What you have published on the internet right now, including whatever nobody remembers putting there.
Real-time attack maps: what they measure and how to read them
There is no spinning globe with coloured arcs on this page. Real-time cyber attack maps belong to the companies that publish them: below are the seven still standing, each under its owner’s name, and what each one measures before you draw a conclusion.
What a real-time attack map is
It is a picture of what one vendor’s own sensor network detects. Every dot, every arc and every country that lights up comes from a product of theirs installed somewhere.
The telemetry is their own, and it is partial. Nobody watches the whole internet: each vendor sees what happens where its products are sold. Two maps opened at the same minute disagree, and neither of them is broken.
- Endpoint software on laptops
- Firewalls in data centres
- Decoys deployed to be attacked
- The traffic crossing their own network, if they also run infrastructure
How to read one: five things to check before the globe
All five are declared somewhere on the map’s own site, and none of them is usually on the main screen.
-
01
What one dot counts They do not all count the same thing. Some plot malware detections, some denial of service, some attempts to exploit one specific vulnerability, some spam or connections to botnet control servers. Adding two of those categories together means nothing, and comparing them across two different maps means less.
-
02
Where the geography comes from From geolocating IP addresses, almost always, and that is an approximation. An address is placed by the registry record for its block and by the operator’s infrastructure, not by where a person is sitting. Put a virtual private network, a rented server on another continent or a cloud region in the path and the country that lights up is the last hop.
-
03
What "real time" means on that particular map It ranges from seconds to totals for the last twenty four hours or the last week. It completely changes what you are looking at, and each vendor declares it in its own small print.
-
04
A country lighting up says more about the vendor than the attacker Wherever that product has a large installed base it produces plenty of detections, and wherever the vendor does not sell, the map looks calm. It is a coverage map as much as a threat map. Reading "this country is the most attacked" where the data says "this is where our sensors are" is the commonest mistake made with these tools.
-
05
With no published scale, two screenshots do not compare Dot size and colour intensity are design decisions until someone publishes how many events they stand for. No scale, no time series: just a different animation every time the tab is opened.
The public maps, and who owns each one
These are the ones still standing today. Each opens on its owner’s own site, with its own branding and its own terms. None belongs to Asperis.
Each checked on 30 July 2026.
Vulnerabilities being exploited right now
The Known Exploited Vulnerabilities catalogue published by CISA, the United States cybersecurity agency, lists vulnerabilities with evidence of exploitation in real attacks. It is distributed under Creative Commons Zero 1.0, which grants commercial use.
It carries no country, no IP address and no coordinate: it is not a map. It carries vendor, product, what to do about it and how long it has been known, which is what you decide on.
Known exploited
Vulnerabilities with confirmed exploitation, published in the last twelve months.
A selection from CISA’s Known Exploited Vulnerabilities catalogue, in technology used across the sectors we work in. This is known exposure in specific products: it is not a record of attacks on any company, and it says nothing about any Asperis client.
-
- ownCloud Improper Authentication Vulnerability Exploited CISA KEV (opens in a new tab)
- JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability Exploited CISA KEV (opens in a new tab)
- Red Hat Libuser Race Condition Vulnerability Exploited CISA KEV (opens in a new tab)
- Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability Exploited CISA KEV (opens in a new tab)
- Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability Exploited CISA KEV (opens in a new tab)
- Gitea Code Injection Vulnerability Exploited CISA KEV (opens in a new tab)
- Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability Exploited CISA KEV (opens in a new tab)
- Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability Exploited CISA KEV (opens in a new tab)
- Oracle E-Business Suite Improper Privilege Management Vulnerability Exploited CISA KEV (opens in a new tab)
- KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability Exploited CISA KEV (opens in a new tab)
- PTC Windchill and FlexPLM Improper Input Validation Vulnerability Exploited CISA KEV (opens in a new tab)
- Lantronix EDS5000 Code Injection Vulnerability Exploited CISA KEV (opens in a new tab)
Source: CISA Known Exploited Vulnerabilities catalogue, under Creative Commons Zero 1.0. Asperis is not affiliated with, or endorsed by, CISA. Cycle checked 1 Sep 2026, 03:13 UTC. Open the catalogue on cisa.gov (opens in a new tab)
What can be measured about your company
A map says nothing about you. These four questions do, and all four have an answer with a name, a date and evidence attached.
What version each of those things runs, and whether any of them appears in the catalogue above.
Which credentials for your domain are circulating in breaches and forums.
How far somebody who gets hold of one of them actually reaches.