#censysarc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #censysarc, aggregated by home.social.
-
The next Censys ARC Flash is September 9 at 11 AM ET.
Join the Censys ARC team for a timely briefing on the research, threats, and Internet activity they're tracking, followed by a live Q&A where you can ask the researchers your questions directly.
Register to attend live:
https://info.censys.com/arc-webcast#CensysARC #ThreatResearch #ThreatIntelligence #InfoSec #CyberSecurity
-
It looks like an MP4. But try to play it and things get interesting.
Censys ARC uncovered an active malware payload hiding inside a fake video file.
Starting with one observed host, they identified 18 builds across 40 live endpoints and mapped the PowerShell → MP4 carrier → NetSupport RAT delivery chain.
Full analysis, detection opportunities, and IOCs: https://censys.com/blog/fake-mp4-file-carries-malicious-payload/
#CensysARC #ThreatIntelligence #Malware #ThreatHunting #DFIR
-
Censys ARC Principal Security Researcher @silas uncovered Moobot source code alongside active attack records, additional DoS tooling and a fraudulent identity verification service.
Read the research: https://censys.com/blog/open-directory-exposes-moobot-source-code-and-activity/#CensysARC #ThreatIntelligence #ThreatHunting #Malware #DDoS
-
The practical half: rebranding a panel takes one line of source, and the firewall these operators ship hides the panel, the API, and the implant socket from scanners. So what still works for hunting? Aidan makes the case for the APK builder, on a port the firewall never covers.
https://censys.com/blog/ermac-source-leak-hookbot/
#CensysARC #ThreatIntelligence #Malware #AndroidSecurity #ThreatHunting
-
𝗧𝗛𝗘 𝗜𝗡𝗧𝗘𝗟 𝗔𝗨𝗧𝗛𝗢𝗥𝗜𝗧𝗬 | AUGUST 2026
AI/LLM tool exposures have risen more than 60% in just nine months.
That's one of the early findings from our upcoming State of the Internet Report 2026.
Also inside this month's Intel Authority:
🔶 New Censys ARC research tracking how leaked DarkSword offensive tooling spread across the Internet
🔶 An exposure assessment following CISA's warning about PLC targeting in the water sector
🔶 53 new fingerprints & 24 new protocol scanners
🔶 What Censys Search users need to know before September 30
🔶 Upcoming threat hunting, ARC Flash, and industry eventsRead the August edition and subscribe to get the next issue. https://www.linkedin.com/pulse/august-censys-intel-authority-new-arc-research-advisories-platform-9vsre
#Cybersecurity #ThreatIntelligence #InternetIntelligence #AI #ICS #CensysARC
-
What caught our attention at Black Hat?
Find out tomorrow at 11 AM ET during the next Censys ARC Flash.
The Censys ARC team will unpack what stood out at Black Hat, what they’re tracking across the Internet, and the latest insights from Censys research.
And because ARC Flash is live, bring your questions and ask our researchers directly during the Q&A. https://info.censys.com/arc-webcast
#CensysARC #BHUSA #Threatintel #Internet
Register to join:
-
DarkSword, a commercial iOS exploit chain that leaked publicly on GitHub, is no longer being used by a single actor.
Using the Censys platform and a single HTTP body hash as the pivot, Censys ARC identified:
🔸 Six DarkSword panels
🔸 Two distinct codebases
🔸 One large operator cluster spanning more than 100 panelsThe research highlights how quickly leaked offensive tooling can spread across multiple threat actors, and why continuous Internet visibility is critical for tracking evolving infrastructure.
Read the full analysis: https://censys.com/blog/darkswords-panel-sprawl/
-
Censys IOC Investigator closed beta launches August 10. Give it an indicator, a bulk list, or a raw intel report — it runs pivots, history checks, and host profiling in parallel across the Censys Internet Map, then returns ranked findings with the evidence and source queries attached.
This started as internal tooling Censys ARC researchers built to scale their own investigations. That's what powers it today, the same process, same Internet intelligence, now available in the platform.
https://censys.com/blog/introducing-censys-ioc-investigator/
-
The full report is available this fall. Pre-register to get it as soon as it publishes.
https://censys.com/blog/state-of-the-internet-2026-preview/ #CensysARC #infosec #threatintelligence #AIrisk #exposuremanagement
-
The research is a reminder that physical infrastructure and cybersecurity are increasingly connected, and that visibility into Internet-exposed devices remains essential.
https://censys.com/blog/russia-camera-hacking-espionage-campaign/#CensysARC #ThreatIntelligence #Cybersecurity #CriticalInfrastructure
-
In Episode 3 of Censys ARC Flash, @thehappydinoa and Silas Cutler discuss Censys ARC research into nearly 40 AsyncRAT variants, how malware families evolve, and why defenders should care.
If you missed the live webcast, the full recording is now available on demand:
https://censys.com/podcasts-videos/censys-arc-flash-episode-3/ -
Every Censys ARC Flash is built around what our researchers are seeing across the Internet.
If you're interested in threat research, Internet intelligence, and understanding how campaigns evolve, we'd love to have you join us live. https://info.censys.com/arc-webcast
-
Join us live on July 8 for the next Censys ARC Flash episode including Q&A.
Register: https://info.censys.com/arc-webcast #CensysARC #cybersecurity #threatIntelligence
-
The key finding? While the malware continues to evolve, many descendants inherit the same TLS certificate structure from their parent.
Instead of chasing every new variant by name, defenders can use those inherited certificate patterns to identify infrastructure across the entire family. Read the full research from #CensysARC: https://censys.com/blog/asyncrat-family-threat-overview/ #Cybersecurity #ThreatIntelligence #DFIR #ThreatHunting
-
A phishing email targeting a politician led to a much bigger discovery.
New research from Censys ARC researcher Martijn Grooten shows how Censys pivots uncovered additional UNC1151 infrastructure, exposing a broader credential theft campaign targeting Belarus and Ukraine.
Read more: https://censys.com/blog/unc1151-phishing-email-campaign/ #Censys #CensysARC #UNC1151 #Phishing
-
🚨 CVE-2026-48908 (CVSS 10.0) A critical flaw in Joomla's SP Page Builder can enable unauthenticated file upload & potential RCE:
▪️Versions 1.0.0–6.6.1 affected
▪️Active exploitation reported
▪️Patched in 6.6.2Censys observed 194,793 web properties loading the component. Full advisory: https://censys.com/advisory/cve-2026-48908/ #CensysARC
-
Missed Episode 2 of Censys ARC Flash?
Watch on-demand and register for Episode 3, streaming live on July 8. https://censys.com/podcasts-videos/censys-arc-flash-episode-2/ #CensysARC
-
It's been a while, Mastodon.
We're back.
We'll be sharing Internet intelligence,
trends, original #CensysARC research, exposure insights, and practical workflows from across the community to help security teams:🔸 Triage alerts faster
🔸 Investigate incidents with greater context
🔸 Hunt for adversary infrastructure
🔸 Defend against emerging threatsLooking forward to reconnecting and working together to make the Internet safer.