Afterglowscreensavers

Security & Privacy Screensavers

Screensavers built on the feeds security people actually read: vulnerability catalogues as the vendors publish them, attack telemetry from volunteered firewall logs, the transparency logs that keep certificate authorities honest, and measurements of censorship and outages around the world. Every one runs on live data and goes fullscreen with a click.

Cyber Threat MapLive botnet command servers, worldwide. Open → Tor NetworkThe Tor network, mapped live. Open → Domain PulseReal domains from live CT logs, pipeline-fed. Open → Exchange Hack LedgerA real historical ledger of crypto's biggest losses. Open → CVE Security FeedLive feed of new security vulnerabilities. Open → Data Breach LedgerA real scrolling ledger of major publicly reported data breaches. Open → GitHub Security AdvisoriesReal new security advisories, live. Open → BGP Route MonitorThe internet rewiring itself, live. Open → Phishing URL FeedFreshly reported phishing hosts, defanged. Open → Ransomware Victim FeedWhat the leak sites are claiming. Open → Distro Security AdvisoriesDebian and Ubuntu advisories, live. Open → Exploit Prediction ScoresWhich flaws will actually be attacked. Open → End-of-Life CountdownSoftware running out of support. Open → What Is Being ScannedSources against targets tells you which. Open → Exploited Right NowThe short list with a deadline. Open → Vendor-Rated CVEsSeverity as the vendor sees it. Open → Waiting On A PatchReported, unfixed, unnamed. Open → Kubernetes CVEsCurated by hand, not by scanner. Open → Exposed SinceHow long each bug lived. Open → Kernel CVEsA map of the tree, by subsystem. Open → CERT/CC NotesWhen one vendor cannot fix it alone. Open → The List, ChangingMostly edits, not new records. Open → What You InstalledOne format, every ecosystem. Open → A Year Of CVEsVolume by severity, month by month. Open → Exploit ArchiveWeb apps outnumber everything. Open → Push-Button ExploitsRank is reliability, not severity. Open → How Attacks WorkFeatures, working as designed. Open → The Shape Of The BugThe mistake behind the CVE. Open → Who Can Name A FlawAuthority, and its limits. Open → Loudest On The WireA flood, or a sweep. Open → Background NoiseSources move less than packets. Open → What The Lists HoldSize is shape, not severity. Open → Where The Ransom WentA floor, never a total. Open → Every Certificate, LoggedMis-issuance can no longer be quiet. Open → Does DNSSEC WorkOne deliberately broken domain. Open → Who Registered ThisLocks are the anti-hijack defence. Open → What The Scanners SeeA small surface, done well. Open → Header Report CardA narrow slice, honestly measured. Open → Supply Chain Report CardMeasures process, not code. Open → Told The RegulatorMaterial enough to disclose. Open → Advisories For MachineryKit that cannot be patched on a cycle. Open → Full DisclosurePublished, ready or not. Open → Coordinated DisclosureMaintainers, not attackers. Open → Blocked From HereA signal, not a verdict. Open → The Internet Going DarkThree signals, one conclusion. Open → Europe's Own Vulnerability RegisterHow bad, and how likely, disagree. Open → Who Owns The ExitA VPN's promise ends at the machine. Open →

Security data has a habit of being presented as a scoreboard. It rarely is one. A vulnerability count says as much about who is looking as about what is broken; a blocklist’s size depends on whether it counts addresses or whole network blocks; an OpenSSF score measures whether a project’s process is legible to automation, not whether its code is safe. These screensavers try to show the data without that flattening — each one states what its numbers do and do not mean.

The vulnerability boards read from the sources that create the records rather than from anyone’s summary: Red Hat rating flaws against its own builds, the Linux kernel assigning its own CVEs, curl publishing the exact release each of its bugs entered and left, the CVE Program’s own log of what it edited this hour. The telemetry boards come from the SANS Internet Storm Center, which aggregates firewall logs that thousands of operators volunteer.

Several run entirely in your browser with no server in between — the DNSSEC board resolves real domains over DNS-over-HTTPS as you watch, including one that is deliberately broken and must fail. Nothing is scanned or probed from your machine: where a screensaver shows what is exposed on a public address, it is reading a record someone else already published.

Frequently asked questions

Is any of this data live?
Yes. Roughly half fetch directly from the source in your browser — NVD, the SANS Internet Storm Center, OSV, Shodan’s InternetDB, Google’s DNS resolver. The rest are refreshed by a scheduled pipeline because the source is large, rate-limited or sends no CORS headers.
Do these screensavers scan anything?
No. Nothing probes, scans or connects to a third party on your behalf beyond reading a public API. Where a board shows open ports on an address, it is reading Shodan’s existing record of infrastructure whose operators publish those ports deliberately.
Why do some boards show fewer results than expected?
Because the source genuinely has fewer. CERT/CC writes a note only when a flaw needs multi-vendor coordination, and fewer than fifty US companies a year file an 8-K calling a cyber incident material. Where a feed is thin, that thinness is the finding.
Can I use these as a security dashboard?
They are screensavers, not monitoring. Nothing alerts, and refresh intervals run from minutes to hours. For ambient awareness on a wall screen they work well; for anything you need to act on, read the sources directly.