Skip to content
COOEY

◄ COMMAND CENTER

SITREP · SITUATIONAL AWARENESS

LIVE

Real-time posture across the intelligence corpus — correlation fires, threat throughput, and active narratives. Windows are 7-day / 30-day, honest to our collector cadence.

Global posture ▸
DEFCON 2
HIGH · 21 SEVERE (DEFCON-1) escalations active
Correlations / 7D
189
▲ 83% vs prior 7d
Active threats / 7D
176
▲ 21% vs prior 7d
KEV · CVE · advisories
FedRAMP monitored
424
authorized products under CVE watch
SYSTEM VITALS 13 SOURCES LIVE · freshest 4h ago 2,678 ENTITIES 3,668 EVENTS 29,282,277 DEFCON EVENTS LIVE
GLOBAL THREAT MAP // LIVE intel · geo →
85.137.53.71 · NL76.76.21.21 · US104.20.24.117 · CA172.66.150.162 · CA209.182.237.133 · JP185.10.68.127 · RO209.94.90.1 · US · Scattered Spider172.66.0.227 · CA · Play, Scattered Spider45.131.66.106 · DE64.20.53.230 · US185.70.42.45 · CH91.132.163.78 · DE · Lazarus Group142.251.186.191 · US18.160.156.19 · US18.160.156.24 · US18.160.156.28 · US18.160.156.44 · US176.65.139.204 · NL3.96.91.14 · CA83.142.209.214 · DE · Rocke34.117.59.81 · US · Rocke178.236.252.133 · NL · Earth Lusca77.91.123.187 · GE · Earth Lusca96.126.130.126 · JP · Sandworm Team188.208.141.177 · IN · Mustang Panda, RedEcho194.5.97.169 · NL · Mustang Panda, RedEcho104.20.44.100 · CA · Sandworm Team172.66.169.62 · CA · Sandworm Team137.220.156.33 · JP104.26.3.16 · CA · Turla104.26.2.16 · CA · Turla172.67.75.40 · CA · Turla174.138.125.138 · US · Turla172.67.183.105 · CA · Earth Lusca104.21.18.221 · CA · Earth Lusca76.76.21.98 · US · Earth Lusca, Contagious Interview76.76.21.22 · US · Earth Lusca, Contagious Interview140.82.113.3 · US · Earth Lusca, Contagious Interview172.66.135.165 · CA172.66.139.132 · CA
malicious IOC origin 40 geolocated indicators · node graph ▸
THREAT ACTIVITY // 7-DAY exposures →
Correlation throughput 7D 30D GEO · LIVE ▸
08-09 correlation fireshigh-sev events 08-15
Active narratives · story clusters
×2
CVE-2021-20021: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac
CVE-2021-20021
CRITICAL
×2
CVE-2019-15107: An issue was discovered in Webmin <=1.920. The parameter old in password_change.
CVE-2019-15107
CRITICAL
×2
CVE-2024-55591: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2
CVE-2024-55591
CRITICAL
×2
CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-16232
CRITICAL
×2
CVE-2023-3519: Unauthenticated remote code execution
CVE-2023-3519
CRITICAL
×2
CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/
CVE-2025-3248
CRITICAL
THREAT_TICKER
CVE-2026-17184 CVE-2026-17184: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could... CVE-2026-17181 CVE-2026-17181: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could... CVE-2026-73678 CVE-2026-73678: MindsDB Minds Platform version 26.1.0 and... CVE-2026-17182 CVE-2026-17182: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could... CVE-2026-17186 CVE-2026-17186: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could... CVE-2026-72830 CVE-2026-72830: Grav API plugin versions before 1.0.13 fail... CVE-2026-65768 CVE-2026-65768: Improper limitation of a pathname to a... CVE-2026-72826 CVE-2026-72826: The getgrav/grav-plugin-api plugin before... CVE-2026-12949 CVE-2026-12949: The Wishlist Member plugin for WordPress is... CVE-2017-11357 CVE-2017-11357: Progress Telerik UI for ASP.NET AJAX before... CVE-2021-30116 CVE-2021-30116: Kaseya VSA before 9.5.7 allows credential... CVE-2010-2861 CVE-2010-2861: Multiple directory traversal vulnerabilities... CVE-2016-1019 CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier... CVE-2026-17482 CVE-2026-17482: IBM Documentation Offline 1.0.0 through... CVE-2026-19297 CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could... CVE-2026-14525 CVE-2026-14525: IBM WebSphere Application Server - Liberty... CVE-2026-17184 CVE-2026-17184: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could... CVE-2026-17181 CVE-2026-17181: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could... CVE-2026-73678 CVE-2026-73678: MindsDB Minds Platform version 26.1.0 and... CVE-2026-17182 CVE-2026-17182: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could... CVE-2026-17186 CVE-2026-17186: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could... CVE-2026-72830 CVE-2026-72830: Grav API plugin versions before 1.0.13 fail... CVE-2026-65768 CVE-2026-65768: Improper limitation of a pathname to a... CVE-2026-72826 CVE-2026-72826: The getgrav/grav-plugin-api plugin before... CVE-2026-12949 CVE-2026-12949: The Wishlist Member plugin for WordPress is... CVE-2017-11357 CVE-2017-11357: Progress Telerik UI for ASP.NET AJAX before... CVE-2021-30116 CVE-2021-30116: Kaseya VSA before 9.5.7 allows credential... CVE-2010-2861 CVE-2010-2861: Multiple directory traversal vulnerabilities... CVE-2016-1019 CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier... CVE-2026-17482 CVE-2026-17482: IBM Documentation Offline 1.0.0 through... CVE-2026-19297 CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could... CVE-2026-14525 CVE-2026-14525: IBM WebSphere Application Server - Liberty...
CORRELATION_FIRES incident vault →
#FIRE-ADB7 08-14 18:20Z
CVE-2026-65768: Improper limitation of a pathname to a restricted directory ('path traversal') i
◈ Microsoft Office 365 GCC High, Azure Government (includes Dynamics 365) +2 more
CVEHIGH
#FIRE-096A 08-14 06:20Z
CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a den
◈ Adobe Learning Manager, Microsoft Office 365 GCC High +12 more
CVECRITICAL
#FIRE-B848 08-14 06:20Z
CVE-2010-2861: Multiple directory traversal vulnerabilities in the administrator console in Ado
◈ Adobe Analytics, Adobe Acrobat Sign for Government +6 more
CVECRITICAL
#FIRE-494B 08-13 18:20Z
CVE-2026-17276: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to esca
◈ SmartCloud for Government, IBM Cloud for Government +3 more
CVECRITICAL
#FIRE-2434 08-13 18:20Z
CVE-2026-16860: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec
◈ IBM Federal HR Cloud, MaaS360 Enterprise Mobility Management +3 more
CVECRITICAL
#FIRE-9473 08-12 06:20Z
CVE-2019-2725: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar
◈ Oracle Enterprise Performance Management (EPM), Aconex for Defense +8 more
CVECRITICAL
#FIRE-49AF 08-12 06:20Z
CVE-2021-20021: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac
◈ Office 365 Multi-Tenant & Supporting Services, Azure Commercial Cloud +2 more
CVECRITICAL
#FIRE-CF1F 08-12 06:20Z
CVE-2021-21972: The vSphere Client (HTML5) contains a remote code execution vulnerability in a v
◈ Workspace ONE, VMware Government Services (VGS)
CVECRITICAL
#FIRE-09F8 08-12 06:20Z
CVE-2020-3992: OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before E
◈ VMware Government Services (VGS), Workspace ONE
CVECRITICAL
#FIRE-9973 08-12 06:20Z
CVE-2021-21985: The vSphere Client (HTML5) contains a remote code execution vulnerability due to
◈ Workspace ONE, VMware Government Services (VGS)
CVECRITICAL