Live threat picture: attacks, exploited vulnerabilities and breaches
Attack volume, vulnerabilities confirmed as exploited, and disclosed breaches. Three public data sources on one page, so you can see what to put first in your own defenses.
Generated 2026-10-08 00:28 (UTC)
Key points
- 4 vulnerabilities were newly confirmed as exploited this week. If any is in a product you run, patch it before your other updates.
- Of the 26 breaches added in the last 90 days, 2 included passwords. Most exposed email addresses, names and phone numbers, which are used for scam emails and texts. Do not sign in through links in messages you receive.
- Attack volume swings a lot from day to day. If you run a site, the practical step is to have something that can absorb a sudden spike, such as a CDN or WAF, set up in advance.
How to read this page, and its limits
- The Cloudflare graphs count only attacks that Cloudflare's network detected and mitigated. They are not the attack volume of the whole internet.
- A "source" country is where the attack traffic came from. The attacker is not necessarily there: hijacked devices and rented cloud servers are often used.
- CISA KEV lists vulnerabilities for which the US CISA has evidence of exploitation. Not being listed does not mean safe.
- Breach numbers include only disclosed breaches. Disclosure can take weeks or months after the breach.
Attack volume, sources and targets
These are Cloudflare Radar graphs embedded as-is. Labels inside the graphs are in English and are updated by Cloudflare (last 7 days).
Network-layer (L3/L4) attack volume, worldwide
DDoS attacks that flood links and servers with traffic. The dotted line is the previous 7 days.
Source: Cloudflare Radar (CC BY 4.0)
Application-layer (L7) attack volume, worldwide
Attacks over HTTP, such as floods of requests to websites and apps.
Source: Cloudflare Radar (CC BY 4.0)
Application-layer (L7) attack volume, Japan
L7 attacks aimed at sites in Japan.
Source: Cloudflare Radar (CC BY 4.0)
Where attacks come from and where they go (L7)
Use Source / Target at the top right to switch. The map and the diagram show which locations send and receive the most attacks.
Source: Cloudflare Radar (CC BY 4.0)
Share of malicious email
Of the email Cloudflare processed, the share classified as malicious (phishing, malware and similar).
Source: Cloudflare Radar (CC BY 4.0)
Newly exploited vulnerabilities this week
Added to CISA KEV (the catalog of vulnerabilities known to be exploited) in the last 7 days. EPSS is the estimated probability that exploitation is observed within 30 days.
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Added to KEV: 2026-10-02Look up →All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Added to KEV: 2026-10-02Look up →An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Added to KEV: 2026-10-01Look up →
Recently disclosed breaches (worldwide)
Two data sets, shown separately: this site's incident log, built from organisations' own notices, and totals from breaches added to Have I Been Pwned.
This site's incident log (last 30 days)
By country / region
- Japan39
- United States7
- United Kingdom2
- France2
- Denmark1
- South Korea1
- Poland1
- Spain1
What leaked or stopped
- Names & contacts50
- Operations halted9
- Government ID numbers9
- Bank data7
- Passwords6
- ID documents4
- Health data3
- Code & credentials2
- Card data1
Highest-impact incidents
- 2026-10-06MrMax (MrMax app and online store)JapanNames & contactsAnalysis →
- 2026-10-05Monogatari Corporation (Yakiniku King app)JapanNames & contactsAnalysis →
- 2026-10-05Denmark's CPR (civil registration system)DenmarkGovernment ID numbersNames & contactsAnalysis →
- 2026-09-25Times Mobility (Times Car)JapanID documentsNames & contactsAnalysis →
- 2026-09-25Fines (reservation system)JapanNames & contactsSource ↗
- 2026-09-24BitgetSeychellesOperations haltedSource ↗
- 2026-09-19AFPAFranceNames & contactsSource ↗
- 2026-09-19LMU MunichGermanyBank dataHealth dataNames & contactsAnalysis →
Only incidents confirmed by the organisation, a regulator or reputable reporting are logged. This is not a complete list of all breaches.
See all 2026 incidents →Breaches added to Have I Been Pwned
- Of 26 breaches in the last 90 days, 2 included passwords
- Median time from breach to listing: about 26 days
Data most often included (last 90 days, number of breaches)
- Email addresses26
- Names24
- Phone numbers19
- Physical addresses17
- Dates of birth9
- Locations8
- Genders7
- Purchases6
Organisation names are not shown: a listing on Have I Been Pwned is not necessarily the organisation's own disclosure. Spam lists, malware/stealer-log data and breaches judged fabricated are excluded.
Breach totals: Have I Been Pwned (CC BY 4.0). Totals are computed by this site.
Sources and licences
- Attack graphs: Cloudflare Radar (CC BY 4.0). The embedded graphs collect usage metrics with Cloudflare Web Analytics (privacy policy).
- Exploited vulnerabilities: CISA Known Exploited Vulnerabilities Catalog (CC0 1.0).
- Exploit probability: FIRST EPSS. See EPSS at https://www.first.org/epss
- Breach totals: Have I Been Pwned (CC BY 4.0). Totals are computed by this site. Have I Been Pwned data is refreshed at most every 12 hours (retrieved 2026-10-07 22:46 UTC).
- Incident log: recorded by this site from organisations' notices, regulators and reporting (all 2026 incidents).