Skip to content
>_ITDITDWeb Security Platform
Auto-updated

Live threat picture: attacks, exploited vulnerabilities and breaches

Attack volume, vulnerabilities confirmed as exploited, and disclosed breaches. Three public data sources on one page, so you can see what to put first in your own defenses.

Generated 2026-10-08 00:28 (UTC)

Key points

  • 4 vulnerabilities were newly confirmed as exploited this week. If any is in a product you run, patch it before your other updates.
  • Of the 26 breaches added in the last 90 days, 2 included passwords. Most exposed email addresses, names and phone numbers, which are used for scam emails and texts. Do not sign in through links in messages you receive.
  • Attack volume swings a lot from day to day. If you run a site, the practical step is to have something that can absorb a sudden spike, such as a CDN or WAF, set up in advance.

How to read this page, and its limits

  • The Cloudflare graphs count only attacks that Cloudflare's network detected and mitigated. They are not the attack volume of the whole internet.
  • A "source" country is where the attack traffic came from. The attacker is not necessarily there: hijacked devices and rented cloud servers are often used.
  • CISA KEV lists vulnerabilities for which the US CISA has evidence of exploitation. Not being listed does not mean safe.
  • Breach numbers include only disclosed breaches. Disclosure can take weeks or months after the breach.

Attack volume, sources and targets

These are Cloudflare Radar graphs embedded as-is. Labels inside the graphs are in English and are updated by Cloudflare (last 7 days).

Network-layer (L3/L4) attack volume, worldwide

DDoS attacks that flood links and servers with traffic. The dotted line is the previous 7 days.

Source: Cloudflare Radar (CC BY 4.0)

Application-layer (L7) attack volume, worldwide

Attacks over HTTP, such as floods of requests to websites and apps.

Source: Cloudflare Radar (CC BY 4.0)

Application-layer (L7) attack volume, Japan

L7 attacks aimed at sites in Japan.

Source: Cloudflare Radar (CC BY 4.0)

Where attacks come from and where they go (L7)

Use Source / Target at the top right to switch. The map and the diagram show which locations send and receive the most attacks.

Source: Cloudflare Radar (CC BY 4.0)

Share of malicious email

Of the email Cloudflare processed, the share classified as malicious (phishing, malware and similar).

Source: Cloudflare Radar (CC BY 4.0)

Newly exploited vulnerabilities this week

Added to CISA KEV (the catalog of vulnerabilities known to be exploited) in the last 7 days. EPSS is the estimated probability that exploitation is observed within 30 days.

4
added in 7 days
  • CVE-2026-88779CriticalCVSS8.7EPSS 0.6%

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

    Added to KEV: 2026-10-04Read analysis →Look up →
  • CVE-2026-102489CriticalCVSS9.4EPSS 1%

    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

    Added to KEV: 2026-10-02Look up →
  • CVE-2026-102490CriticalCVSS9.4EPSS 0.6%

    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

    Added to KEV: 2026-10-02Look up →
  • CVE-2026-104286CriticalCVSS9.8EPSS 2%

    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

    Added to KEV: 2026-10-01Look up →
See all exploited vulnerabilities (threat feed) →

Recently disclosed breaches (worldwide)

Two data sets, shown separately: this site's incident log, built from organisations' own notices, and totals from breaches added to Have I Been Pwned.

This site's incident log (last 30 days)

58
disclosed incidents

By country / region

  • Japan39
  • United States7
  • United Kingdom2
  • France2
  • Denmark1
  • South Korea1
  • Poland1
  • Spain1

What leaked or stopped

  • Names & contacts50
  • Operations halted9
  • Government ID numbers9
  • Bank data7
  • Passwords6
  • ID documents4
  • Health data3
  • Code & credentials2
  • Card data1

Highest-impact incidents

  • 2026-10-06MrMax (MrMax app and online store)JapanNames & contactsAnalysis →
  • 2026-10-05Monogatari Corporation (Yakiniku King app)JapanNames & contactsAnalysis →
  • 2026-10-05Denmark's CPR (civil registration system)DenmarkGovernment ID numbersNames & contactsAnalysis →
  • 2026-09-25Times Mobility (Times Car)JapanID documentsNames & contactsAnalysis →
  • 2026-09-25Fines (reservation system)JapanNames & contactsSource ↗
  • 2026-09-24BitgetSeychellesOperations haltedSource ↗
  • 2026-09-19AFPAFranceNames & contactsSource ↗
  • 2026-09-19LMU MunichGermanyBank dataHealth dataNames & contactsAnalysis →

Only incidents confirmed by the organisation, a regulator or reputable reporting are logged. This is not a complete list of all breaches.

See all 2026 incidents →

Breaches added to Have I Been Pwned

7
Breaches added (30 days)
26
Breaches added (90 days)
39.5M
Accounts exposed (30 days)
167M
Accounts exposed (90 days)
  • Of 26 breaches in the last 90 days, 2 included passwords
  • Median time from breach to listing: about 26 days

Data most often included (last 90 days, number of breaches)

  • Email addresses26
  • Names24
  • Phone numbers19
  • Physical addresses17
  • Dates of birth9
  • Locations8
  • Genders7
  • Purchases6

Organisation names are not shown: a listing on Have I Been Pwned is not necessarily the organisation's own disclosure. Spam lists, malware/stealer-log data and breaches judged fabricated are excluded.

Breach totals: Have I Been Pwned (CC BY 4.0). Totals are computed by this site.

Sources and licences