January 5, 2026

Summary

ASM

  • ASM users can now configure their AWS Cloud Connectors to ingest or exclude cloud resources from the ap-east-2, ap-southeast-7, and ap-southeast-6 regions.

Rapid Response

The Censys Rapid Response team published information about and queries for the following issue.

New fingerprints

Added the following fingerprints.

TypeNameDescriptionQuery
softwareHPE OneViewThis is an HPE OneView infrastructure management platform.Platform query
softwareHack the BoxThis is a Hack the Box service or endpoint.Platform query
riskUnauthenticated NATS ServiceA NATS messaging system is exposed without authentication. This allows unauthenticated clients to publish messages to subjects and subscribe to subjects to receive published messages, potentially exposing sensitive data or allowing unauthorized data manipulation.ASM risk query:
risks.name: `Unauthenticated NATS Service`
riskUnauthenticated ZeroMQ ServiceA ZeroMQ service is exposed without authentication. ZeroMQ services allow unauthenticated clients to connect and interact with the messaging system, which introduces a risk of unintended data exposure or manipulation.ASM risk query:
risks.name: `Unauthenticated ZeroMQ Service`
riskVulnerable SmarterMail [CVE-2025-52691]This SmarterMail server is running a build version vulnerable to CVE-2025-52691, an arbitrary file upload vulnerability that allows unauthenticated attackers to upload arbitrary files to any location on the mail server, potentially enabling remote code execution. Build versions 9406 and earlier are vulnerable.ASM risk query:
risks.name: `Vulnerable SmarterMail [CVE-2025-52691]`
riskExposed HPE OneViewAn HPE OneView infrastructure management application is exposed to the Internet.ASM risk query:
risks.name: `Exposed HPE OneView`