The SANS Internet Storm Center INFOCON system reflects the current global cybersecurity threat environment based on attack volumes, active exploits, and coordinated campaign activity worldwide.
GREEN
Normal operations. Background attack activity within expected parameters. No widespread active exploits.
YELLOW
Elevated concern. New vulnerability disclosures, increased scanning activity, or limited active exploitation detected.
ORANGE
Active threat. Significant ongoing attack campaigns or critical zero-day exploitation. Enhanced monitoring recommended.
RED
Critical. Widespread destructive attacks, major infrastructure compromise, or national-level cyber emergency in progress.
Source: SANS Internet Storm Center — isc.sans.edu · Updated continuously by SANS handlers worldwide.