News & Insights

The Data Center Move - All the Gory Details and Extras

October 16, 2020
As everyone knows now, Shadowserver had a bit of a funding issue earlier this year which caused us to go through the process of needing a new space for our data operations.  A place to call home for all that storage and computing that we do daily.  A new data center was required.  This story will go through that recent history, the actual move, and a few after action and post move things that occurred.  This blog will be partially serious, some tongue in cheek, and some sad comedy, so enjoy our journey.

Fundraising Update - Avast (and Urgent 2020 Target Achieved)

September 8, 2020
Fundraising update: Avast has very generously committed $500,000 USD to support Shadowserver’s public benefit services in 2020, taking us to up to our $2.1M urgent 2020 operational target. Now we can start focusing on long term sustainability in 2021+

Supporting Shadowserver Through Optional Voluntary Invoicing

August 11, 2020
As a non-profit organization, Shadowserver has been funded to date by donations and sponsorship. However, some constituents find international donation logistics difficult. This post introduces the concept of optional voluntary invoicing to support our ongoing public benefit mission. This definitely does not mean that Shadowserver is going commercial in any way - our services continue to be freely available to all who need them. But it does provide organizations who appreciate our services with another potential complementary mechanism for financially supporting us.

The Data Center is Moving to its new Home

July 31, 2020
The Data Center is moving and we expect to be down from 2020-08-14 (Friday) to 2020-08-18 (Tuesday).  This will impact all of our services except incoming email.  Most of our data collection system will remain functional, but we will have no way of importing and reporting anything.  In fact, all reports will be suspended until we come back up.

Helping fight ransomware with NoMoreRansom

July 8, 2020
After successfully collaborating with founder partners Europol and the Dutch National Police on cybercrime disruption for many years, Shadowserver are very pleased to formally join their NoMoreRansom initiative. Available in 36 languages, supported by over 150 law enforcement agencies and business worldwide, and supporting decryption tools for over 120 different ransomware variants, NoMoreRansom is the go-to resource for education and helping victims battle ransomware. We highly recommend that you follow their advice and help support this great public benefit partnership.

Accessible Radmin Report - Exposed Radmin Services on the Internet

July 7, 2020
We have recently enabled a new IPv4 Internet-wide scan and report for accessible Radmin services on port 4899/TCP. Radmin is a remote access software product commonly in use today. Our daily scans uncover around 50,000 accessible Radmin services on port 4899/TCP. While Radmin is in general considered a secure mechanism for remote access, care should be taken as with all similar types of services to ensure no misconfiguration has taken place.

Accessible CoAP Report - Exposed Constrained Application Protocol Services on the Internet

June 24, 2020
We have enabled a new scan for exposed CoAP (Constrained Application Protocol) devices on port 5683/UDP. The scan has uncovered around 460 000 exposed CoAP services that can be potentially abused for CoAP amplification DDoS attacks. These services may also leak information or expose other vulnerabilities. This is the third IoT scan implemented as part of the EU CEF VARIoT project.

Open IPP Report - Exposed Printer Devices on the Internet

June 10, 2020
We have enabled a new scan dedicated to finding open IPP (Internet Printing Protocol) devices exposed on port 631/TCP. The roughly 80,000 devices uncovered as a result of the scan have connected to the Internet without adequate access controls or authorization mechanisms in place. This could allow for a potential range of different types of attacks, from information disclosure and service disruption/tampering, to, in some cases, remote command execution. Results of the scan are collected in the new Open IPP report. This is the second scan enabled under the EU CEF VARIoT project.

Fundraising Update - Internet Society

May 27, 2020
Another fundraising update: fellow not-for-profit organisation The Internet Society (ISOC) has very generously provided $400,000 to support our data center move and the continuing operation of Shadowserver’s public benefit services. We thank you ISOC! Getting closer to our urgent 2020 target and can achieve it with the continued help of the community.

Fundraising Update - Trend Micro

May 27, 2020
An update on progress towards our urgent 2020 fundraising target. Long term partner in fighting cybercrime Trend Micro has very generously committed $600,000 to support Shadowserver’s public benefit services ($200,000 per year for three years). Thank you very much Trend!