Cyber, spectrum, and routing
The cyber surface aggregates four public-source signal streams that reshape the operating picture in real time but do not fit cleanly under conflict or weather: BGP route leaks and origin hijacks from Cloudflare Radar, OONI per-country censorship measurement, MISP threat-actor presence by country, and the GPS jamming and spoofing layer rendered live on the globe.
OONI censorship leaderboard
Top countries by 30-day anomaly rateThe Open Observatory of Network Interference is a global volunteer measurement network that tests for blocked websites, throttled services, deep-packet-inspection events, and middlebox interference. The list below ranks countries by their 30-day anomaly rate (the share of probes that returned an anomalous response). Click into any country for the full per-app and per-category breakdown.
- TKMTurkmenistan100.0%105 probes
- CHNChina65.0%1,204,526 probes
- IRNIran41.4%563,007 probes
- RUSRussia30.0%7,413,339 probes
- GABGabon22.8%5,794 probes
- YEMYemen21.1%59,279 probes
- MMRMyanmar15.3%182,820 probes
- TZATanzania14.4%170,054 probes
- VENVenezuela13.5%2,810,672 probes
- SYRSyria12.5%136,091 probes
- OMNOman11.6%15,682 probes
- PAKPakistan11.2%213,542 probes
- AFGAfghanistan9.9%47,107 probes
- MLIMali9.7%72 probes
- DJIDjibouti9.3%606 probes
BGP route leaks and hijacks
Snapshot 3d agoBGP leaks happen when an autonomous system announces routes it should not have advertised; hijacks are claims of address space owned by another network. Both result in traffic redirection on the underlying internet. SENTINEL surfaces leaks and hijacks tracked by Cloudflare Radar.
Threat actors by country
474 groups across 35 countriesThe MISP galaxy taxonomy catalogues named threat actors (APT groups, financially motivated criminal groups, hacktivist collectives) by attributed sponsor country. Click into any country to see its full per-actor table on the dossier page.
- CHNChina214 groups
- RUSRussia79 groups
- IRNIran60 groups
- PRKNorth Korea26 groups
- PSEPalestine9 groups
- TURTurkey7 groups
- UKRUkraine6 groups
- VNMVietnam6 groups
- INDIndia5 groups
- USAUnited States5 groups
- ISRIsrael5 groups
- PAKPakistan4 groups
- BRABrazil4 groups
- LBNLebanon4 groups
- BLRBelarus4 groups
- NGANigeria3 groups
- IDNIndonesia3 groups
- KORSouth Korea2 groups
- TUNTunisia2 groups
- AREUnited Arab Emirates2 groups
- 1937CN
- Amaranth-Dragon
- Antlion
- Aoqin Dragon
- APT.3102
- APT1
- APT10
- APT12
- APT14
- APT15
- APT16
- APT17
- APT18
- APT19
GPS jamming and spoofing
GPS jamming is rendered live as a hex-bin heatmap on the globe; spoofing surfaces as discrete events on the patterns rail. Both feeds are too high-resolution to enumerate here usefully, but the categorical state across the major flashpoints is steady: persistent interference around Russia, Iran, the Eastern Mediterranean, and Israel, with intermittent step-changes around active strike windows.
The spoof classifier looks for the spurious-position signature where multiple aircraft simultaneously report a fix at the same impossible coordinate. Receiver-handoff false positives in mid-Atlantic and mid-Pacific coverage gaps are filtered.
See it live
The cyber tab on the live globe carries the four data feeds above with full per-country drill-down, BGP timeseries graphs, OONI 30-day anomaly trends, and a threat-actor table. The country panel on each country page (axonia.us/<iso>) summarises the same data per-country.