Breaches
Every breach published by Have I Been Pwned. The method is read from HIBP's own write-up.
How company data got out
Company breaches only. Most write-ups say a breach happened without the method.
Data types exposed most often
Accounts exposed by year of breach
Largest company breaches
| Company | Breached | Accounts | Method |
|---|
Select a row for the write-up. Source: Have I Been Pwned, CC BY 4.0.
Attacks
Malware and botnet servers, criminal networks and ransomware leak-site activity, from researchers' public feeds.
Malware families
Hosting countries
Networks hosting the most malware servers
| Network | Type | Servers |
|---|
Ransomware, last 7 days
Networks run by criminals
Exploited flaws
CISA's catalogue of flaws exploited in real attacks, with FIRST EPSS exploitation probabilities.
Patch these first
Select the vendors you run. Ranked by EPSS percentile, ransomware use, vendor reach and recency.
| Score | Flaw | Product | Why |
|---|
Vendors, last 12 months
Flaws added per month
Latest additions
| Added | Flaw | Product | Ransomware | EPSS 30 d |
|---|
Sources: CISA Known Exploited Vulnerabilities catalog (US government public data); FIRST EPSS, scored daily.
Sign-in check
Two weeks of the account's usual sign-ins go to the model first, then the test sign-in. IP addresses are real, from each country's networks.
Verdict
Select a scenario or run a check.
News
Security headlines and videos from public feeds, cached for 30 minutes. Each item links to its source.
Headlines
Videos
Sources and accuracy
Threat data is downloaded on a schedule; the login models were trained once on 2020 to 2021 data. Both are stated plainly below.
Model results in plain words
Feed freshness
| Source | Licence | Last downloaded | Refresh |
|---|
Login models
| Model | Data | Trained on | Tested on |
|---|