Attack Surface Overview
Last scan: 12 Jun 2026, 09:42 ICT · Next scheduled: 13 Jun 2026, 09:00 ICT
Jun 6 – Jun 12, 2026
Composite Risk Score
Updated 4 hours ago
62
/ 100
ELEVATED
People
1,247
Assets
3,842
Services
684
Discovered Hosts
526
Attack Surface Summary
6 categories
Vulnerabilities
147
Issue Categories
7 types
Uptime Monitoring
Giám sát thời gian hoạt động
14
Brand Protection
Bảo vệ thương hiệu
8
Vulnerability Mgmt
Quản lý lỗ hổng
47
Product Weakness
Điểm yếu sản phẩm
19
Data Breach Monitor
Giám sát rò rỉ dữ liệu
5
Botnet Detection
Phát hiện botnet
3
Threat Investigation
Điều tra mối đe dọa
11
Open Issues
23 open
CVE-2026-4821 — RCE via unauthenticated API endpoint
VULN-2847
Open
Exposed S3 bucket with PII data
EXPOS-192
In Progress
SSL certificate expires in 7 days — 3 domains affected
CERT-048
Acknowledged
DNS record leak — internal service exposed to public
DNS-033
Open
Outdated dependencies — 4 critical CVEs in npm packages
DEP-127
In Progress
Recent Detections
View all →
Brute force attempt on admin portal
47 failed login attempts from 12 IPs in 8 min — admin.gskywatch.io
09:38
SQL injection probe detected
Automated scanner targeting /api/v2/search endpoint — blocked by WAF
09:12
Unusual data transfer spike
Outbound traffic to unknown IP — 2.3 GB in 15 min from worker-04
08:47
New subdomain discovered
staging-api.gskywatch.io — DNS record created, not in asset inventory
08:20
Certificate renewed successfully
api.gskywatch.io — Let's Encrypt auto-renewal completed
07:55
Asset Inventory
All discovered assets across your attack surface
Jun 6 – Jun 12, 2026
Hosts
1,247
Services
684
Discovered Hosts
526
Asset Groups
18
emm.trin.net
testwebservices.hawaiianairlines.com
49.88.112.75
172.16.0.88
Rows per page:
Page 1 of 1
shadow-api.corp.net
legacy-app.internal
vpn-gateway-02.corp.net
Rows per page:
Page 1 of 1
HTTPS Web Server 443
REST API Gateway 8443
SSH Management 22
SMTP Relay 25
PostgreSQL Database 5432
Rows per page:
Page 1 of 1
Production Web
API Services
Internal Tools
Customer Facing
Rows per page:
Page 1 of 1
Sky Assistant
Online — Last sync 2 min ago
Critical Reports
12
High Severity
34
Total Reports
89
Resolved
67
VULNERABILITY
Critical CVE Batch — Q2 2026
12 critical vulnerabilities discovered across 3 assets. Includes Remote Code Execution on Apache Struts and SQL Injection on authentication endpoints. Immediate remediation required.
EXPOSURE
Subdomain Takeover Risk
3 subdomains with dangling DNS records detected. These can be taken over by malicious actors to serve phishing pages or steal cookies.
UPTIME
Service Downtime Alert — API Gateway
API Gateway experienced 14 minutes of downtime at 03:42 UTC. Root cause: upstream DNS resolution failure. Service restored automatically.
BRAND
Phishing Domain Detected — g-skywatch.com
A lookalike domain g-skywatch.com was registered 3 days ago. SSL certificate issued by Let's Encrypt. Currently serving a credential-harvesting page mimicking the login portal.
BOTNET
C2 Communication Detected — 3 Hosts
3 internal hosts communicating with known Cobalt Strike C2 server (185.220.101.42). Traffic pattern indicates possible lateral movement. Immediate isolation recommended.
REMEDIATION
Weekly Remediation Summary — W25
67 of 89 open issues resolved this week. Average remediation time improved from 4.2 days to 2.8 days. 3 critical CVEs patched within SLA. 12 findings still pending owner assignment.