Essential Guide: Mitigating MikroTik Threats on Your Network

In case you missed it, we have +2.6 million exposed MikroTik instances. Top: Brazil, Indonesia, USA. Time to check your networks. I’ve had several peers ask to dust off the MikroTik security guide from 2023. Here is an update:Essential Guide: Mitigating MikroTik Threats on Your Networkhttps://www.senki.org/essential-guide-mitigating-mikrotik-threats-on-your-network/Shadowserver now has a new dedicated report for MikroTik. These started reporting out (daily) MikroTik instances with exposed… Read More

CEO’s Wake Up! Operation Ramz, Shadowserver, and the Case for Funding Public-Benefit Cyber Defense

“Cybercrime is a borderless, multi-billion-dollar enterprise. We cannot defend against it solely by building taller walls around individual networks. Operation Ramz proves that actionable intelligence, combined with trusted public-private partnerships, results in actual arrests and dismantled infrastructure.” The organizations most concerned about cybercrime must fund the non-profit engine that actually disrupts it. Call to Action: Visit shadowserver.org/partner/ to invest in action. Read More

Origin of Protective DNS and RPZ

The Architectural Evolution of Protective DNS: From Academic Prototyping to Global Security Standard The historical trajectory of the Domain Name System (DNS) has transitioned from a rudimentary directory service into the fundamental control plane of modern internet security. This transformation was neither accidental nor purely market-driven; it was the result of a protracted conflict between Read More

Meaningful Security Conversations with Your Vendors: The 2026 Q1 Guide to Digital Safety & Resilience

Executive Summary: The Imperative for a New Dialogue In the contemporary operational environment, defined by industrialized cyber warfare and systemic supply chain compromises—exemplified by the Salt Typhoon and Volt Typhoon campaigns—the evaluation of network vendors has shifted from a procurement checklist to a strategic imperative. Organizations can no longer rely solely on perimeter defenses; they Read More

FAQ – Which Shadowserver Reports list CVEs

FAQ – Which Shadowserver Reports list CVEs? Many people frequently ask how Shadowserver includes CVEs (Common Vulnerabilities and Exposures) in its reports. Currently, there are over 140 reports published, with more on the way. The Shadowserver Alliance is active, working together to support the Shadowserver initiative and develop new report types. It’s a logical question to ask. The wonders of today make it soooo easy to find answers. You don’t need to ask gurus to kick-start your journey…. Read More

FAQ – Which Shadowserver Reports list CVEs

FAQ – Which Shadowserver Reports list CVEs? Many people frequently ask how Shadowserver includes CVEs (Common Vulnerabilities and Exposures) in its reports. Currently, there are over 140 reports published, with more on the way. The Shadowserver Alliance is active, working together to support the Shadowserver initiative and develop new report types. It’s a logical question Read More

US ISP CPE SUPPLY CHAIN

Who Makes What, and Where with the US ISP CPE Supply Chain Version 2.0 | March 24, 2026 senki.org | bgreene@senki.org This research tool was curated from detailed questions by a +40-year Internet engineer, large network architect, and cybersecurity specialist. The questions were used to build out logic flows in multiple LLMs to gather insights Read More