Shadowserver — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 17, 2025
Last Seen
January 27, 2026

Shadowserver is a organization tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed December 17, 2025; most recent activity January 27, 2026.

Overview

Shadowserver Foundation is a nonprofit cybersecurity threat intelligence and incident response organization that collects and shares indicators of compromise, malware activity, and other security data to help defenders globally. It collaborates with vendors, CERTs, researchers, and operators to improve visibility into internet-wide threats and to accelerate mitigation efforts.

Related Threat Clusters

  • SonicWall SMA1000 Zero-Day Vulnerability Disclosed

    SonicWall has alerted customers to a local privilege escalation vulnerability (CVE-2025-40602) in the SMA1000 Appliance Management Console, which has been exploited in the wild in conjunction with another vulnerability…

    5 articles · Updated December 17, 2025
  • Over 6,000 SmarterMail Servers Exposed to Critical Vulnerability

    Shadowserver researchers identified over 6,000 SmarterMail servers exposed online, likely vulnerable to a critical authentication bypass flaw tracked as CVE-2026-23760. The vulnerability was disclosed by cybersecurity…

    2 articles · Updated January 27, 2026

Recent Intelligence Reports

  • Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online — Securityaffairs.Co · January 27, 2026
  • Sonicwall warns of new SMA1000 zero — Bleepingcomputer · December 17, 2025

CVSS v3.1 Breakdown