Security & Privacy Screensavers
Screensavers built on the feeds security people actually read: vulnerability catalogues as the vendors publish them, attack telemetry from volunteered firewall logs, the transparency logs that keep certificate authorities honest, and measurements of censorship and outages around the world. Every one runs on live data and goes fullscreen with a click.
Security data has a habit of being presented as a scoreboard. It rarely is one. A vulnerability count says as much about who is looking as about what is broken; a blocklist’s size depends on whether it counts addresses or whole network blocks; an OpenSSF score measures whether a project’s process is legible to automation, not whether its code is safe. These screensavers try to show the data without that flattening — each one states what its numbers do and do not mean.
The vulnerability boards read from the sources that create the records rather than from anyone’s summary: Red Hat rating flaws against its own builds, the Linux kernel assigning its own CVEs, curl publishing the exact release each of its bugs entered and left, the CVE Program’s own log of what it edited this hour. The telemetry boards come from the SANS Internet Storm Center, which aggregates firewall logs that thousands of operators volunteer.
Several run entirely in your browser with no server in between — the DNSSEC board resolves real domains over DNS-over-HTTPS as you watch, including one that is deliberately broken and must fail. Nothing is scanned or probed from your machine: where a screensaver shows what is exposed on a public address, it is reading a record someone else already published.
Frequently asked questions
- Is any of this data live?
- Yes. Roughly half fetch directly from the source in your browser — NVD, the SANS Internet Storm Center, OSV, Shodan’s InternetDB, Google’s DNS resolver. The rest are refreshed by a scheduled pipeline because the source is large, rate-limited or sends no CORS headers.
- Do these screensavers scan anything?
- No. Nothing probes, scans or connects to a third party on your behalf beyond reading a public API. Where a board shows open ports on an address, it is reading Shodan’s existing record of infrastructure whose operators publish those ports deliberately.
- Why do some boards show fewer results than expected?
- Because the source genuinely has fewer. CERT/CC writes a note only when a flaw needs multi-vendor coordination, and fewer than fifty US companies a year file an 8-K calling a cyber incident material. Where a feed is thin, that thinness is the finding.
- Can I use these as a security dashboard?
- They are screensavers, not monitoring. Nothing alerts, and refresh intervals run from minutes to hours. For ambient awareness on a wall screen they work well; for anything you need to act on, read the sources directly.














































