Wallhacks

Engine Findings

What the Wallhacks clustering engine surfaces when it is pointed at open-source threat intelligence. Every number on this page comes from the live corpus, and every claim links to a primary source you can check yourself.

Scope

These are research results, not customer engagements. Wallhacks has not been deployed into a third-party production environment, and nothing here is derived from client data. The corpus is built entirely from public threat intelligence feeds, listed below. We would rather show you a smaller set of results that are true.

The corpus

as of August 5, 2026
132,167indicators ingested
109,607
Domains
22,435
IP addresses
87
File hashes
30
URLs
8
Email addresses
Collection window
November 24, 2025 August 5, 2026
Cluster assignments
15,330
Active feeds
5

Where it comes from

Named so you can audit them. No proprietary or undisclosed sources feed the results on this page.

phishing-db
Reported phishing domains
391,606
blocklist.de
Hosts observed attacking public infrastructure
374,251
Tor exit nodes
Current Tor egress addresses
22,050
abuse.ch URLhaus
Malware distribution URLs
15,537
abuse.ch Feodotracker
Botnet command-and-control IPs
7
abuse.ch SSLBL
Botnet C2 SSL certificates — retired upstream
retired

How it works

01

Ingest

Public feeds are pulled on a daily schedule and filtered by indicator type, recency window, and TLD risk before anything enters the corpus.

02

Enrich

Each indicator is enriched against multiple providers, then normalised into a single scoring schema so signals from different sources stay comparable.

03

Cluster

Indicators and public threat reporting are embedded into a vector space and grouped without supervision, surfacing structure no analyst defined in advance.

04

Review

Nothing publishes automatically. Every finding is checked by a human against primary sources first.

Verified findings

Published one at a time, as each is checked.

CVE-2025-59718CISA KEV · December 16, 2025

FortiCloud SSO authentication bypass

Affects FortiOS, FortiProxy, FortiSwitchManager

An unauthenticated attacker can bypass FortiCloud single sign-on by submitting a crafted SAML message, gaining administrative access to the device. The underlying flaw is improper verification of a cryptographic signature. FortiCloud SSO is off in factory settings, but registering a device to FortiCare through the GUI enables it unless an administrator explicitly opts out — which widened exposure considerably across registered deployments.

What the engine did

On 7 January 2026 the clustering run grouped four CISA-sourced advisory documents into a single coherent cluster centred on this vulnerability, with no analyst defining the campaign, the vendor, or the CVE in advance. The grouping formed roughly three weeks after the vulnerability entered CISA's Known Exploited Vulnerabilities catalogue.

Cluster
#144
Documents
4
Clustered
2026-01-07

Run an indicator through it

Enrichment is free to try. Paste in a domain, IP, hash, or URL and see what the engine returns.