Media Coverage

Shadowserver in the news

More Details Emerge on Exploited PaperCut Vulnerabilities

Security Week, September 1, 2026

PaperCut Software has released a second emergency patch for zero-day vulnerabilities exploited against users of its NG and MF print management solutions as more information has emerged about the flaws and their exploitation. Roughly 1,000 PaperCut instances are currently exposed to the internet, a majority in North America and Europe, according to data from the ShadowServer Foundation.

Sality Malware Disrupted in International Cyber Takedown

US Department of Justice, September 1, 2026

The Department of Justice today announced a multinational operation involving actions in the United States, Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation, to disrupt the botnet and malware known as Sality and take down its infrastructure. The victim computers infected with Sality were part of a peer-to-peer (P2P) botnet, which is a network of computers (each a “bot”) infected with the Sality malware and controlled by the Sality operator.

On Monday, CrowdStrike’s Counter Adversary Operations team, in collaboration with the Department of Justice, FBI, DCIS, international law enforcement, and private industry partners executed a peer-to-peer sinkhole operation and coordinated disruption of the Sality botnet. In conjunction with these efforts, private industry partner The Shadowserver Foundation is working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and aid in victim notification and remediation.

Investigators and prosecutors from multiple jurisdictions provided crucial assistance, including Bulgaria’s General Directorate Combating Organized Crime, Hungary’s National Bureau of Investigation Cybercrime Department, Romania’s Romanian Police / Directorate for Combating Organized Crime / Central Cybercrime Unit, Eurojust, and Europol. The Department of Justice’s Office of International Affairs provided significant assistance. Assistant United States Attorney Lauren Restrepo of the National Security Division, along with the FBI’s Los Angeles Field Office and DCIS led the U.S. efforts.

Over 8,300 Gitea servers vulnerable to code execution attacks

Bleeping Computer, August 28, 2026

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. The code injection vulnerability (CVE-2026-60004) targeted in these attacks was reported by Salesforce security researcher Shai Rod, and it allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint. “We are scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (code injection), with 8393 IPs found vulnerable on 2026-08-27,” Shadowserver said.

Critical Zimbra RCE flaw now actively exploited in attacks

Bleeping Computer, August 20, 2026

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). ZCS is a popular email and collaboration software suite used by hundreds of millions of people and organizations worldwide, including thousands of businesses and hundreds of government agencies. Internet security watchdog Shadowserver now tracks over 12,100 Zimbra servers exposed online, most of them in Europe (4,382) and Asia (4,492). However, there is no information on how many of them are honeypots or have already been patched against the CVE-2026-73570 security flaw.

Dysphoria Hijacks Routers, Gateways and IP Cameras to Build Massive IoT Botnet

GB Hackers, August 14, 2026

The Dysphoria botnet has expanded into a major Internet of Things threat, with a new Shadowserver Special Report identifying approximately 296,000 compromised devices. The campaign targets exposed routers, gateways, IP cameras and other embedded Linux systems, converting poorly secured equipment into a distributed platform for DDoS attacks and increasingly, residential proxy and relay operations. Shadowserver’s new dataset indicates that the exposure is broader and provides defenders with a substantially larger remediation target. For network defenders, the Shadowserver Special Report is designed as a retrospective, high-value notification rather than a normal 24-hour daily report.

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

Bleeping Computer, August 11, 2026

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers. Internet security watchdog group Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online, with over 200 of them unpatched against the CVE-2026-45659 vulnerability.

INTERPOL report finds AI linked to more than half of cybercrime in Africa

INTERPOL, August 3, 2026

Artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect, according to INTERPOL’s African Cyberthreat Assessment Report 2026. The 40-page report draws on survey data from 36 African member countries and highlights a defining shift: cyber-criminality has evolved from isolated incidents into an industrialized, borderless ecosystem.

In its recommendations, the report calls for standardized digital forensic capabilities, enhanced cross-border cooperation, investment in AI literacy among law enforcement officers and formal-public private partnership to support effective prevention, detection and response. INTERPOL’s Africa Cyberthreat Assessment is part of the Organization’s African Joint Operation against Cybercrime initiative funded by the United Kingdom’s Foreign, Commonwealth and Development Office. The assessment benefited from data contributed by partners Fortinet, Mastercard, the Shadowserver Foundation, S2W and TrendAI.

VulnCheck State of Exploitation 1H-2026

VulnCheck, July 28, 2026

Key takeaways from VulnCheck’s analysis in the First Half of 2026 include: In the first half of 2026, 23.43% of KEVs showed evidence of exploitation on or before the day the CVE was published. A slight drop percentage wise from the 28.93% of KEVs we observed in 2025. At the same time, vulnerabilities appear to be being exploited faster, with the median time from CVE publication to KEV falling from 120 days in 2025 to 80 days during the first half of 2026. Exploitation activity early in the CVE lifecycle remained steady, with roughly 200 CVEs becoming exploited within 31 days in the first half of 2026. Early exploitation activity has not scaled at the same pace as CVE issuance. Content management systems remained the most targeted technology category, accounting for one-third of all KEVs, a more significant percentage of KEVs than we’ve seen historically.

During the first half of 2026, 79 unique sources were the first to report exploitation. The top six sources first to report include Patchstack (70 KEVs), CrowdSec (64 KEVs), ShadowServer (57 KEVs), VulnCheck (37 KEVs), Wordfence (20 KEVs), and CISA (19 KEVs).

CISA warns admins to patch actively exploited SharePoint flaws

Bleeping Computer, July 15, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions, including SharePoint Server Subscription Edition. Internet security watchdog group Shadowserver currently tracks nearly 10,000 Internet-exposed Microsoft SharePoint servers, with over 800 of them unpatched against the CVE-2026-32201 and CVE-2026-45659 vulnerabilities.

CISA orders feds to patch max severity ColdFusion flaw by Friday

Bleeping Computer, July 8, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. The vulnerability (CVE-2026-48282) affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems. Internet security watchdog group Shadowserver currently tracks nearly 800 Adobe ColdFusion instances exposed online, but there is no information on how many are honeypots or have been secured against attacks targeting the CVE-2026-48282 flaw.