October 5, 2026

Summary

Platform

Adversary Investigation module

  • The AI investigations feature is now generally available.
  • Use new API endpoints to programmatically initiate, monitor, and retrieve the results of an AI investigation. The following endpoints have been added:
    API endpointDescription
    Investigations: Create file uploadPrepare to upload a PDF, text file, or image for use in an investigation. This endpoint returns a URL for to upload the file to.
    Investigations: Create jobStart an investigation from a set of indicators, a set of previously uploaded evidence files, or both. This endpoint returns a job_id that you can poll to retrieve its status and results.
    Investigations: Get job resultsDownload the ZIP archive that contains a completed AI investigation's report and evidence.
    Investigations: Get job statusRetrieve the status of one AI investigation. Poll this endpoint until the investigation is completed, then download its report and evidence.
    Investigations: Get usageRetrieve your organization's investigation limit, current usage, and the number of remaining investigations.
    Investigations: List jobsList the AI investigations you have started.

New fingerprints and risks

Added three new fingerprints to the Platform and two new risk fingerprints to ASM.

Note that new ASM risk fingerprints may be disabled by default in your workspace. Reference your risk type configuration in the ASM web console to review new risk types.

New fingerprints

TypeNameDescriptionQuery
softwareASUS Control CenterA centralized, web-based IT management and monitoring software designed for businesses to oversee multiple computers, servers, and workstations from a single platform.Platform query
softwareFileRunA self-hosted, web-based file management, synchronization, and sharing platform.Platform query
softwareJFrog ArtifactoryA universal binary repository manager that stores, organizes, and distributes software packages, container images, and AI/ML models across an organization's development pipeline.Platform query

New risks

NameDescriptionQuery
Vulnerable MikroTik RouterOS [CVE-2026-67279, CVE-2026-86060, CVE-2026-67276]This is a service running a version of MikroTik RouterOS vulnerable to three unauthenticated SSH issues fixed together: CVE-2026-67279 (RouterOS enters the SSH connection protocol after a client rekey without authentication, letting an unauthenticated client write/overwrite files in the managed file namespace), CVE-2026-86060 (an argument-injection flaw in the SSH login helper allows changing the trusted policy mask, leading to privilege escalation), and CVE-2026-67276 (7.x only -- RSA public-key comparison omits the exponent, letting an attacker who knows an authorized key's modulus forge a valid signature with exponent 1 and open a session as that user). Fixed in 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
risks.name: "Vulnerable MikroTik RouterOS [CVE-2026-67279, CVE-2026-86060, CVE-2026-67276]"

Censys ARC Rapid Response

The Censys ARC team published information about the following issues.