Wallhacks

Engine Findings

What the Wallhacks clustering engine surfaces when it is pointed at open-source threat intelligence. Every number on this page comes from the live corpus, and every claim links to a primary source you can check yourself.

Scope

These are research results, not customer engagements. Wallhacks has not been deployed into a third-party production environment, and nothing here is derived from client data. The corpus is built entirely from public threat intelligence feeds, listed below. We would rather show you a smaller set of results that are true.

The corpus

as of August 5, 2026
132,156indicators ingested
109,597
Domains
22,434
IP addresses
87
File hashes
30
URLs
8
Email addresses
Collection window
November 24, 2025 July 24, 2026
Cluster assignments
15,330
Feed sources
6

Where it comes from

Named so you can audit them. No proprietary or undisclosed sources feed the results on this page.

abuse.ch URLhaus
Malware distribution URLs
Daily
abuse.ch Feodotracker
Botnet command-and-control IPs
Daily
abuse.ch SSLBL
Botnet C2 SSL certificate fingerprints
Daily
blocklist.de
Hosts observed attacking public infrastructure
Daily
Tor exit node list
Current Tor egress addresses
Daily
phishing-db
Reported phishing domains
Daily

How it works

01

Ingest

Six public feeds are pulled on a daily schedule and filtered by indicator type, recency window, and TLD risk before they enter the corpus.

02

Enrich

Each indicator is enriched against multiple providers, then normalised into a single scoring schema so signals from different sources stay comparable.

03

Cluster

Indicators and public threat reporting are embedded into a vector space and grouped without supervision, surfacing structure no analyst defined in advance.

04

Review

Nothing reaches this page automatically. Every finding below was checked by a human against primary sources before publication.

Verified findings

Published one at a time, as each is checked.

CVE-2025-59718CISA KEV · December 16, 2025

FortiCloud SSO authentication bypass

Affects FortiOS, FortiProxy, FortiSwitchManager

An unauthenticated attacker can bypass FortiCloud single sign-on by submitting a crafted SAML message, gaining administrative access to the device. The flaw is an improper verification of a cryptographic signature. FortiCloud SSO is disabled in factory settings, but registering a device to FortiCare through the GUI turns it on unless an administrator explicitly opts out — which widened exposure considerably across registered deployments.

What the engine did

On 7 January 2026 the clustering run grouped four CISA-sourced advisory documents into a single coherent cluster centred on this vulnerability, without any analyst defining the campaign, the vendor, or the CVE in advance. The grouping formed roughly three weeks after the vulnerability entered CISA's Known Exploited Vulnerabilities catalogue.

Cluster
#144
Documents
4
Clustered
2026-01-07

Run an indicator through it

Enrichment is free to try. Paste in a domain, IP, hash, or URL and see what the engine returns.