SENTINEL // OPEN INTEL
◤ Cyber and spectrum

Cyber, spectrum, and routing

The cyber surface aggregates four public-source signal streams that reshape the operating picture in real time but do not fit cleanly under conflict or weather: BGP route leaks and origin hijacks from Cloudflare Radar, OONI per-country censorship measurement, MISP threat-actor presence by country, and the GPS jamming and spoofing layer rendered live on the globe.

OONI censorship leaderboard

Top countries by 30-day anomaly rate

The Open Observatory of Network Interference is a global volunteer measurement network that tests for blocked websites, throttled services, deep-packet-inspection events, and middlebox interference. The list below ranks countries by their 30-day anomaly rate (the share of probes that returned an anomalous response). Click into any country for the full per-app and per-category breakdown.

BGP route leaks and hijacks

Snapshot 3d ago

BGP leaks happen when an autonomous system announces routes it should not have advertised; hijacks are claims of address space owned by another network. Both result in traffic redirection on the underlying internet. SENTINEL surfaces leaks and hijacks tracked by Cloudflare Radar.

20
Recent leaks
20
Recent hijacks
5
Top originating ASNs
94
Update samples (24h)
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
leak·
Leak by AS? ·
hijack·3d ago·201.54.189.0/24
Hijack by AS270304 · 201.54.189.0/24
AS270304 (FIBRAVELOZ PROVEDOR DE INTERNET LTDA) [BR]
hijack·3d ago·85.28.35.0/24
Hijack by AS9009 · 85.28.35.0/24
AS9009 (M247 Europe SRL) [RO]
hijack·3d ago·41.220.8.0/24
Hijack by AS36901 · 41.220.8.0/24
AS36901 (DATANET.COM LLC) [UG]
hijack·3d ago·103.213.105.0/24
Hijack by AS138322 · 103.213.105.0/24
AS138322 (Afghan Wireless Communication Company) [AF]
hijack·3d ago·2804:3ab4::/32
Hijack by AS263258 · 2804:3ab4::/32
AS263258 (INTERLIG TELECOM) [BR]
hijack·3d ago·103.11.68.0/22
Hijack by AS60117 · 103.11.68.0/22
AS60117 (Host Sailor Ltd) [AE]
hijack·3d ago·103.103.137.0/24
Hijack by AS23679 · 103.103.137.0/24
AS23679 (PT. Media Antar Nusa) [ID]
hijack·3d ago·119.148.21.0/24
Hijack by AS63939 · 119.148.21.0/24
AS63939 (Agni Systems Limited) [BD]
hijack·3d ago·185.225.68.0/22
Hijack by AS41075 · 185.225.68.0/22
AS41075 (ATW Internet Kft.) [HU]
hijack·3d ago·212.154.128.0/19
Hijack by AS9198 · 212.154.128.0/19
AS9198 (JSC Kazakhtelecom) [KZ]
hijack·3d ago·199.166.36.0/23
Hijack by AS36351 · 199.166.36.0/23
AS36351 (IBM Cloud) [US]
hijack·3d ago·189.74.113.0/24
Hijack by AS9123 · 189.74.113.0/24
AS9123 (TimeWeb Ltd.) [RU]
hijack·3d ago·185.93.69.0/24
Hijack by AS51559 · 185.93.69.0/24
AS51559 (Netinternet Bilisim Teknolojileri AS) [TR]
hijack·3d ago·103.169.158.0/24
Hijack by AS38026 · 103.169.158.0/24
AS38026 (MetroNet Bangladesh Limited) [BD]
hijack·3d ago·103.124.226.0/24
Hijack by AS137491 · 103.124.226.0/24
AS137491 (Peerex Networks Ltd.) [BD]
hijack·3d ago·91.235.84.0/22
Hijack by AS197335 · 91.235.84.0/22
AS197335 (Artem Zubkov) [GE]
hijack·3d ago·83.147.223.0/24
Hijack by AS49434 · 83.147.223.0/24
AS49434 (FBW NETWORKS SAS) [FR]
hijack·3d ago·45.196.90.0/24
Hijack by AS149175 · 45.196.90.0/24
AS149175 (UNION FU WAH DIGITAL TECHNOLOGY LIMITED) [HK]
hijack·3d ago·45.66.151.0/24
Hijack by AS43043 · 45.66.151.0/24
AS43043 (aurologic GmbH) [DE]
hijack·3d ago·2401:8680:4102::/48
Hijack by AS45102 · 2401:8680:4102::/48
AS45102 (Hangzhou Alibaba Advertising Co.,Ltd.) [CN]
10 of 40

Threat actors by country

474 groups across 35 countries

The MISP galaxy taxonomy catalogues named threat actors (APT groups, financially motivated criminal groups, hacktivist collectives) by attributed sponsor country. Click into any country to see its full per-actor table on the dossier page.

Sample groups attributed to China
  • 1937CN
  • Amaranth-Dragon
  • Antlion
  • Aoqin Dragon
  • APT.3102
  • APT1
  • APT10
  • APT12
  • APT14
  • APT15
  • APT16
  • APT17
  • APT18
  • APT19

GPS jamming and spoofing

GPS jamming is rendered live as a hex-bin heatmap on the globe; spoofing surfaces as discrete events on the patterns rail. Both feeds are too high-resolution to enumerate here usefully, but the categorical state across the major flashpoints is steady: persistent interference around Russia, Iran, the Eastern Mediterranean, and Israel, with intermittent step-changes around active strike windows.

The spoof classifier looks for the spurious-position signature where multiple aircraft simultaneously report a fix at the same impossible coordinate. Receiver-handoff false positives in mid-Atlantic and mid-Pacific coverage gaps are filtered.

See it live

The cyber tab on the live globe carries the four data feeds above with full per-country drill-down, BGP timeseries graphs, OONI 30-day anomaly trends, and a threat-actor table. The country panel on each country page (axonia.us/<iso>) summarises the same data per-country.