Sign in

ONYPHE

@onyphe.io
139 followers 61 following 52 posts

Provider of Attack Surface Discovery (ASD), Attack Surface Management (ASM) and CTI solutions. Scanning at Internet-scale since 2017 - contact at onyphe dot io

PostsRepliesMedia
ONYPHE @onyphe.io · 06/02/2026
🏁 La nouvelle année est déjà entamée, c’est le moment de revenir sur 2025 et de lister ce que nous avons fait chez @onyphe.io. C’est également le moment de parler des évolutions à venir. Et c’est encore une fois ambitieux, comme chaque année chez nous: blog.onyphe.io/rtrospective...
blog.onyphe.io
Rétrospective 2025 et feuille de route 2026 – Blog | Big Data for Cyber Defense
000
ONYPHE @onyphe.io · 04/02/2026
📣 Just added 400 new ports to scan 👀 Total: 3,000+ ports - weekly refresh #ASM #Internet #Scanner
010
ONYPHE @onyphe.io · 12/01/2026
📣 UPDATE: now scanning 2,600+ ports, weekly refresh.
010
ONYPHE @onyphe.io · 08/01/2026
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #n8n product: CVE-2026-21858: unauthenticated remote code execution #Ni8mare search.onyphe.io/search?q=cat...
021
ONYPHE @onyphe.io · 02/01/2026
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #SmarterMail product: CVE-2025-52691: remote unauthenticated file upload & overwrite search.onyphe.io/search?q=cat...
020
ONYPHE @onyphe.io · 30/12/2025
📣 UPDATE: new vulnerable IPs count is ~100K. Our first request was not the most suited one and was updated. 👍 That's why it's important for organizations to communicate on such critical issues: it helps everyone improve for the greater good.
010
ONYPHE @onyphe.io · 29/12/2025
📣 ANNOUNCEMENT: we have reached the 2,100+ scanned ports milestone, at Internet scale with a weekly refresh rate. Next step: 5,000+ ports, weekly refresh. Then 10,000 by end of next year. We will be the competitor number 1 to @censys.bsky.social in 2026. #ASM #CTI #ASD
022
ONYPHE @onyphe.io · 28/12/2025
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #MongoDB product: CVE-2025-14847: remote unauthenticated memory reading #MongoBleed search.onyphe.io/search?q=cat...
031
ONYPHE @onyphe.io · 19/12/2025
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #WatchGuard Firebox: CVE-2025-14733: unauthenticated remote code execution through out of bound writes No one has patched yet, everyone is vulnerable.
000
Reposted by ONYPHE
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️‍🌈 @hrbrmstr.dev · 03/06/2025
For personal use I added a "geolocus" tool to a Deno-based MCP server (that has alot of random tools/functions in it). It's been useful enough that I started extracting it to a standalone geolocus MCP server I shld be able to release in a couple days. The @onyphe.io folks are super rad.
011
ONYPHE @onyphe.io · 16/05/2025
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #Ivanti product: CVE-2025-4427+CVE-2025-4428 unauth RCE search.onyphe.io/search?q=cat... Thanks to watchTowr for detection method.
002
Reposted by ONYPHE
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 27/04/2025
ONYPHE has a super cool geolocus MMDB — www.geolocus.io — that gets updated daily and has network-level metadata for IP addresses (ref first image JSON). Since it's way more efficient to use this than their API, I built a cross-platform CLI tool for […] [Original post on mastodon.social]
The image shows a block of structured JSON data displayed on a dark background. 

The JSON object has the following top-level structure:
	•	abuse:
A list of four email addresses related to reporting abuse at Amazon and AWS:
	•	amzn-noc-contact@amazon.com
	•	aws-routing-poc@amazon.com
	•	aws-rpki-routing-poc@amazon.com
	•	trustandsafety@support.aws.com
	•	asn: "AS14618"
(This is Amazon’s autonomous system number.)
	•	continent: "NA" (North America)
	•	continentname: "North America"
	•	country: "US" (United States)
	•	countryname: "United States"
	•	domain:
A list of three domains:
	•	amazon.com
	•	amazonaws.com
	•	aws.com
	•	ip: "3.215.138.152"
(The specific IP address being described.)
	•	isineu: 0
(Indicates whether the IP is in the European Union — 0 means no.)
	•	latitude: "37.09024"
	•	longitude: "-95.712891"
	•	location: "37.09024, -95.712891"
	•	netname: "AMAZON-IAD"
(The name of the network.)
	•	organization: "Amazon Data Services NoVa"
	•	physical_asn: "AS14618"
	•	physical_continent: "NA"
	•	physical_continentname: "North America"
	•	physical_country: "US"
	•	physical_countryname: "United States"
	•	physical_isineu: 0
	•	physical_latitude: "37.09024"
	•	physical_longitude: "-95.712891"
	•	physical_location: "37.09024, -95.712891"
	•	physical_organization: "Amazon.com, Inc."
	•	physical_subnet: "3.208.0.0/12"
	•	physical_timezone: "America/Chicago"
	•	subnet: "3.208.0.0/12"
	•	timezone: "America/Chicago"Usage
# Download the latest Geolocus database
geolocus-cli download

# Look up IPs from a file
geolocus-cli lookup -i ips.txt -o results.json

# Process IPs from stdin and output to stdout
cat ips.txt | geolocus-cli lookup

# Output in CSV format
geolocus-cli lookup -i ips.txt -f csv -o results.csv

# Output in JSONL format (one JSON object per line)
geolocus-cli lookup -i ips.txt -f jsonl -o results.jsonl

# Disable session caching
geolocus-cli lookup -i ips.txt --no-cache

Command-line Options
Commands:
  download    Download a fresh copy of the geolocus.mmdb database
  lookup      Lookup and enrich IP addresses from a file or stdin

Options:
  -h, --help              Show help information
  -i, --input <file>      Input file containing IP addresses (one per line)
  -o, --output <file>     Output file for results (defaults to stdout)
  -f, --format <format>   Output format: json, csv, or jsonl (default: json)
  --no-cache              Disable IP caching for the current session
043
Reposted by ONYPHE
Hacker & Security News @hacker.at.thenote.app · 28/04/2025
New geolocus-cli For ONYPHE’s Geolocus Database ONYPHE has made available a free API and free MMDB download of their new Geolocus database. It provided IP address metadata in the form of: { "abuse": [ "amzn-noc-contact@amazon.com", "aws-routing-poc@amazon.com", "aws-rpki-routing… #hackernews #news
securityboulevard.com
New geolocus-cli For ONYPHE’s Geolocus Database
ONYPHE has made available a free API and free MMDB download of their new Geolocus database. It provided IP address metadata in the form of: { "abuse": [ "amzn-noc-contact@amazon.com", "aws-routing-poc@amazon.com", "aws-rpki-routing-poc@amazon.com", "trustandsafety@support.aws.com" ], "asn": "AS14618", "continent": "NA", "continentname": "North America", "country": "US", "countryname": "United States", "domain": [ "amazon.com", "amazonaws.com", "aws.com" ], "ip": "3.215.138.152", "isineu": 0, […]
021
ONYPHE @onyphe.io · 29/04/2025
The recovery continues, but things are not yet back to normal
011
ONYPHE @onyphe.io · 28/04/2025
Things are not yet getting better in Spain and Portugal. General downward trend and some visible instability in the remaining networks that are reachable. #PowerOutage
Chart showing Internet scan data for France, Spain and Portugal. Spain and Portugal show significant drops in devices responding at 12:30, and some significant instability visible in Spanish networks from 17:00 to 20:00
020
ONYPHE @onyphe.io · 28/04/2025
The electrical power outage in Spain and Portugal as seen from the Internet (France included for reference)
A chart showing Internet scan data plots for three countries; Spain, Portugal and France. The three lines are stable, with minor variations from 09:00 to 12:30. At 12:30 the lines for  Spain and Portugal drop almost vertically to roughly 50% of their original levels. The line for France continues as for the start of the day.
The lines for Spain and Portugal have not returned to their original levels.
022
ONYPHE @onyphe.io · 25/04/2025
#CVE-2025-32432 #0day #CraftCMS discovered by Orange Cyberdefense 💥Unauthenticated Remote Code Execution. No CVSS yet, we suggest to give it a 10 📌40,000 IP addresses representing over 37,000 domain names exposed, 12,168 unique domains vulnerable Blog: blog.onyphe.io/en/cve-2025-...
blog.onyphe.io
CVE-2025-32432 – 0day Craft CMS discovered by Orange Cyberdefense – Blog | Big Data for Cyber Defense
122
ONYPHE @onyphe.io · 22/04/2025
UPDATE: our scan has finished, near 22,000 devices are compromised.
000
ONYPHE @onyphe.io · 21/04/2025
💥Méthode de détection de la #backdoor #symlink sur #fortinet "nous sommes prêts à la partager, en privé" Plus de 18,000 équipements compromis Lire l'article : blog.onyphe.io/backdoor-sym...
blog.onyphe.io
Backdoor symlink sur des VPN SSL Fortinet – Blog | Big Data for Cyber Defense
020
ONYPHE @onyphe.io · 21/04/2025
💥Detection method for #symlink #backdoor on #fortinet "we are willing to share it, privately" More than 18k devices compromised Read more: blog.onyphe.io/en/symlink-b...
blog.onyphe.io
Symlink backdoor on Fortinet SSL-VPN devices – Blog | Big Data for Cyber Defense
052
ONYPHE @onyphe.io · 16/04/2025
Time to search for a decentralized way to deal with vulnerability identifiers.
020
Reposted by ONYPHE
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️‍🌈 @hrbrmstr.dev · 24/03/2025
And there's an #RStats package for it—now. codeberg.org/hrbrmstr/geo...
codeberg.org
geolocus
geolocus R Package
2154
ONYPHE @onyphe.io · 24/03/2025
❓Ever wanted to have an IP geolocation database with 2 locations, one physical for the device and one logical from whois data? 👉We provide a free MMDB file for download and a brand new Website for lookups & even a free API access: www.geolocus.io
geolocus.io
Geolocus by ONYPHE
Geolocus is an IPv4 & IPv6 geolocation service. Our motto is: you don't need misleading GPS coordinates, you need trusted IP to country locations. Furthermore, an IP address truly has 2 locations: 1 l...
032
Reposted by ONYPHE
Rayna 🤓🇪🇺👩‍💻📚✍️ @maliciarogue.bsky.social · 23/03/2025
👓La Cyber-revue à bas bruit est de retour ! L'alpha et l'oméga de cette édition : les zero days. C'est... surprenant 😇 Et aussi un podcast (coucou @nolimitsecu.bsky.social), des chiffres passionnants d' @onyphe.io et de La tech est politique et sa nouvelle rubrique. www.linkedin.com/pulse/zero-d...
linkedin.com
Zero Day
Bonjour ☕ Bienvenue dans la Cyber-revue à bas bruit de la semaine. Je sais, ça fait un bail, mais : j'ai eu des semaines de ouf (dont une qui s'est finie avec votre dévouée bloquée à Bruxelles pour ca...
074
ONYPHE @onyphe.io · 18/03/2025
The latest version of our cli tool has been released. Get v4.19.0 and find wrappers with sweet new APIs inside. Available here ➡️ search.onyphe.io/docs/onyphe-... or here 🐳 hub.docker.com/r/onyphe/ony... or even here 🥷 metacpan.org/dist/Onyphe
search.onyphe.io
Installation | ONYPHE
Installation
032
ONYPHE @onyphe.io · 01/03/2025
💥 Great news 💥 #ASD #AttackSurfaceDiscovery APIs are on their way to general availability. It will never be as easy to create an asset inventory for any organization attack surface #EASM Backed by 10th of billions of informations we collect.
000
Reposted by ONYPHE
-= StalkPhish =- @stalkphish.bsky.social · 15/02/2025
📣 Meet Thomas Damonneville - our founder - at the #M3AAWG organized by the Messaging, Malware, Mobile Anti-Abuse Working Group in Lisbon next week for his presentation entitled: “Hunting for phishing URLs, kits and business”. 👋 In partnership with Signal Spam #phishing #phishingkit #cybersecurity
131
ONYPHE @onyphe.io · 14/02/2025
Yes, still 50k compromised devices. Since more than 12 months.
021
ONYPHE @onyphe.io · 14/02/2025
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #PaloAltoNetworks PA product: CVE-2025-0108: authentication bypass on management interface search.onyphe.io/search?q=cat... Thanks to @assetnote.io for having shared the detection method.
063
Reposted by ONYPHE
James Atack @jamesatack.com · 12/02/2025
Yet by performing an awkward legal waltz around the subject, Talos have helpfully supported my hypothesis that compromised IOS XE devices are part of an ORB network serving multiple APTs. archive.hack.lu/hack-lu-2024...
archive.hack.lu
The XE Files - Trust No Router hack.lu 2024
On the 16th October 2023 Cisco Talos shared intelligence about a handful of compromised routers discovered while resolving customer support requests. As the full story unfolded, a handful of backdoore...
122
ONYPHE @onyphe.io · 31/01/2025
🎉 Retrospective 2024 and Roadmap 2025 👉 Over the last 12 months, we massively increased our visibility of Internet exposed assets. Until now, we focused on #ASM, but this year we will improve our automatic #ASD and expand into the #CTI segment. Read more: search.onyphe.io/docs/write-u...
052
Reposted by ONYPHE
James Atack @jamesatack.com · 03/01/2025
we tag it at a risky protocol there are 2.2M results for Windows RPC boxes
onyphe ctiscan result showing the number of rpc protocol exposed on Windows boxes, that is 2193060 found in 0.26 seconds
111
ONYPHE @onyphe.io · 21/01/2025
Cc @greynoise.infosec.exchange.ap.brid.gy
010
ONYPHE @onyphe.io · 21/01/2025
🪘 That's probably the best advertisement we may have: an independent benchmark from GreyNoise Intelligence about benign Internet scanning activity. It shows our #scanning technology can give you a better view on your exposed assets that cyber-criminals.
100
ONYPHE @onyphe.io · 17/01/2025
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #Fortinet FortiGate product: CVE-2024-55591: unauthenticated remote issue allows to gain super-admin privileges search.onyphe.io/search?q=cat... Thanks to @WatchTowr for sharing detection method.
010
ONYPHE @onyphe.io · 17/01/2025
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #SimpleHelp SimpleHelp product: CVE-2024-57727: sensitive information disclosure caused by path traversal vulnerability search.onyphe.io/search?q=cat...
000
Reposted by ONYPHE
ONYPHE @onyphe.io · 12/01/2025
Just starting to scan #IPv6 at application layer and already found a compromised device running a #MeshCentral #C2 #Panel
084
ONYPHE @onyphe.io · 12/01/2025
Just starting to scan #IPv6 at application layer and already found a compromised device running a #MeshCentral #C2 #Panel
084
Reposted by ONYPHE
James Atack @jamesatack.com · 06/01/2025
Couple of additional datapoints about the "Trojan Panel" C2 that \@shanholo had already found in April i) the github followers list is an eye-opener ii) Oracle the leading public cloud for once details below 👇
Screenshot from Twitter / X of a post by @shanholo with screenshot of the Trojan Panel C2
121
Reposted by ONYPHE
James Atack @jamesatack.com · 03/01/2025
I'm going to stop there for now for biological reasons If anyone is interested, our data supports the hypothesis that UAC-0050, targeting the Ukranian government, is exploiting DCE/RPC on Windows boxes to establish C2 capability for the duration of a campaign.
011
Reposted by ONYPHE
James Atack @jamesatack.com · 03/01/2025
Looking at the first C2 IP 111[.]90.140.76 with @onyphe.bsky.social (yeah well...) nothing currently up but looking back in historical data we've got an RDP box with dcerpc also exposed going back to Sep 24
onyphe screenshot showing result for IP 111[.]90.140.76 on port 3389 exposing RDP, dated to 3 nov 2024. Also exposing port 135 dcerpc
121
ONYPHE @onyphe.io · 21/12/2024
The Great #Honeypot of China in one picture:
010
Reposted by ONYPHE
Valéry Rieß-Marchive @valerymarchive.bsky.social · 20/12/2024
Mais que montrent les données de @onyphe.bsky.social ? Un système Citrix Gateway qui semble, un temps, ne pas avoir répondu à ses sondes 🤔
111
Reposted by ONYPHE
James Atack @jamesatack.com · 04/12/2024
Si vous cherchez une école du 21ème siècle à Paris 👇
021
ONYPHE @onyphe.io · 06/12/2024
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #Mitel MiCollab product: CVE-2024-35286: unauthenticated SQL injection on login page CVE-2024-41713: unauthenticated arbitrary file read www.onyphe.io/search?q=cat...
052
Reposted by ONYPHE
-= StalkPhish =- @stalkphish.bsky.social · 23/11/2024
Hi there \o/
021
Reposted by ONYPHE
Patrice <GomoR> Auffret @patriceauffret.bsky.social · 21/11/2024
@onyphe.bsky.social identifies more than 2k vulnerable IPs. That could mean all of them are compromised :/
022
ONYPHE @onyphe.io · 19/11/2024
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #PaloAltoNetworks PA product: CVE-2024-0012: authentication bypass on mgmt interface CVE-2024-9474: authenticated (bypassed) RCE on mgmt interface www.onyphe.io/search?q=cat...
063
Reposted by ONYPHE
Valéry Rieß-Marchive @valerymarchive.bsky.social · 19/11/2024
And guess what! SonicWall again according to data from @onyphe.bsky.social 😉 #Akira
021
Reposted by ONYPHE
Valéry Rieß-Marchive @valerymarchive.bsky.social · 19/11/2024
Oh gosh, one of the recently claimed #Akira victims ticked all the boxes with an outdated Exchange server and a SonicWall VPN, right end of August 🤯 (data courtesy of @onyphe.bsky.social)
052