Latest news
Most recent across every source.
Highest severity right now
Newest critical and high CVEs and advisories, worst first.
Latest indicators
Newest across exploited CVEs, botnet C2 and ransomware victims.
Newly published CVEs
Critical and high severity, published in the last 7 days, from NVD. Severity is read from the CVSS metric each record actually carries.
Supply-chain advisories
GitHub Security Advisories — vulnerabilities in packages, by ecosystem, with the fixed version where one exists.
Indicators
Exploited CVEs, botnet C2 infrastructure and ransomware victims.
Look an indicator up
Paste an IP, domain, CVE, hash or company name and see whether it appears anywhere in the feeds currently loaded. This searches what is on this page — it is not a reputation service, so "no match" means "not in these feeds", not "safe".
Feed health
Every upstream source, whether it answered on the last refresh, how many items it returned and how long it took. Stale data shown as fresh is worse than no data, so failures are named rather than absorbed.
Export everything
The whole current feed, not just the page you are looking at.
Copy all IOCs gives plain addresses and hashes, one per line, for pasting into a block list. STIX is a 2.1 bundle of indicator objects with patterns, which most SIEM and TIP tools will ingest directly.
Victims over time
Posted victims per day across the last 30 days, from ransomware.live's monthly archives rather than the recent-100 feed.
Most active groups
Ranked over the same window as the chart above.
Sectors hit
Which industries these victims come from.
Countries
Where the victim organisations are based.