Sign in

Censys

@censys.bsky.social
259 followers 68 following 174 posts

Censys is the authority in Internet intelligence & insights. Delivering the most comprehensive, accurate, and up-to-date global map of Internet infrastructure, Censys provides the real-time external visibility.

PostsRepliesMedia
Censys @censys.bsky.social · 17h
A messaging protocol with a multi-year ransomware track record. An actively exploited Cisco SD-WAN flaw. We added 22 new protocol and endpoint scanners last month. See what else might be exposed in your environment. bit.ly/4yHJ6dI
A digital network visualization with interconnected nodes. Icons depicting a building, a database, a Wi-Fi router, and a security camera are connected by lines, symbolizing communication and data transfer across a global network. The background features a subtle image of the Earth, enhancing the theme of connectivity.
011
Censys @censys.bsky.social · 08/10/2026
🚨 Rapid Response: SonicWall patched a critical CVSS 10.0 pre-auth SSRF in SMA1000 (CVE-2026-102255). Censys detects 5,966 Internet-exposed hosts and 39,310 web properties running SMA1000/Secure Mobile Access, excluding honeypots. Censys ARC advisory: bit.ly/3VWfWJc
Censys map highlighting countries with varying host counts, showing higher concentrations in the United States, Germany, and Japan. A sidebar lists host counts, with the United States at 1,832, followed by Germany at 594. Additional countries include Canada, Australia, and the United Kingdom.
011
Censys @censys.bsky.social · 07/10/2026
🚨 Rapid Response: CVE-2026-21589 is a critical arbitrary file access vulnerability affecting eight Atlassian Data Center products. Censys detects 95,366 Internet facing hosts and 431,502 web properties running affected products. Details: bit.ly/4dWwYgs
000
Censys @censys.bsky.social · 07/10/2026
New research from Censys ARC examines open directories exposing the full DarkSword/Coruna iOS exploitation platform: C2, admin panel, live victim telemetry, and 18 wallet-theft modules. Read the full analysis: bit.ly/3VVJGG6 #CensysARC
Diagram of the DarkSword exploit chain involving six CVEs. It includes steps such as the remote code execution (RCE) in WebKit, sandbox escapes, and injection-loading techniques. Specific CVEs are listed, each contributing to the overall chain, with detailed methods like iCloud dumper and stage-0 beacon noted. The final outcome describes data exfiltration using AES-ECB encryption and spoofing a Mobile Safari user agent.
041
Censys @censys.bsky.social · 07/10/2026
Join Censys ARC for a special edition of Censys ARC Flash at 11 AM ET for highlights of what they found across the vast and volatile Internet. Register to join: bit.ly/4uEpjd2 #CensysARC #CensysSOTIR
011
Censys @censys.bsky.social · 06/10/2026
Welcome to Censys, Jeff Hackett! Jeff joins us as CFO, bringing 20+ years of finance experience across cybersecurity, technology, and SaaS. More: bit.ly/3VpYEUN
030
Censys @censys.bsky.social · 05/10/2026
🚨 RAPID RESPONSE: CVE-2026-84411 is a critical unauthenticated RCE affecting MikroTik RouterOS web management. Censys detects 364,341 exposed hosts. This is an exposure count, not confirmed vulnerable devices. No public exploitation reported. Censys ARC advisory: bit.ly/4rXOqaf
001
Censys @censys.bsky.social · 02/10/2026
🚨 Fortinet reports CVE-2026-104286 is being exploited in the wild. Censys observes ~2,800 Internet-exposed FortiMail hosts, excluding honeypots. No fixed builds are available yet. Censys ARC advisory: bit.ly/4htjUkY
000
Censys @censys.bsky.social · 30/09/2026
In the 2026 State of the Internet Report, we are looking beyond the weekly news cycle to benchmark security trends across more than 2 years of Internet data. Join Censys ARC Flash on Oct 14 at 11 AM ET to hear directly from the researchers behind the report & ask questions. bit.ly/3ToHoyz
021
Censys @censys.bsky.social · 29/09/2026
AI can make your SOC faster. It can’t fix incomplete data. At Cybersec Netherlands, Censys Senior Solutions Engineer Jonas Gyllenhammar explains why fresh Internet Intelligence matters for triage, investigation, hunting, and defense. Watch the session: www.youtube.com/watch?v=EKDdEYV8twE
youtu.be
The Intelligence Gap: Why Modern SOCs Depend on Complete Internet Visibility
YouTube video by Cybersec
000
Censys @censys.bsky.social · 28/09/2026
🚨Two Citrix NetScaler RCE vulnerabilities are being actively exploited as zero-days. Censys sees 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC advisory:
011
Censys @censys.bsky.social · 25/09/2026
Our most ambitious report yet. The 2026 Censys State of the Internet Report looks across more than two years of Internet data to uncover what’s changing, what persists, and where new risks are emerging. The full report arrives October 13. Pre-register to get your copy: bit.ly/4yPefeO
020
Censys @censys.bsky.social · 24/09/2026
We're open-sourcing nine skills that teach your agents and AI assistants to drive the Censys CLI. bit.ly/4rxi1qW
000
Censys @censys.bsky.social · 22/09/2026
Thank you to our Censys Partners! We're expanding the Censys Channel Partner Program by investing even more in helping partners bring real-time Internet intelligence to customers worldwide. bit.ly/4h5Fz2z #CensysPartner #CensysEverywhere
000
Censys @censys.bsky.social · 21/09/2026
🚨 CVE-2026-10747: A critical pre-auth RCE in IBM MQ carries a CVSS 10.0. Censys ARC observes IBM MQ consoles on 120 hosts Internet-wide. IBM has released fixes; no active exploitation is currently known. bit.ly/4jh5qWx
000
Censys @censys.bsky.social · 18/09/2026
From an IP in a threat report to real-time Internet context. One click, less friction. 🙌
010
Censys @censys.bsky.social · 18/09/2026
@feedly.com now links straight into Censys. When a threat report surfaces an IP, it rarely tells you what that host is doing right in real-time. Now analysts can click 'Open in Censys' from a Feedly IoC Insights Card and land on the live host record. Great threat intel integration! bit.ly/3V4kr42
021
Censys @censys.bsky.social · 16/09/2026
🚨CVE-2026-91843 is a critical (CVSS 9.8) pre-auth RCE affecting Check Point Quantum Security Management and Log Servers. Censys sees 3,836 hosts globally with the management/log server role. No public PoC or confirmed exploitation as of publication. Patches are available. bit.ly/4cRApEJ
033
Censys @censys.bsky.social · 16/09/2026
Building software that collects data used to require real engineering. That skill gate, unknowingly, protected people. AI tools removed it. What came next? Dozens of student-facing apps collecting homework photos, GPAs, & essays, with no one watching where any of it goes. bit.ly/4gTy2Uv
bit.ly
No One Inside The Machine - Censys
Censys analyzes vibe-coded AI apps that target students and children. Unprotected and not yet detectable with conventional threat detection.
000
Censys @censys.bsky.social · 15/09/2026
Censys ARC sees 131 Mythic-associated hosts on the public Internet, with some clear fingerprints. This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: bit.ly/4xRKcTG #CensysARC
031
Censys @censys.bsky.social · 15/09/2026
🚨 GitLab CVE-2026-85706 is a CVSS 10.0 vulnerability under active exploitation. Censys sees 86K+ GitLab hosts on the Internet. If your instance was exposed while vulnerable: patch, rotate credentials, and investigate for compromise. bit.ly/4A690c6
021
Censys @censys.bsky.social · 11/09/2026
Your CFO’s phone is pwned. You have an alert with an IP. Now what? The IOC isn’t the incident. It’s where the investigation starts. See how to go from indicator ➡️ Internet infrastructure ➡️ incident scope: bit.ly/4xeQ5cx
censys.com
So Your CFO's Phone Has Been Pwned: A DFIR Journey - Censys
Learn how to pivot from an IOC to a full DFIR history with two real-world examples that draw on recent Censys ARC research.
001
Censys @censys.bsky.social · 10/09/2026
New in Censys: map your search results. 🗺️ Click a country or draw a box around a region. Try it! docs.censys.com/docs/platform-quick…
000
Censys @censys.bsky.social · 09/09/2026
A few hours to go. Join @silascutler.bsky.social and @martijngrooten.bsky.social at 11 AM ET for Censys ARC Flash to hear about their latest Internet research. Join live to participate in the Q&A. Register: bit.ly/4uEpjd2 #CensysARC
043
Censys @censys.bsky.social · 08/09/2026
70% of Internet-exposed ICS hosts are on consumer and mobile networks, where registration data points to the telecom provider, not the operator. Censys ARC on the exposure notification gap: bit.ly/46NSdwY
censys.com
2026 State of the Internet: The Exposure Notification Gap in ICS Devices - Censys
New data from Censys' upcoming State of the Internet Report reveals a major blind spot in Internet-exposed industrial control systems (ICS).
011
Censys @censys.bsky.social · 04/09/2026
New Censys ARC research from @silascutler.bsky.social looks across NPS infrastructure on the Internet and breaks down the signals that can help distinguish ordinary deployments from potentially malicious ones. bit.ly/4yibWAF
bit.ly
Neither Malware nor Harmless: Tracking the NPS Proxy Across the Internet - Censys
Most deployments of the NPS tunneling tool are benign. Some are not. Censys ARC shares signals for distinguishing the benign from the malicious.
011
Censys @censys.bsky.social · 03/09/2026
What is the Censys ARC team tracking right now? Find out live on Sept. 9 at 11 AM ET during the next Censys ARC Flash. Hear from our researchers, then bring your questions for the live Q&A. Register: bit.ly/4uEpjd2 #CensysARC
000
Censys @censys.bsky.social · 31/08/2026
🎥 Looks like an MP4. Carries an encrypted NetSupport client. Censys ARC researcher @exraritas.bsky.social uncovered an active malware payload hiding inside a fake video file. He tracked the NetSupport RAT delivery kit across 40 live endpoints and 18 builds. bit.ly/3Uuc15N #CensysARC
bit.ly
The Video That Plays You: Fake MP4 File Carries Malicious Payload - Censys
Censys ARC examines the kit that hides malicious payloads within a fake MP4 file that can pass file-type checks. Here's how it works.
031
Censys @censys.bsky.social · 28/08/2026
🚨 New Rapid Response: CVE-2026-77550 is a CVSS 10.0 authentication bypass affecting UniFi OS. Censys sees ~102,000 UniFi OS management interfaces exposed to the Internet. Patches are available. bit.ly/3UpcKoO #CVE202677550
021
Censys @censys.bsky.social · 27/08/2026
Censys ARC researcher @silascutler.bsky.social examines an exposed server containing Moobot botnet source code, active attack records, additional DoS tooling, and a fraudulent identity verification service. Full analysis of what the exposed directory revealed: bit.ly/3SUCPvz
052
Censys @censys.bsky.social · 25/08/2026
🚨 CVE-2026-55040 + CVE-2026-63520 can be chained to bypass authentication and achieve RCE on Microsoft SharePoint Server. Censys sees 329,000 Internet-facing servers. Read the advisory: bit.ly/4qKJSUc #CVE202655040 #CVE202663520
020
Censys @censys.bsky.social · 25/08/2026
ERMAC and HookBot are tracked as two families. Censys ARC researcher @thehappydinoa.dev read the leaked source and found one code base, where a single constant decides which name the panel shows. Also in the post: which detection artifacts survive a rebrand, and which do not. bit.ly/46lP3Ao
012
Censys @censys.bsky.social · 20/08/2026
"Very useful for OSINT investigations with IP's, hashes and potential malicious entities" Read the full review here: www.gartner.com/reviews/market/exte…
000
Censys @censys.bsky.social · 14/08/2026
Catch every episode of Censys ARC Flash on Spotify and stay up to date with the latest research, emerging threats, and Internet intelligence from the Censys ARC team. 🎧 Follow us on Spotify: bit.ly/4wgaMo2 #CensysARC
open.spotify.com
Censys ARC Flash
Podcast · Censys · Join the Censys ARC research team to stay ahead of emerging cyber threats through expert-led insights drawn directly from cutting-edge Censys ARC research. Each concise episode deli...
000
Censys @censys.bsky.social · 14/08/2026
Censys intelligence is now powering BlinkOps AI agents and response workflows to give them the Internet visibility to investigate exposures and drive remediation end-to-end. Attacker-accurate data. Agentic action. With full external context. bit.ly/45ZkNuZ
censys.com
Censys + BlinkOps - Censys
Organizations today face an expanding external attack surface driven by cloud adoption, mergers and acquisitions, shadow IT, and rapidly changing internet-facing infrastructure. Security teams need continuous visibility into exposed assets and the abili...
030
Censys @censys.bsky.social · 13/08/2026
𝗧𝗛𝗘 𝗜𝗡𝗧𝗘𝗟 𝗔𝗨𝗧𝗛𝗢𝗥𝗜𝗧𝗬 | AUGUST 2026 🔶 New Censys ARC research 🔶 An exposure assessment 🔶 53 new fingerprints & 24 new protocol scanners 🔶 Upcoming threat hunting, ARC Flash, and industry events www.linkedin.com/pulse/august-censy…
000
Censys @censys.bsky.social · 11/08/2026
Tomorrow at 11 AM ET during the Censys ARC team will unpack what stood out at Black Hat, what they’re tracking across the Internet, and the latest insights from Censys research. Bring your questions and ask our researchers directly during the Q&A. bit.ly/4uEpjd2 #CensysARC
000
Censys @censys.bsky.social · 07/08/2026
Your SOC has more data than ever. But if that data is stale, you're not making better decisions, you're just making bad ones faster. Censys collapses Internet-context into one workflow: discovery, freshness, history & enrichment tied to the indicators you’re investigating. bit.ly/3TKT66i
000
Censys @censys.bsky.social · 05/08/2026
Join the Censys ARC team on Aug 12 for a live discussion of what stood out at Black Hat and the latest insights from Censys Internet intelligence research. Live Q&A included. Register: bit.ly/4uEpjd2 #CensysARC #BHUSA
000
Censys @censys.bsky.social · 03/08/2026
New research from @thehappydinoa.dev identifies a threat actor running 100+ DarkSword panels. Censys ARC has now observed at least 7 (likely 8) unrelated crews using the leaked iOS exploit chain. bit.ly/4fMX71w #CensysARC
bit.ly
DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster - Censys
Censys ARC noticed a recent spike in DarkSword hosts and web properties. Here are the IOCs and pivots you need to track the growing threat.
011
Censys @censys.bsky.social · 31/07/2026
Censys IOC Investigator is our AI-powered threat investigation feature. Open beta launches August 10. Built on how Censys ARC researchers actually work: parallel pivots, evidence-backed findings, deterministic pipeline. bit.ly/4xk5etH
bit.ly
Introducing Censys IOC Investigator: Run Every Lead Like You've Got Hours - Censys
Learn about Censys' new IOC Investigator: an AI-powered threat investigation feature that automates pivoting, infrastructure mapping, and host profiling.
011
Censys @censys.bsky.social · 31/07/2026
🚨A critical JetBrains TeamCity vulnerability CVE-2026-63077 could allow unauthenticated RCE on Internet-facing servers. Censys sees ~4,500 TeamCity web properties. ▪️No active exploitation has been reported by JetBrains. ▪️Patches are available bit.ly/45DhGIQ
000
Censys @censys.bsky.social · 30/07/2026
Censys ARC researchers found that AI/LLM tool exposures increased 60% in the past 9 months. This is just one early finding from the upcoming 2026 State of the Internet Report. The full report is available this fall. Pre-register to get it as soon as it publishes. bit.ly/44JNRGq #CensysARC
000
Censys @censys.bsky.social · 29/07/2026
Real-time Internet intelligence. No more stitching together feeds. No more manual investigations. No more inconsistent outcomes.
000
Censys @censys.bsky.social · 28/07/2026
Early findings from the 2026 Censys State of the Internet Report show AI/LLM exposures have increased over 60% in the past nine months. AI is compressing the window between vulnerability and exploit. Patching faster won't save you. Our CEO wrote a full breakdown:
010
Censys @censys.bsky.social · 23/07/2026
Every year, Censys scans the Internet and publishes what we find. This year's State of the Internet Report is almost here. The full report drops this fall. bit.ly/44JNRGq
010
Reposted by Censys
Help Net Security @helpnetsecurity.com · 22/07/2026
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) 📖 Read more: www.helpnetsecurity.com/2026/07/22/s... #PoC #SharePoint #vulnerability #vulnerabilitymanagement #cybersecurity #cybersecuritynews @censys.bsky.social
helpnetsecurity.com
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) - Help Net Security
Attackers are exploiting an unauthenticated SharePoint RCE vulnerability (CVE-2026-50522) to extract the servers' IIS machine keys.
011
Censys @censys.bsky.social · 20/07/2026
DNS intelligence in the Censys Internet Map, in motion. Pivot from a domain to the infrastructure behind it, no separate tools, no lost context. bit.ly/4gBsaPU
000
Censys @censys.bsky.social · 17/07/2026
Happy #WorldEmojiDay to everyone who's lived this sequence more times than they'd like: 🚨 something's on fire, allegedly 🔍 turns out it's been exposed for months 🧩 different tools, different answers 🚩 there it is 😴 waiting on the scan to finish ✅ closed, for now What's missing from ours?
000
Censys @censys.bsky.social · 17/07/2026
Following a new Dutch intelligence advisory, Censys ARC Principal Security Researcher Martijn Grooten analyzed Internet-connected camera exposure across Europe. Censys sees: 🔻Nearly 2K with known exploited vulns 🔻87K+ across Europe & Ukraine Read more: bit.ly/3T77aqu #CensysARC
044