Situational awareness for NIS2 and KRITIS
German vulnerability intelligence in real time.
We aggregate NVD, CISA KEV, BSI CERT-Bund, GHSA and 40+ OSV ecosystems, enrich with German analysis, NIS2 and CRA (Cyber Resilience Act) mapping, and sector context — delivered as API, webhook, MISP feed and RSS.
Vulnerability explorer
970,271 advisories curated for SMB and KRITIS operators under NIS2. Actively exploited vulnerabilities (CISA KEV) and critical CVEs are surfaced first.
Situational stats
Refreshed every 30 seconds — counters tick live without a reload.
CVE inflation, but CISA is getting faster
The volume of published CVEs is growing exponentially — yet the share of actually exploited vulnerabilities stays in the low single digits. In parallel, CISA has cut the time between CVE publication and KEV listing down to a handful of days. Together: less noise, sharper signal.
Median days between CVE publication and CISA-KEV listing. Lower = prioritized sooner.
Year-to-date CVE publications
Cumulative CVE publications per year, derived from the earliest publication date across our ingested sources (NVD, CVE.org, OSV, MSRC, Debian, Ubuntu). Note: our capture ratio against the MITRE CVE List is currently below 100% — NVD records with status "Received / Awaiting Analysis" are now counted (since 2026-06-07), a full cvelistV5 sync follows in a later wave. A 1 : 1 match with FIRST/first.org/epss/data_stats is the target but not yet reached.
Threat Intelligence
Check live indicators in seconds
Look up an IP, domain, URL or file hash against our consolidated IoC database. Fed by abuse.ch (URLhaus, MalwareBazaar, Feodo Tracker), AlienVault OTX, CISA and curated industry feeds.
indicators total
525,501
across all sources, deduplicated
new in 24 h
71,287
freshness as a situational signal
active feeds
11
abuse.ch, OTX, internal
Top sources
- blocklist_de173,060
- cins_army156,647
- abusech_threatfox116,859
- ipsum66,392
- abusech_urlhaus46,674
- abusech_malware_bazaar16,802
Quick lookup
One IP, domain, URL or file hash — we return score and last-seen. Full provenance is available to signed-in users.
Most recently observed indicators
redacted preview
🇯🇵27.133.x.xScore 92ipJPAS9370SAKURA-B SAKURA Internet Inc.Cobalt Strikeabusech_feodo_trackerabusech_threatfox2026-07-28 12:06 UTC🇬🇧178.62.x.xScore 92ipGBAS14061DIGITALOCEAN-ASN - DigitalOcean, LLCCobalt Strikeabusech_feodo_trackerabusech_threatfox2026-07-28 12:06 UTC🇺🇸34.204.x.xScore 90ipUSAS14618AMAZON-AESQakBotabusech_feodo_tracker2026-07-28 12:06 UTC🇺🇸50.16.x.xScore 90ipUSAS14618AMAZON-AESQakBotabusech_feodo_tracker2026-07-28 12:06 UTC🇺🇸162.243.x.xScore 92ipUSAS14061DIGITALOCEAN-ASNbotnet_ccabusech_feodo_trackerabusech_threatfox2026-07-28 12:06 UTChttp://*.29.57:60054/…Score 85urlMoziabusech_urlhaus2026-07-28 12:06 UTChttp://*.194.171:48855/…Score 85urlmipsabusech_urlhaus2026-07-28 12:06 UTChttp://*.82.226:49051/…Score 85urlMoziabusech_urlhaus2026-07-28 12:06 UTC
Note: IP and domain values are redacted in the public view for DSGVO reasons (1.2.x.x, *.example.com). Full values are available to customers via the API.
Situational news & topics
Current cyber situation from curated feeds
Aggregated from BSI Bürger-CERT, BSI WID, SANS NewsBites, Krebs on Security, The Hacker News and the Allianz für Cyber-Sicherheit. Partner ads are filtered out.
- Newssecurityweek
Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model
The company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing. The post Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model appeared first on SecurityWeek .
2026-07-28 11:11 UTC - Newssecurityweek
Act Security Emerges from Stealth to Fight the Patch Problem
Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first on SecurityWeek .
2026-07-28 11:00 UTC - Newssecurityweek
Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. The post Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker appeared first on SecurityWeek .
2026-07-28 11:00 UTC - Newssecurityweek
Hush Security Raises $30 Million for AI Agent Governance
The startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million for AI Agent Governance appeared first on SecurityWeek .
2026-07-28 10:17 UTC - Newstheregister-security
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Unauthenticated command injection scores perfect 10 and may expose managed Edge devices
2026-07-28 09:15 UTC - Newsbleepingcomputer
Data breach at medical billing firm MCBS affects 1.26 million people
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
2026-07-28 09:10 UTC
Editorial
From the blog
Cybersecurity Is Survival
Howard Solomon's CSO Online piece says out loud what many in the industry think but rarely state plainly: any organization that still treats prevention as the centre of its security strategy is buying theatre. What that means for German entities under NIS2 — and why resilience on paper is worth nothing.
nis2resilienzIran Imports China's Playbook — The Barati Arrest and the Mabna Institute
An Iranian national arrested in Montenegro, a 2018 US indictment thread reaching back to Tehran, 31 terabytes of stolen research data over eight years. Kim Zetter traces how Iran — around 2013, the same year Mandiant exposed China as APT-1 — appears to have imported an economic-espionage playbook from Beijing. What that means for German universities and research institutions.
iranaptGoogle Ads as Malware Delivery: The MacSync Stealer Case
A Google Ad impersonating Anthropic's Claude Code sends macOS users to a Google Sites page, delivers a Base64-obfuscated terminal command, and steals — in one motion — browser passwords, cloud tokens, and, if present, the seed phrase of a Ledger hardware wallet. Lucas Martin's CyberPress report walks through the six stages. What that means for German developers and their employers.
malvertisingmacos
Latest priority advisories
Ranked by priority score — KEV, EPSS, CVSS, recency and CPE relevance.
CVE-2026-10520
[KEV] [critical] Ivanti Sentry — Ivanti Sentry OS Command Injection Vulnerability
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
CVE-2026-48907
[KEV] [critical] Widget Factory Joomla Content Editor: Schwachstelle ermöglicht Codeausführung
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
CVE-2021-22555
[KEV] [high] Oracle JD Edwards: Mehrere Schwachstellen
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
CVE-2023-22518
[KEV] [high] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye und Jira): Mehrere Schwachstellen
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.