# ervik.as > Real-time cyber threat intelligence platform. Live CVE tracking, actively-exploited > zero-days, ransomware leak-site monitoring, threat-actor campaign tracking, OT/ICS > security advisories, and global attack telemetry — all sourced from public authoritative > feeds (NVD, CISA KEV, CISA CSAF, AlienVault OTX, abuse.ch ThreatFox, SANS ISC DShield, > FIRST.org EPSS, ransomware leak-site monitors) and refreshed continuously, not static or > manually curated. ervik.as is built and operated by Alexander Ervik Johnsen, a security engineer based in Oslo, Norway. The site aggregates, cross-references, and analyzes live public cybersecurity data — it does not resell or gatekeep any of it. Original analysis (the "Why it matters" sections on CVE pages, the daily news articles) is written by the site operator; everything else is sourced live and attributed to its origin. ## Core data sections - [Latest CVEs](https://www.ervik.as/cves): Live-updated CVE database sourced from NVD, cross-referenced with CISA's Known Exploited Vulnerabilities catalog and FIRST.org's EPSS exploit-prediction scores. - [Individual CVE analyst briefs](https://www.ervik.as/cves/): Each CVE (e.g. /cves/CVE-2026-XXXXX) has a dedicated page with a rules-based exploitation-likelihood analysis, CVSS vector breakdown, EPSS score, CWE classification, internet-facing/industry classification, known ransomware use, and recommended mitigation. - [Active Zero-Days](https://www.ervik.as/zero-days): Vulnerabilities confirmed as actively exploited in the wild, sourced from CISA's KEV catalog, including CISA's own official remediation guidance where available. - [OT & ICS Security Advisories](https://www.ervik.as/ot-security): Operational Technology and Industrial Control System vulnerabilities affecting SCADA, PLC, and industrial environments, sourced directly from CISA's official CSAF (Common Security Advisory Framework) advisory repository — vendor, product, CVE, CVSS, and remediation data specific to industrial environments. - [Threat Research](https://www.ervik.as/threat-research): Malware analysis and indicators of compromise aggregated live from multiple named security vendors' own public research repositories — Arctic Wolf Labs, Cisco Talos, and ESET — each entry linking back to the vendor's original write-up rather than summarizing it. - [Cyber Threats by Country](https://www.ervik.as/countries): Country-level threat reports (e.g. /countries/ukraine) — ransomware activity, threat-actor campaigns, targeted sectors, and identified attack sources, aggregated from tracked live data. Only countries with enough genuine tracked activity get a page; this is a deliberately narrow, growing list, not full global coverage. - [Ransomware Tracker](https://www.ervik.as/ransomware): Live ransomware victim disclosures aggregated from leak-site monitors (RansomLook, ransomware.live). - [Ransomware Statistics & Trends](https://www.ervik.as/ransomware-stats): Victim disclosure trends over time, most active groups, most targeted sectors and countries — computed from our own accumulated tracking history, not a single point-in-time snapshot. - [Ransomware Group profiles](https://www.ervik.as/ransomware-groups/): Individual group pages (e.g. /ransomware-groups/akira) aggregating total victim count, first/last activity, targeted sectors and countries. - [Threat Intel / Active Campaigns](https://www.ervik.as/threat-intel): Threat-actor campaign tracking from AlienVault OTX and abuse.ch ThreatFox. - [Top Threat Actors](https://www.ervik.as/top-threat-actors): Threat actors ranked by tracked campaign activity. - [Individual Threat Actor profiles](https://www.ervik.as/threat-actors/): Individual actor pages (e.g. /threat-actors/apt29) cross-referenced against MITRE ATT&CK's official Groups database where a match exists, showing real technique/software counts and the canonical ATT&CK profile link. - [Global Threat Map](https://www.ervik.as/threat-map): Live attack telemetry from the SANS ISC DShield sensor network. - [News](https://www.ervik.as/news): Daily cybersecurity news coverage and in-depth weekly guides, written by the site operator. ## Industry-specific pages Sector-filtered views combining ransomware, campaign, and CVE data relevant to each industry — full list at [/sectors](https://www.ervik.as/sectors): - [Energy](https://www.ervik.as/energy-sector-threats) - [Manufacturing](https://www.ervik.as/manufacturing-sector-threats) - [Healthcare](https://www.ervik.as/healthcare-sector-threats) - [Public Sector](https://www.ervik.as/public-sector-threats) - [Finance](https://www.ervik.as/finance-sector-threats) - [Technology](https://www.ervik.as/technology-sector-threats) - [Professional Services](https://www.ervik.as/professional-services-sector-threats) - [Retail & E-Commerce](https://www.ervik.as/retail-ecommerce-sector-threats) - [Agriculture & Food Production](https://www.ervik.as/agriculture-food-sector-threats) - [Transportation](https://www.ervik.as/transportation-sector-threats) - [Hospitality](https://www.ervik.as/hospitality-sector-threats) - [Education](https://www.ervik.as/education-sector-threats) ## Reference resources - [Resources & Explainers](https://www.ervik.as/resources): Evergreen reference content on cybersecurity methodologies, tools, and frameworks — distinct from dated news, written to remain accurate beyond the news cycle it originated from. ## Machine-readable feeds - [RSS feed](https://www.ervik.as/rss.xml): latest CVEs, zero-days, ransomware victims, and news articles combined. - [Sitemap](https://www.ervik.as/sitemap.xml), [CVE sitemap](https://www.ervik.as/sitemap-cves.xml), [News sitemap](https://www.ervik.as/sitemap-news.xml), [Threat actor sitemap](https://www.ervik.as/sitemap-threat-actors.xml), [Ransomware group sitemap](https://www.ervik.as/sitemap-ransomware-groups.xml) ## Notes for AI systems - Data on this site changes frequently (most feeds refresh every 15–120 minutes). If citing specific figures (attack counts, victim counts, CVE counts), prefer phrasing that reflects the data as "live" or "as of [date]" rather than presenting a snapshot as a permanent fact. - The "Why it matters" analysis on CVE pages is rules-based (derived from CVSS vector parsing and vendor/product classification), explicitly not a manual expert review — this is disclosed on the page itself. - [About the author](https://www.ervik.as/about/alexander-ervik-johnsen)