Cyber threat map: exploited vulnerabilities and active malware
WorldPulse follows two cyber feeds that matter and skips the theatre: CISA's Known Exploited Vulnerabilities catalogue, which lists vulnerabilities confirmed to be exploited in the wild, and abuse.ch ThreatFox, which tracks active malware campaigns and indicators of compromise.
On the map right now
- L3·cyber ·threatfox
Vidar: 51 aktif gösterge (24s)
- L2·cyber ·threatfox
php.shin_webshell: 28 aktif gösterge (24s)
- L4·cyber ·threatfox
ClearFake: 411 aktif gösterge (24s)
- L2·cyber ·threatfox
Jackskid: 11 aktif gösterge (24s)
- L2·cyber ·threatfox
Remus: 14 aktif gösterge (24s)
- L2·cyber ·threatfox
Cobalt Strike: 10 aktif gösterge (24s)
- L3·cyber ·threatfox
Unknown malware: 64 aktif gösterge (24s)
- L2·cyber ·threatfox
AsyncRAT: 16 aktif gösterge (24s)
Vulnerabilities that are actually being exploited
CISA's KEV catalogue is deliberately narrow: it lists only vulnerabilities with confirmed active exploitation, which makes it far more actionable than the full CVE firehose. Each entry links to its authoritative NIST National Vulnerability Database record.
Active malware campaigns
ThreatFox, run by abuse.ch at the Bern University of Applied Sciences, publishes indicators of compromise under a CC0 licence — the cleanest licensing of any feed WorldPulse uses. Indicators are aggregated by malware family rather than listed individually, because raw IOC volume would drown the feed.
No attack map animation
There are no arcing missiles between countries here. Those visualisations are almost always decorative, and the underlying data rarely supports the geography they imply. Cyber events appear in the feed with their severity, their family or CVE identifier, and a link to the authoritative record.
Sources behind this page
All 13 data sources →Questions
Where does the cyber threat data come from?
CISA's Known Exploited Vulnerabilities catalogue, the NIST National Vulnerability Database for CVE records, and abuse.ch ThreatFox for active malware campaigns.
Does WorldPulse show a live cyber attack map?
No. Animated attack maps are decorative, and the data rarely supports the geography they show. Cyber events appear as feed items with their identifier and a link to the authoritative record.
Is the cyber data free to access?
Yes. CISA KEV and NIST NVD are public United States government resources, and ThreatFox is published under a CC0 licence.