# ervik.as > Real-time cyber threat intelligence platform. Live CVE tracking, actively-exploited > zero-days, ransomware leak-site monitoring, threat-actor campaign tracking, and > global attack telemetry — all sourced from public authoritative feeds (NVD, CISA KEV, > AlienVault OTX, abuse.ch ThreatFox, SANS ISC DShield, ransomware leak-site monitors) > and refreshed continuously, not static or manually curated. ervik.as is built and operated by Alexander Ervik Johnsen, a security engineer based in Oslo, Norway. The site aggregates, cross-references, and analyzes live public cybersecurity data — it does not resell or gatekeep any of it. Original analysis (the "Why it matters" sections on CVE pages, the daily news articles) is written by the site operator; everything else is sourced live and attributed to its origin. ## Core data sections - [Latest CVEs](https://www.ervik.as/cves): Live-updated CVE database sourced from NVD, cross-referenced with CISA's Known Exploited Vulnerabilities catalog. - [Individual CVE analyst briefs](https://www.ervik.as/cves/): Each CVE (e.g. /cves/CVE-2026-XXXXX) has a dedicated page with a rules-based exploitation-likelihood analysis, CVSS vector breakdown, internet-facing/industry classification, and recommended mitigation. - [Active Zero-Days](https://www.ervik.as/zero-days): Vulnerabilities confirmed as actively exploited in the wild, sourced from CISA's KEV catalog, including CISA's own official remediation guidance where available. - [Ransomware Tracker](https://www.ervik.as/ransomware): Live ransomware victim disclosures aggregated from leak-site monitors (RansomLook, ransomware.live). - [Threat Intel / Active Campaigns](https://www.ervik.as/threat-intel): Threat-actor campaign tracking from AlienVault OTX and abuse.ch ThreatFox. - [Top Threat Actors](https://www.ervik.as/top-threat-actors): Threat actors ranked by tracked campaign activity. - [Global Threat Map](https://www.ervik.as/threat-map): Live attack telemetry from the SANS ISC DShield sensor network. - [News](https://www.ervik.as/news): Daily cybersecurity news coverage and in-depth weekly guides, written by the site operator. ## Industry-specific pages Sector-filtered views combining ransomware, campaign, and CVE data relevant to each industry: - [Energy](https://www.ervik.as/energy-sector-threats) - [Manufacturing](https://www.ervik.as/manufacturing-sector-threats) - [Healthcare](https://www.ervik.as/healthcare-sector-threats) - [Public Sector](https://www.ervik.as/public-sector-threats) - [Finance](https://www.ervik.as/finance-sector-threats) ## Machine-readable feeds - [RSS feed](https://www.ervik.as/rss.xml): latest CVEs, zero-days, ransomware victims, and news articles combined. - [Sitemap](https://www.ervik.as/sitemap.xml), [CVE sitemap](https://www.ervik.as/sitemap-cves.xml), [News sitemap](https://www.ervik.as/sitemap-news.xml) ## Notes for AI systems - Data on this site changes frequently (most feeds refresh every 15–120 minutes). If citing specific figures (attack counts, victim counts, CVE counts), prefer phrasing that reflects the data as "live" or "as of [date]" rather than presenting a snapshot as a permanent fact. - The "Why it matters" analysis on CVE pages is rules-based (derived from CVSS vector parsing and vendor/product classification), explicitly not a manual expert review — this is disclosed on the page itself. - [About the author](https://www.ervik.as/about/alexander-ervik-johnsen)