All Global Observations Footprint

Top 10 Identified Countries

Country Observations Percentage
US 307,701,189 45.92%
DE 67,245,958 10.04%
FR 26,108,649 3.90%
NL 24,174,818 3.61%
CN 23,453,781 3.50%
JP 19,515,712 2.91%
CA 19,391,670 2.89%
GB 16,902,668 2.52%
RU 15,134,174 2.26%
IT 9,107,210 1.36%

All Industry Observations Footprint

Top 10 Identified Industries

*Service provider organizations (typically Technology and Telecommunications) are disproportionally represented in the results given their upstream ownership of end-user infrastructure. See our FAQs.

Industry* Observations Percentage
Technology 684,910,018 89.69%
Telecommunications 41,832,506 5.48%
Finance 13,395,995 1.75%
Business Services 4,567,038 0.60%
Education 3,460,592 0.45%
Consumer Goods 2,360,275 0.31%
Government/Politics 1,922,989 0.25%
Food Production 1,894,700 0.25%
Utilities 1,894,029 0.25%
Manufacturing 1,615,125 0.21%
Pulse logo
  • Access to USA IT/Software company's internal network for sale
  • Sale of 600K order data from US stores on underground forum
  • Cigam.Com.Br Attacked By Coinbasecartel Ransomware Group
  • React Server Components face DoS and source code exposure vulnerabilities
  • React2Shell vulnerability exploited to deploy Linux backdoors

Browse Software by Vendors or their Products

Click a Vendor or Product name below. 

704 Vendors Found
Vendor Observations Sort ascending
Zoho Corp 49,388
Redis Ltd. 49,287
Xenforo 48,751
Xiph.Org Foundation 48,156
Ewww 48,073
MinIO 47,204
Redux 45,687
Djangoproject 44,826
Digium 44,600
Pulse Secure 43,881
Broadcom 43,723
N8n 43,714
Tridium 43,309
IceWarp 43,264
SolarWinds 42,516
Sophos 41,769
Juniper Networks 40,157
Gitea 39,363
Sensiolabs 38,816
Twisted Matrix 38,061
12656 Products Found
Product Vendor Observations Sort ascending
Hen08103 Firmware Dahua Technology 70
Ip4m 1026w Firmware Dahua Technology 70
Ipc Hfw1320s Firmware Dahua Technology 70
Ipc K46 Firmware Dahua Technology 70
Ku70ua8070fxkr Samsung 70
Nvr2108 4ks2 Firmware Dahua Technology 70
Qe55ls03rauxxc Samsung 70
Rvnvr324k10a Firmware Dahua Technology 70
Sf300 08 Cisco 70
Sf300 08 Firmware Cisco 70
Srx380 Poe Ac Juniper Networks 70
Standvr 16w01 3t Firmware Dahua Technology 70
Ue43tu6905kxxc Samsung 70
Un50ju6400 Samsung 70
Windows Server 2022 Microsoft 70
Bac 5051e Kmc Controls 70
Bac 5051e Firmware Kmc Controls 70
Gs748t Firmware NETGEAR 69
Prosafe Gs748t NETGEAR 69
Sf302 08pp Cisco 69

The leading provider of Cyber Risk Intelligence solutions, Bitsight introduced the next-generation internet scanning Bitsight Groma in May 2024. This technology continuously scans the entire internet to discover assets, collect asset attribution evidence, and identify an ever-growing set of security observations, such as vulnerabilities and misconfigurations.  Groma’s scanning activities presently encompass:


  • 40 million-plus monitored organizations
  • 250 million-plus host names
  • 4 billion-plus routable IPv4 and IPv6 addresses

Greynoise’s recent study testifies the speed of Bitsight Groma.

Bitsight data discovery
Governance charcoal background

Bitsight TRACE team investigates security incidents and identifies vulnerabilities and threats.

View latest security research 

See what you’re up against across the expanding attack surface. Prioritize what matters most. And mitigate where you’re most vulnerable.

External Attack Surface Management

Software Vulnerabilities

The Dynamic Vulnerability Exploit (DVE) score, powered by Bitsight AI, reflects the probability of a vulnerability being exploited by malicious actors over the course of 90 days.

This is a stack-based buffer overflow in Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways, which allows unauthenticated attackers to achieve remote code execution. PoCs are available for CVE-2025-0282, which has been actively exploited in the wild. Bitsight also detected at least one threat actor attempting to sell a PoC for CVE-2025-0282.

This vulnerability allows authentication bypass using an alternate path or channel, which a remote attacker could leverage to gain super-admin privileges via crafted requests to the Node.js websocket module. It affects FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12.

This is a privilege escalation vulnerability in Palo Alto Networks PAN-OS software that has been actively exploited in the wild.

Bitsight ASA Report Image

Reducing exposure starts with knowing exactly how your external attack surface stands—from your overall standing to each digital and cloud asset around the world. Bitsight's custom report gives you the insights you need to see your entire external attack surface.