Censys
Censys is the authority in Internet intelligence and insights. Delivering the most comprehensive, accurate, and up-to-date global map of Internet infrastructure, Censys provides the real-time external visibility organizations need to accelerate security operations, investigate threats, and understand Internet exposure. Global governments, Fortune 500 companies, and security providers trust Censys to uncover risks faster and respond more effectively.
👀 It has been quite a wild week in the land of CVEs. Get the Censys research team perspective in our latest blog, "Now You CVE, Now You Don't: How the MITRE CVE Program Nearly Went Dark". https://censys.com/blog/now-you-cve-now-you-dont-how-the-cve-program-nearly-went-dark
The botnets 👾 out there; you just have to know how to grab them. We know how to grab them. Together with @greynoise@infosec.exchange, we've brought threat hunting to the next level. https://censys.com/blog/hunting-botnets-with-cursorai-greynoise-censys-and-censeye
Around 12PM UTC on June 18, scan error rates in Iran surged to nearly 100%, indicating a sudden, nationwide outage affecting almost all services. Systems that were previously reachable are now timing out or rejecting connections.
We used the new Censys Threat Hunting Module to investigate a Colombian threat actor, uncovering a series of remote access trojan (RAT) C2 servers.
We also show how to use this information to create a set of IOCs for defensive measures:
https://censys.com/blog/unmasking-the-infrastructure-of-a-spearphishing-campaign
🔌 Iran Internet Outage Update
Since June 18, Iran has faced a near-total internet blackout. June 21 marked the lowest point in visibility—but signs of recovery are emerging.
📉 Some networks (e.g., DATAK, HAMYAR-AS) remain unstable.
📈 Others (e.g., RESPINA-AS, MOBINNET-AS) are bouncing back strong.
🧭 TIC appears in nearly all slow-recovering transit paths.
We’re tracking it all.
🔍 View the update at Censys: https://censys.com/blog/irans-internet-a-censys-perspective
#InternetShutdown #Iran #NetworkOutage #Censys #InternetIntelligence
In October 2024, Censys researchers discovered ~400 U.S. water facility web-based HMIs exposed online. Within a month of sharing data with the EPA and the vendor, 58% of systems were protected. Read more here:
May 6 Advisory: Critical RCE Vulnerability Identified in Craft CMS [CVE-2025-32432] https://censys.com/advisory/cve-2025-32432
Multiple US gov agencies have warned orgs to stay vigilant for potential Iran-affiliated cyber activity. We studied exposure of 4 vendors previously known to be of interest to IR-affiliated groups.
Read more: https://censys.com/blog/ics-iran-exposure-of-previously-targeted-devices
A defining moment for Censys - We are excited to announce that the Threat Hunting Module in the new Censys Platform is now #ga
https://www.censys.com/blog/internet-scale-proactive-threat-hunting-and-detection
Trend Micro recently uncovered a campaign leveraging TikTok to distribute malware via AI-generated videos, tricking users into installing Vidar and StealC infostealers instead of the promised pirated software.
Using IOCs provided by Trend Micro, we used Censys to find more related infrastructure, including a relatively new bulletproof service provider. Read our analysis here:
If you think Salt Typhoon has moved on—you might want to double-check your attack surface. We’re still seeing critical telecom infrastructure exposed to active targeting. Find out what we uncovered (and what you should be looking for) https://censys.com/blog/salt-typhoon-attacks-highlight-need-for-advanced-defenses
🚨 Launch Alert 🚨Censys just redefined threat hunting. Our new Threat Hunting Module delivers unmatched visibility and context from real-time Internet Intelligence that empowers you to proactively hunt emerging threats. See it in action: https://censys.com/solutions/threat-hunting #cybersecurity #threathunting
🔍 We looked at the C2 server associated with the Flodrix botnet and used an internet-exposed RPC service to uncover a world-readable NFS mount and 745 compromised hosts!
Thousands of compromised ASUS routers are being co-opted into a volatile but persistent botnet. Our latest blog takes IoCs from @greynoise@infosec.exchange and breaks down how the AyySSHush campaign has evolved over the past 5 months — and what makes it stand out:
https://censys.com/blog/tracking-ayysshush-a-newly-discovered-asus-router-botnet-campaign
🚩 May 7 Advisory: Unauthenticated Code Injection Vulnerability in Langflow [CVE-2025-3248] https://censys.com/advisory/cve-2025-3248
Censys was a proud contributor to the 2025 Verizon Data Breach Investigations Report, shedding light on the growing threat to firewalls, VPNs, and other perimeter gear. See that this sharp increase in targeting edge security devices means ➡️ https://censys.com/blog/postcards-from-the-edge-verizon-dbir-reveals-sharp-increase-in-targeting-of-edge-security-devices
Security advisory update for this week. April 28 Advisory: SAP NetWeaver Actively Exploited Unauthenticated File Upload Vuln [CVE-2025-31324]
This is an especially severe issue that combines several of the worst-case risk factors. Read more: https://censys.com/advisory/cve-2025-31324
Threat hunters, this is your inside track. 🎥 We just dropped an exclusive threat intelligence briefing from malware analyst Silas Cutler. Get insight into the BeaverTail malware campaign, North Korea’s infiltration of global tech, and more. Watch now. https://censys.com/podcasts-videos/inside-north-korea-cyber-ops-with-silas-cutler
CISA's SCuBA reminds us: strong government cloud security starts with strong fundamentals. 🔐 Censys' lead federal solutions engineer calls for a return to basics in a brand new Federal News Network article.
https://federalnewsnetwork.com/commentary/2025/04/securing-federal-cloud-environments-cisa-scuba-reminds-cloud-service-providers-of-the-basics/
Every year, Censys scans the Internet and publishes what we find. This year's State of the Internet Report is almost here.
Following a joint advisory from Dutch intelligence services, Censys ARC Principal Security Researcher Martijn Grooten examined Internet-connected camera exposure across Europe.
Censys observed more than 87,000 Internet-connected cameras with potentially exploitable vulnerabilities across Europe and Ukraine.
Sometimes sensitive data is just sitting on the public Internet. An exposed database, an unauthenticated message broker, or a forgotten file transfer server, all accessible to anyone who finds it.
In this clip from the Censys ARC Flash, Silas Cutler and Michael Schwartz discuss what we're seeing across the Internet and why it matters.
Detection Engineering has evolved beyond the SIEM, into a broader SecOps discipline.
Detections increasingly have to start before endpoint execution: in identity, DNS, proxy, cloud, SaaS, exposed infrastructure, and the public Internet itself.