See it.Nix it.
The world's cyber threats, read straight off the wire. Exploited CVEs, adversary dossiers and a free JSON API, around the clock.
last dispatch · as of UTC
- GHSA-mxm6-v9r6-r94c: @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at
- GHSA-33f5-2c5q-wgwj: RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
- Cisco Advance Notification for Publication of September 16, 2026, Security AdvisoriesKEV
- Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
- Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)
- US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
- Vulnerabilities in WNC T-Mobile 5G Box IDU routers
The world's threat reporting, read for you, filed where you can find it.
The wire
Every report that matters, filed within hours of the source, read in one line. Actively-exploited CVEs get flagged, not buried.
The archive
Every dispatch ever published, newest first, each one grounded to the outlet that broke it — and to the others that carried it.
The feed
The same wire as JSON and RSS, live today, no key — point a reader, a SIEM or an agent at it. A developer API and an MCP server are being built; early access gets them first.
curl https://skopnix.com/feed.json
{ "version": "https://jsonfeed.org/version/1.1",
"items": [ { "title": "…", "_skopnix": { "kev": true } } ] }measured worldwide 2026-09-14 · vs 2026-09-07
- SonicWall SSL-VPN▲ 6,131 (1.4%)428,994
Akira's routine way in. Repeatedly on CISA KEV.
- FortiGate SSL-VPN▲ 8,667 (2.6%)344,029
FortiOS SSL-VPN. Persistent KEV entries, ransomware entry point.
- RDP, exposed to the internet▲ 967 (0.3%)328,207
A desktop answering the open internet. Still the oldest way in.
- Palo Alto GlobalProtect▲ 3,298 (1.5%)220,857
Edge VPN portal. A 2024 KEV zero-day is still being found unpatched.
- MikroTik RouterOS▲ 3,253 (1.6%)201,047
Router fleets, widely conscripted into proxy and DDoS infrastructure.
- Microsoft Exchange▲ 2,384 (2.1%)117,996
On-premise mail. Years of KEV entries and no shortage of targets.
- Outlook Web (OWA)▲ 494 (0.8%)65,102
The login page in front of that mail.
- Zimbra Mail▼ 205 (0.4%)46,914
Repeatedly exploited in the wild against government mail.
- VMware ESXi▲ 44 (1.1%)3,871
Hypervisors. One host, every VM on it.
A scan count, not an inventory. This is how many hosts answered a probe from the public internet on the date shown — not how many are unpatched, not how many are vulnerable, and not how many are real (some are honeypots). It is a floor on the attack surface, and it is the number that moves when a vendor ships a patch nobody applies.
Everything on the wire is grounded to its source. Nothing is invented.
Counts over the same published-story gate the pipeline uses before a dispatch reaches Telegram. Refreshed hourly.
- dispatches · 7d
- 146
- KEV · actively exploited
- 13
- with CVE ids
- 81
- sources reporting
- 29
Want the keys?
Early access opens three things first: the actor API and MCP server, alerts when an adversary you follow lands on the wire, and STIX export. One email when it's ready. Nothing else, ever.