Real-time attack maps: what they measure and how to read them

There is no spinning globe with coloured arcs on this page. Real-time cyber attack maps belong to the companies that publish them: below are the seven still standing, each under its owner’s name, and what each one measures before you draw a conclusion.

What a real-time attack map is

It is a picture of what one vendor’s own sensor network detects. Every dot, every arc and every country that lights up comes from a product of theirs installed somewhere.

The telemetry is their own, and it is partial. Nobody watches the whole internet: each vendor sees what happens where its products are sold. Two maps opened at the same minute disagree, and neither of them is broken.

Where a dot comes from
  • Endpoint software on laptops
  • Firewalls in data centres
  • Decoys deployed to be attacked
  • The traffic crossing their own network, if they also run infrastructure

How to read one: five things to check before the globe

All five are declared somewhere on the map’s own site, and none of them is usually on the main screen.

  1. 01
    What one dot counts They do not all count the same thing. Some plot malware detections, some denial of service, some attempts to exploit one specific vulnerability, some spam or connections to botnet control servers. Adding two of those categories together means nothing, and comparing them across two different maps means less.
  2. 02
    Where the geography comes from From geolocating IP addresses, almost always, and that is an approximation. An address is placed by the registry record for its block and by the operator’s infrastructure, not by where a person is sitting. Put a virtual private network, a rented server on another continent or a cloud region in the path and the country that lights up is the last hop.
  3. 03
    What "real time" means on that particular map It ranges from seconds to totals for the last twenty four hours or the last week. It completely changes what you are looking at, and each vendor declares it in its own small print.
  4. 04
    A country lighting up says more about the vendor than the attacker Wherever that product has a large installed base it produces plenty of detections, and wherever the vendor does not sell, the map looks calm. It is a coverage map as much as a threat map. Reading "this country is the most attacked" where the data says "this is where our sensors are" is the commonest mistake made with these tools.
  5. 05
    With no published scale, two screenshots do not compare Dot size and colour intensity are design decisions until someone publishes how many events they stand for. No scale, no time series: just a different animation every time the tab is opened.

The public maps, and who owns each one

These are the ones still standing today. Each opens on its owner’s own site, with its own branding and its own terms. None belongs to Asperis.

Each checked on 30 July 2026.

Vulnerabilities being exploited right now

The Known Exploited Vulnerabilities catalogue published by CISA, the United States cybersecurity agency, lists vulnerabilities with evidence of exploitation in real attacks. It is distributed under Creative Commons Zero 1.0, which grants commercial use.

It carries no country, no IP address and no coordinate: it is not a map. It carries vendor, product, what to do about it and how long it has been known, which is what you decide on.

Known exploited

Vulnerabilities with confirmed exploitation, published in the last twelve months.

A selection from CISA’s Known Exploited Vulnerabilities catalogue, in technology used across the sectors we work in. This is known exposure in specific products: it is not a record of attacks on any company, and it says nothing about any Asperis client.

Source: CISA Known Exploited Vulnerabilities catalogue, under Creative Commons Zero 1.0. Asperis is not affiliated with, or endorsed by, CISA. Cycle checked 1 Sep 2026, 03:13 UTC. Open the catalogue on cisa.gov (opens in a new tab)

What can be measured about your company

A map says nothing about you. These four questions do, and all four have an answer with a name, a date and evidence attached.

01

What you have published on the internet right now, including whatever nobody remembers putting there.

02

What version each of those things runs, and whether any of them appears in the catalogue above.

03

Which credentials for your domain are circulating in breaches and forums.

04

How far somebody who gets hold of one of them actually reaches.