with the addition of many new partner organizations bringing the current total to more than 40 partners. The Alliance is made up of like-minded organizations that support Shadowserver’s nonprofit mission while enjoying the many benefits the Alliance has to offer.  Among other things, the Alliance offers Partners access to a secure online Alliance chat platform where a community of cybersecurity experts from Shadowserver, fellow Alliance Partners, and nCSIRTs from around the world offer timely insights and information on the latest vulnerabilities, attack observations, and other significant cyber threats that organizations need to stay ahead of to ensure their networks are secure.

2025 saw a number of organizations become new Alliance Partners, including: Public Interest Registry (PIR), CERT Orange Polska, Arctic Security, Identity Digital, CERT.LV, SURFcert, and VulnCheck. A complete list of Alliance Partners and information on joining the Alliance can be found on our Partner page.

Help Shadowserver Support You and the Community

The complex technical nature and global scale of our free public benefit services mean that we must operate our own data center and maintain a small but highly skilled staff, resulting in operating costs totaling approximately $6 million per year at a minimum (not considering inflation or hardware replacement). Achieving consistent, sustainable funding is a constant and significant challenge.

To continue providing free public benefit services that help make the Internet more secure for all, we need your support! Please consider joining the Shadowserver Alliance, or supporting us with a one-time donation, a request for a voluntary invoice, or a funded project. You can contact us and visit our Partners Page for more information. With your help, together we can continue to detect and disrupt emerging cybersecurity threats, and keep making the Internet safer for everyone.

Recent Articles