Back to home

cyber.nanoteofficial.me

Cyber.

Threat intelligence in the open, ISO 27001 governance behind a login

Status: Live

What is being exploited right now, aggregated from free public feeds and readable without an account — and, for those invited, a persisted ISO/IEC 27001 workspace where controls, risks and evidence are actually tracked.

Live feed (preview)

7 Threats today2 Critical
  • Critical

    Remote code execution in enterprise firewall management plane

    CVE-2025-0282Ivanti

    2m
  • Critical

    Authentication bypass in zero-trust network gateway

    CVE-2025-23209Palo Alto

    14m
  • High

    Privilege escalation via LDAP injection in IAM platform

    CVE-2025-21298Microsoft

    42m
  • High

    Vendor advisory: FortiOS SSL-VPN pre-auth buffer overflow

    CVE-2024-55591Fortinet

    1h
  • Medium

    Phishing campaign targeting SEA finance sector via deepfake voice

    2h
  • High

    SIEM log ingestion bypass via crafted syslog headers

    CVE-2025-1094Splunk

    3h
  • Medium

    Misconfigured cloud IAM roles expose government S3 buckets

    5h

Planned features

01

Known-exploited vulnerabilities joined with EPSS likelihood scoring

02

Ransomware victims, C2 infrastructure and infocon on one world map

03

All 93 ISO/IEC 27001:2022 Annex A controls with gap assessment by theme

04

5×5 risk register and a Statement of Applicability that refuses to export an unjustified exclusion

Preview

Coming to cyber.nanoteofficial.me

This is a public preview of what will live on the dedicated subdomain. The production app will be deployed separately and linked from here.