Media Coverage

Shadowserver in the news

768 Vulnerabilities Exploited in the Wild in 2024: A 20% Year-Over-Year Surge

Cyber Security News, February 3, 2025

According to the latest findings from VulnCheck, 768 Common Vulnerabilities and Exposures (CVEs) were publicly reported as exploited in the wild for the first time this year (2024). Spikes in exploitation reporting frequently coincided with major industry events, including the RSA Conference, or were influenced by disclosures from newly onboarded sources like ShadowServer. ShadowServer’s integration into reporting processes in January also led to increased public awareness of exploitation.

The 2024 report highlighted that the initial evidence of exploitation came from a diverse set of 112 unique sources, underscoring the importance of collaboration within the security community. These sources include: Third-party security vendors, Government Agencies; Non-profits: Groups like ShadowServer significantly contributed to disclosure efforts; Product Vendors; and Independent Platforms.

Hackers exploiting flaws in SimpleHelp RMM to breach networks

Bleeping Computer, January 28, 2025

Hackers are believed to be exploiting recently fixed SimpleHelp Remote Monitoring and Management (RMM) software vulnerabilities to gain initial access to target networks. The flaws, tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, allow threat actors to download and upload files on devices and escalate privileges to administrative levels.

Threat monitoring platform Shadowserver Foundation reported they see 580 vulnerable instances exposed online, most (345) located in the United States.

50,000 Fortinet Firewalls Remain Vulnerable to Critical Zero-Day Exploit

Cyber Security News, January 22, 2025

As of January 22, 2025, nearly 50,000 Fortinet firewall devices remain exposed to a critical zero-day vulnerability despite urgent warnings and available patches. CVE-2024-55591 is an authentication bypass vulnerability in Fortinet’s FortiOS and FortiProxy products.

Data from the Shadowserver Foundation reveals that over 50,000 devices remain unpatched as of January 21, with significant concentrations in Asia (20,687), North America (12,866), and Europe (7,401).

2,048 Ivanti VPN Instances Vulnerable to Exploited Zero-Day Attacks

Cyber Security News, January 11, 2025

The vulnerability is a critical stack-based buffer overflow with a CVSS score of 9.0 that allows unauthenticated remote code execution. It affects multiple Ivanti products, including Connect Secure versions.

Shadowserver observed that 2,048 instances worldwide are vulnerable. The vulnerability tracked as CVE-2025-0282, has been actively exploited since mid-December 2024.

The Pall Mall Process: Consultation on Good Practices Summary Report

GOV.UK, January 8, 2025

In February 2024, representatives from States, international organisations, private industry, academia, and civil society came together to consider the challenges posed by the proliferation and irresponsible use of commercial cyber intrusion capabilities (CCICs) and launched the Pall Mall Process. In August 2024, the Pall Mall Process launched a consultation on good practices through which to tackle this shared threat. This report summarises responses to the Pall Mall Process consultation into good practices, including examples, recommendations and concerns raised by participants in written responses and through virtual workshops.

Civil society and academia represented: Shadowserver Foundation

Backdooring Your Backdoors - Another $20 Domain, More Governments

watchTowr Labs, January 8, 2025

Put simply – we have been hijacking backdoors (that were reliant on now abandoned infrastructure and/or expired domains) that themselves existed inside backdoors, and have since been watching the results flood in. This hijacking allowed us to track compromised hosts as they ‘reported in’, and theoretically gave us the power to commandeer and control these compromised hosts. Over 4000 unique and live backdoors later…

For the same reasons that both this research and the .MOBI research came to exist, we would be guilty of the exact same careless disposal of infrastructure if we were to let these domains expire as their previous owners did. We’re incredibly grateful for the support of The Shadowserver Foundation, who have agreed yet again to save us from our own adventures and to take ownership of the domains implicated in this research and sinkhole them.

Playbook for Strengthening Cybersecurity in Federal Grant Programs for Critical Infrastructure

whitehouse.gov, December 17, 2024

The Cybersecurity and Infrastructure Security Agency (CISA) and Office of the National Cyber Director (ONCD) published Playbook for Strengthening Cybersecurity in Federal Grant Programs for Critical Infrastructure to enable grant-making agencies to incorporate cybersecurity into their grant programs, and to enable grant-recipients to build cyber resilience into their grant-funded infrastructure projects.

The guide includes a comprehensive list of cybersecurity resources available to support grant recipient project execution. Shadowserver is included in the Advisory Support/Technical Assistance Service section in the Protect category.

Fraudulent shopping sites tied to cybercrime marketplace taken offline

Europol, December 5, 2024

Europol has supported the dismantling of a sophisticated criminal network responsible for facilitating large-scale online fraud. In an operation led by the Hanover Police Department (Polizeidirektion Hannover) and the Verden Public Prosecutor’s Office (Staatsanwaltschaft Verden) in Germany, and supported by law enforcement authorities across Europe, over 50 servers were seized, significant digital evidence was secured, and two key suspects were placed in pretrial detention.

Conflict, Stability and Security Fund annual report 2023 to 2024

GOV.UK, December 5, 2024

The UK Government published its 2023 to 2024 annual report on the Conflict, Stability and Security Fund (CSSF), a cross-government Fund, that acted as a catalyst for a more integrated government response to tackling conflict, insecurity and instability.

The section on ‘Transnational Threats: Cyber’ highlights the Shadowserver Foundation’s project work funded through the CSSF Indo-Pacific Cyber Programme – ‘Improving Threat Data for Indonesia, Malaysia, the Philippines and Thailand’. This project improved the quality of free daily cyber threat intelligence provided to national telecoms and cyber security incident response teams. In early 2024, a significant and new malware vulnerability was identified in the region, released by a Chinese state actor. Shadowserver quickly responded by detecting and reporting on the exposed networks and devices, alerting cyber response teams, network owners and media. New scanning techniques were developed to determine whether exposed devices were vulnerable and reported through existing mechanisms. Through CSSF funding, Shadowserver helped multiple governments and users in the Indo-Pacific and across the world, including the UK, to help identify and reduce vulnerabilities to a new cyber threat.

Cybercriminal Network Dismantled – Successful "Action Day" in the Fight Against Phishing and Data Trafficking

Polizeidirektion Hannover, December 5, 2024

On Wednesday, December 4, 2024, law enforcement authorities dismantled key structures of an extensive network for committing cybercrime during a coordinated operation. In close collaboration with Europol and police forces across Europe, the Lower Saxony prosecution authorities shut down over 50 servers, secured extensive digital evidence, and placed two suspects in pretrial detention.

The operation involved police authorities from the Netherlands, Finland, Austria, Czech Republic, Poland, and Norway, as well as Europol task forces, alongside the Verden Public Prosecutor’s Office and Hanover Police Directorate. The investigative authorities were also supported by the nonprofit organization The Shadow Server Foundation.