Summary

Platform

An example host and its reputation score shown in the Platform UI.

  • Use reputation scores in the Censys Platform to quickly determine the potential risk associated with hosts, validated by transparent evidence in the Censys dataset. This score enables you to prioritize alerts with IP indicators faster and perform triage and analysis more effectively with a transparent and consistent scoring methodology.
    • Reputation scores and their attendant data are only available to Censys Enterprise users. Additional score context data is available to Censys Enterprise users with access to the Adversary Investigation module. See the documentation for more information.

Censys ARC Rapid Response

The Censys ARC team published information about and queries for the following issue.

New fingerprints and risks

Added the following fingerprints and risks.

Note that new ASM risk fingerprints may be disabled by default in your workspace. Reference your risk type configuration in the ASM web console to review new risk types.

New fingerprints

NameDescriptionQuery
handlebars.jsThis asset embeds the Handlebars.js JavaScript templating library.Platform query
Cisco ExpresswayCisco Expressway is a collaboration gateway that provides firewall-traversal technology for voice, video, content, and instant messaging.Platform query
Sangoma AsteriskSangoma Asterisk is an open-source communications framework for building Voice over Internet Protocol Private Branch Exchange (VoIP PBX) systems, voicemail, and conferencing.Platform query
Sangoma Certified AsteriskSangoma Certified Asterisk is a specialized version of Asterisk designed for enterprise environments requiring high reliability and support.Platform query
Sangoma FreePBXFreePBX is a web-based open-source GUI for controlling and managing Asterisk.Platform query
STARFACESTARFACE is a Session Initiation Protocol (SIP) trunking service and IP-based telephony solution.Platform query
Wildix Media GatewayWildix Media Gateway is a device that bridges traditional telephony lines (analog, PRI, BRI, GSM/LTE) with the Wildix VoIP PBX system.Platform query

New ASM risks

Name

Description

Query

Vulnerable Handlebars.js [CVE-2026-33937]

This service is using a version of Handlebars.js (4.0.0–4.7.8) vulnerable to CVE-2026-33937, a critical server-side remote code execution vulnerability. Handlebars.compile() emits the value field of a NumberLiteral AST node directly into generated JavaScript without sanitization. An attacker who controls the AST passed to compile() can inject and execute arbitrary JavaScript in any Node.js application that passes user-controlled input to compile().

ASM risk query:

risks.name: "Vulnerable Handlebars.js [CVE-2026-33937]"

Vulnerable FortiClient EMS [CVE-2026-35616]

This is an exposed FortiClient EMS instance prone to an improper access control vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

ASM risk query:

risks.name: "Vulnerable FortiClient EMS [CVE-2026-35616]"

Summary

  • Added 19 new fingerprints for SSL VPNs, operating systems, and several other products and services.

New fingerprints

Added the following fingerprints.

NameDescriptionQuery
ALEOSThis is an ALEOS operating system for Sierra Wireless devices.Platform query
Stormshield SSL VPNThis is a Stormshield SSL VPN server.Platform query
SonicWall Virtual OfficeThis is a SonicWall Virtual Office SSL VPN server.Platform query
SonicWALL ProThis is a SonicWALL Pro series firewall (covers Pro 100, Pro 200, and so on).Platform query
SonicWALL NSSPThis is a SonicWALL NSSP (Network Security Services Platform) device.Platform query
Leadsec SSL VPNThis is a Leadsec SSL VPN server.Platform query
KobzVPNThis is a KobzVPN server.Platform query
Juniper NSMThis is a Juniper NSM (Network and Security Manager) server, covering NSM3000 and NSM Express.Platform query
Huawei SSL VPNThis is a Huawei SSL VPN server.Platform query
DPtech SSL VPNThis is a DPtech SSL VPN server.Platform query
Citrix SD-WANThis is a Citrix SD-WAN server.Platform query
Citrix Access GatewayThis is a Citrix Access Gateway server.Platform query
Cisco StarOSThis is a Cisco StarOS utility server.Platform query
Cisco IOS XRThis is a Cisco IOS XR operating system, commonly found on routers.Platform query
Cisco Cloud Services Router 1000vThis is a Cisco Cloud Services Router 1000v.Platform query
Cisco AnyConnect Secure Mobility ClientThis is a Cisco AnyConnect Secure Mobility Client (SSL VPN) server.Platform query
Check Point SSL Network ExtenderThis is a Check Point SSL Network Extender server.Platform query
Check Point Harmony SASEThis is a Check Point Harmony SASE server.Platform query
Barracuda SSL VPNThis is a Barracuda SSL VPN server.Platform query

Summary

Platform

  • Run queries for trending security advisories published the Censys ARC team directly from the Platform home page.

    • ARC, Censys' cybersecurity research team, frequently releases new advisories and queries for trending security issues. These are shown in a carousel under the search bar. Use these queries to track important issues and learn how to build your own targeted searches. Most of these queries utilize data that is available to Free users, but sometimes they will use regex or other entitled fields.
  • You can now view interactive demos of data add-on modules in the Platform web console. Use the left navigation bar to view demos for the Adversary Investigation and Critical Infrastructure modules.

Adversary Investigation

  • Use new CensEye APIs to create pivot analysis jobs to find web infrastructure related to threats and other assets.
    • The new pivot analysis job endpoint extracts default pivot fields from the target asset and counts matching documents for each field-value pair. This is similar to using CensEye in the Platform web UI.
    • The other two new endpoints can be used to check job status and retrieve job results.

Rapid Response

The Censys ARC team published information about and queries for the following issue.

Summary

Platform

  • Use the new Censys for Splunk SOAR and Censys for Splunk Platform integrations to enhance your SOC workflows with Censys data enrichment and playbook actions.
    • These integrations include several ad hoc enrichment actions for hosts, web properties, and certificates that can be used on an ad hoc basis or used for automated enrichment.
    • Watch this video to learn more about how to use the Splunk SOAR application.
  • The name of the "Explore Threats" page in the Platform UI has been changed to "Tracked Threats."

Rapid Response

The Censys Rapid Response team published information about and queries for the following issue.

New fingerprints

Added the following fingerprints.

Note that new ASM risk fingerprints may be disabled by default in your workspace. Reference your risk type configuration in the ASM web console to review new risk types.

Type

Name

Description

Query

hardware

NetBox

NetBox is an open-source DCIM and IPAM tool for managing network infrastructure.

Platform query

risk

Exposed FortiAnalyzer Application

An HTTP service is exposing a Fortinet FortiAnalyzer application. FortiAnalyzer is a centralized logging and reporting solution that aggregates security and traffic data from FortiGate and other Fortinet devices. Exposing this management interface to the internet can allow unauthorized access to sensitive network and security analytics.

ASM risk query:

risks.name: "Exposed FortiAnalyzer Application"

risk

Exposed NetBox Application

A NetBox application is exposed to the internet. NetBox is a DCIM and IPAM tool that manages network infrastructure, IP allocations, and device inventories. Exposure may allow unauthorized access to sensitive network topology and infrastructure data.

ASM risk query:

risks.name: "Exposed NetBox Application"

Summary

New fingerprints

Added the following fingerprints.

TypeNameDescriptionQuery
softwareDatto RMMDatto RMM is a cloud-based tool used for remote monitoring and management (RMM).Platform query
softwareDatto SIRISDatto SIRIS is a business continuity and disaster recovery (BCDR) tool designed for MSPs.Platform query
softwareAteraAtera is an RMM tool.Platform query
softwareSimpleHelpSimpleHelp is an RMM tool.Platform query
softwareSplashtopSplashtop is an RMM tool.Platform query
softwareZoho AssistZoho Assist is an RMM tool.Platform query

New protocols and application scanners

Added support for the following protocols and applications.

Protocol/applicationQueryData availability
ANERMA_CF_FORTHPlatform queryData is only visible and searchable to users with access to the Critical Infrastructure module.
ICAPPlatform queryData is visible to and searchable by Starter, Core, and Enterprise users.
STUNPlatform queryData is visible to Starter users and is visible to and searchable by Core and Enterprise users.

Summary

Platform

  • Users with access to the Critical Infrastructure module can use the new Critical Infrastructure dashboard to quickly pivot through a filterable view of ICS/OT assets and data identified by Censys scans.

    • Use the dashboard to find assets of interest based on location, vendor, product name, protocol, text extracted from screenshots, and more. Learn more in the documentation.
  • Use new integrations to add Censys data enrichment to hosts, domains, certificates, and more to OpenCTI and CyWare.

    • These integrations were developed and are maintained by OpenCTI and CyWare, respectively.
  • Leverage the new get service history for a host API endpoint to retrieve time ranges during which services were detected on the host.

  • Use new extracted_text data on services and endpoints to find assets with screenshots that include keywords like vendor or product names, login interfaces, and more. This data can be found in the following new fields:

    • host.services.screenshots.extracted_text
    • host.services.endpoints.screenshots.extracted_text
    • web.endpoints.screenshots.extracted_text
    • extracted_text data is only available to users on the Core or Enterprise plans.

New fingerprints

Added the following fingerprints.

Note that new ASM risk fingerprints may be disabled by default in your workspace. Reference your risk type configuration in the ASM web console to review new risk types.

Type

Name

Description

Query

risk

Exposed Fast Reverse Proxy (FRP) Server

An exposed Fast Reverse Proxy (FRP) server dashboard has been detected. FRP is an open-source reverse proxy tool that allows users to expose internal services through NAT or firewalls to the internet without authorization. When deployed without IT approval, FRP constitutes shadow IT and creates significant security risks: it bypasses firewall controls, exposes internal services without proper security review, and has been observed being used by threat actors as a command-and-control tunneling mechanism.

ASM query:

risks.name: `Exposed Fast Reverse Proxy (FRP) Server`

risk

Exposed Gogs Application

This is an exposed HTTP service running Gogs. This self-hosted Git service often contains source code repositories, user credentials, and CI/CD configurations. The sensitive nature of the information contained in this application makes it a target.

ASM query:

risks.name: `Exposed Gogs Application`

risk

Exposed Gitea Application

This is an exposed HTTP service running Gitea. This self-hosted Git service often contains source code repositories, user credentials, and CI/CD configurations. The sensitive nature of the information contained in this application makes it a target.

ASM query:

risks.name: `Exposed Gitea Application`

risk

Exposed Nagios Fusion Application

A Nagios Fusion application is exposed to the internet. Nagios Fusion is a multi-server management platform that provides a unified view of monitoring servers. Exposure may allow unauthorized access to centralized monitoring management.

ASM query:

risks.name: `Exposed Nagios Fusion Application`

risk

Exposed Nagios Log Server Application

A Nagios Log Server application is exposed to the internet. Nagios Log Server is a centralized log management platform that can contain sensitive operational data. Exposure may allow unauthorized access to log data.

ASM query:

risks.name: `Exposed Nagios Log Server Application`

risk

Exposed Nagios Network Analyzer Application

A Nagios Network Analyzer application is exposed to the internet. Nagios Network Analyzer is a netflow and bandwidth monitoring tool that provides network traffic visibility. Exposure may allow unauthorized access to network analytics.

ASM query:

risks.name: `Exposed Nagios Network Analyzer Application`

risk

Exposed Nagios Core Application

A Nagios Core application is exposed to the internet. Nagios Core is an open-source monitoring platform that provides infrastructure monitoring and alerting. Exposure may allow unauthorized access to monitoring data.

ASM query:

risks.name: `Exposed Nagios Core Application`

risk

Exposed Nagios Cross Platform Agent Application

A Nagios Cross Platform Agent (NCPA) application is exposed to the internet. Nagios Cross Platform Agent (NCPA) is a cross-platform monitoring agent that provides system metrics and remote management capabilities. Exposure may allow unauthorized access to system metrics and agent management.

ASM query:

risks.name: `Exposed Nagios Cross Platform Agent Application`

risk

Exposed Nagios XI Application

A Nagios XI application is exposed to the internet. Nagios XI is an enterprise monitoring platform that provides infrastructure visibility and alerting. Exposure may allow unauthorized access to monitoring data and system management.

ASM query:

risks.name: `Exposed Nagios XI Application`

software

N-able Take Control

N-able Take Control is a remote support solution that can give users access to Windows, Mac, Linux, and mobile devices.

Platform query

software

GrowthBook

GrowthBook is the an open-source platform for feature flagging and experimentation.

Platform query

hardware

Coslat Firewall

This is a Coslat Firewall instance.

Platform query

software

Blackboard Transact Suite

Blackboard Transact Suite is a cloud-based campus management solution used in higher education for integrated payments, security, and commerce.

Platform query

software

Zoho Meeting

Zoho Meeting is an online meeting platform.

Platform query

software

RAGFlow

RAGflow is an open-source Retrieval-Augmented Generation (RAG) engine.

Platform query

software

Cisco Catalyst SD-WAN Manager

This is a Cisco Catalyst SD-WAN Manager server.

Platform query

software

Nagios Log Server

This is a Nagios Log Server for centralized log management.

Platform query

software

Nagios NCPA

This is a Nagios Cross-Platform Agent (NCPA) web interface.

Platform query

software

Nagios Fusion

This is a Nagios Fusion monitoring dashboard.

Platform query

software

Nagios Network Analyzer

This is a Nagios Network Analyzer for netflow analysis and bandwidth monitoring.

Platform query

software

Raspberry Shake

Raspberry Shake is a low-cost, professional-grade personal seismograph that pairs with a Raspberry Pi computer to detect ground vibrations, including earthquakes, volcanic activity, and human-made noise.

Platform query

software

Remotely Admin Console

Remotely is an open-source, self-hosted remote control and management solution built with .NET 8, Blazor, and SignalR, designed as a TeamViewer alternative.

Platform query

software

Neo4j Graph Database

Neo4j is a graph database management system detected via HTTP API JSON response.

Platform query

Summary

Platform UI updates

The Censys Platform web UI has been updated to make the search bar the focus on the home page and improve navigation.

Left-side navigation panel

  • The organization you are currently logged into is displayed in the top of the left-side nav bar. Switch to your Free account or another organization and access your organizational and personal settings from the organization drop-down.
    • Open the account selector menu, select your account or organization, and click the credits section to go to the Credit Management page.
  • Access to search and the dashboards for the Threat Hunting and Critical Infrastructure modules is now located in the Intelligence section of the left-side nav bar.
  • The My Work section contains your collections, a link to the Investigation Manager, and your search history.
  • The Resources section includes links to the Release Notes feed, the Censys Community. Additional resources like the Censys Academy and Data Definitions are nested under Learn in this section.

Alerts and Notifications

  • Access webhook configuration by clicking the bell icon for Alerts and Notifications in the top-right corner.

Personal Access Tokens, account management, and more

  • Create and manage Personal Access Tokens (PATs), manage your account, and switch between light and dark mode using the profile menu in the top right corner.

Platform Search History page

New protocols and application scanners

Added support for the following protocol.

Protocol/applicationQueryData availability
GEMINIPlatform queryVisible and searchable to all user tiers.

New fingerprints

Added the following fingerprints.

Note that new ASM risk fingerprints may be disabled by default in your workspace. Reference your risk type configuration in the ASM web console to review new risk types.

Type

Name

Description

Query

risk

Exposed Ollama Application

An exposed Ollama server. This application allows users to run and manage large language models (LLMs) locally. Exposing this service to the public internet can allow unauthorized access to AI models and computational resources.

ASM query:

risks.name: "Exposed Ollama Application"

hardware

TiVo DVR

This is a TiVo digital video recorder (DVR).

Platform query

software

Gitea

Gitea is a self-hosted Git service.

Platform query

software

Gogs

Gogs is a self-hosted Git service.

Platform query

Rapid Response

The Censys Rapid Response team published information about and queries for the following issue.

As part of the plan to decommission Legacy Search (search.censys.io) in 2026, Censys will update its host data backend on March 31, 2026. In Legacy Search, this will result in changes to virtual host behavior, data freshness, select API fields, and other minor adjustments. These changes are described in detail below.

These changes do not remove host coverage from Legacy Search. Additionally, this change does not affect Platform (platform.censys.io) data or functionality.

Overall host coverage, scan cadence, historical data retention, existing functionality, query syntax, UI workflows, and entitlements in Legacy Search are not impacted.

Virtual hosts

The table below summarizes key changes to virtual host data after the change.

AreaBeforeAfterImpact
Virtual host definitionOne per each hostname and IP addressBased on latest scanned IP per portIncreased historical view of data
Service persistenceUp to 45 daysRemoved on next negative scan14-day expiry, yielding less stale data
IP associationServices persisted across IPsServices move scan IPsData “may” move between IPs
DuplicationCommonReducedMore accurate representation of web assets

Data freshness

  • Expiration is changing to 14 days (previously 45 days).
  • Index updates will occur only when a scan for that IP is received.
  • The "See Latest" UI indication may appear more often.
  • In general, there will be less long-lived stale data.

API and service lifecycle changes

  • Timeline API: Forward pagination will be removed. API users must set reversed=true.
  • Service lifecycle: Services pending removal will be immediately removed from assets when a scan indicates they are no longer visible, instead of being marked as pending.

Removed fields

The following fields will be removed from Legacy Search:

  • services.parsed.rocketmq.version (RocketMQ)
  • services.ipp.response (IPP)
  • services.ipp.cups_response (IPP)
  • services.elasticsearch.http_info (Elasticsearch)
  • services.tls.server_key_exchange (TLS)
  • services.prometheus.http_info (Prometheus)
  • services.transport_fingerprint.* (Transport)

DNS records

  • dns.records.record_type will no longer return CNAME.
  • Record types will be limited to A and AAAA only.

Certificate API update frequency

The update frequency for the following APIs will change from realtime to every six hours:

  • /v2/hosts/{ip}/certificates
  • /v2/certificates/{fingerprint}/observations

We encourage you to review your workflows and integrations to prepare for these upcoming changes. If you have any questions or concerns about this transition, please reach out to our team at [email protected].

Summary

New protocols and application scanners

Added support for the following protocols and applications.

Protocol/applicationQueryData availability
CISCO_NSIPlatform queryData is only visible to and searchable by Core and Enterprise users.
FLASH_SOCKET_POLICYPlatform queryData is only visible to and searchable by Core and Enterprise users.
MELSECPlatform queryData is only visible to and searchable by users with access to the Critical Infrastructure module.
MEMBERLISTPlatform queryData is only visible to and searchable by Core and Enterprise users.
ROUTEROS_APIPlatform queryData is only visible to and searchable by Core and Enterprise users.
RUSTDESK_HEARTBEATPlatform queryVisible to and searchable by all user tiers.
RUSTDESK_RELAYPlatform queryVisible to and searchable by all user tiers.
RUSTDESK_RENDEZVOUSPlatform queryVisible to and searchable by all user tiers.

New fingerprints

Added the following fingerprint.

Note that new ASM risk fingerprints may be disabled by default in your workspace. Reference your risk type configuration in the ASM web console to review new risk types.

Type

Name

Description

Query

risk

Exposed NextGen Healthcare Mirth Connect

A NextGen Healthcare Mirth Connect administrator interface is exposed to the internet. Mirth Connect is healthcare integration software that processes and transforms medical data. Exposure may allow unauthorized access to sensitive health information.

ASM query:

risks.name: "Exposed NextGen Healthcare Mirth Connect"

Summary

Platform

  • To improve usability, when web properties have multiple endpoints they are now collected on a single hostname and port card instead of split across multiple cards.

  • Redirect chains are now shown on host service and web endpoint cards.

New fingerprints

Added the following fingerprints.

TypeNameDescriptionQuery
operating_systemApple macOSThis is a device running Apple macOS.Platform query
softwareFortinet FortiClient Endpoint Management ServerThis is a FortiClient Endpoint Management Server (EMS). EMS is a security management solution that enables scalable and centralized management of multiple endpoints.Platform query
softwareQuestDBThis is a QuestDB instance. QuestDB is an open-source time-series database.Platform query

Rapid Response

The Censys Rapid Response team published information about and queries for the following issue.