October 5, 2026
about 1 hour ago
Summary
- Role-based access control for the Platform has been redesigned and features Platform- and module-specific roles so you can more effectively manage the resources that your organization users have access to.
- Added service accounts to the Platform to enable you to connect applications with Platform APIs without using a personal user account.
- The AI investigations feature in the Platform Adversary Investigation module is now generally available.
- Use six new API endpoints to start, monitor, and retrieve the results of an AI investigation.
- Added three new fingerprints to the Platform and one new risk fingerprint to ASM.
- Two new Censys ARC Rapid Response advisories for Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution [CVE-2026-88771, CVE-2026-88772] and Fortinet FortiMail Path Traversal Vulnerability [CVE-2026-10426].
Platform
- Role-based access control for the Platform has been redesigned and features Platform- and module-specific roles so you can more effectively manage the resources that your organization users have access to.
- Added service accounts to the Platform to enable you to connect applications with Platform APIs without using a personal user account.
Adversary Investigation module
- The AI investigations feature is now generally available.
- Use new API endpoints to programmatically initiate, monitor, and retrieve the results of an AI investigation. The following endpoints have been added:
API endpoint Description Investigations: Create file upload Prepare to upload a PDF, text file, or image for use in an investigation. This endpoint returns a URL for to upload the file to. Investigations: Create job Start an investigation from a set of indicators, a set of previously uploaded evidence files, or both. This endpoint returns a job_idthat you can poll to retrieve its status and results.Investigations: Get job results Download the ZIP archive that contains a completed AI investigation's report and evidence. Investigations: Get job status Retrieve the status of one AI investigation. Poll this endpoint until the investigation is completed, then download its report and evidence. Investigations: Get usage Retrieve your organization's investigation limit, current usage, and the number of remaining investigations. Investigations: List jobs List the AI investigations you have started.
New fingerprints and risks
Added three new fingerprints to the Platform and two new risk fingerprints to ASM.
Note that new ASM risk fingerprints may be disabled by default in your workspace. Reference your risk type configuration in the ASM web console to review new risk types.
New fingerprints
| Type | Name | Description | Query |
|---|---|---|---|
| software | ASUS Control Center | A centralized, web-based IT management and monitoring software designed for businesses to oversee multiple computers, servers, and workstations from a single platform. | Platform query |
| software | FileRun | A self-hosted, web-based file management, synchronization, and sharing platform. | Platform query |
| software | JFrog Artifactory | A universal binary repository manager that stores, organizes, and distributes software packages, container images, and AI/ML models across an organization's development pipeline. | Platform query |
New risks
| Name | Description | Query |
|---|---|---|
| Vulnerable MikroTik RouterOS [CVE-2026-67279, CVE-2026-86060, CVE-2026-67276] | This is a service running a version of MikroTik RouterOS vulnerable to three unauthenticated SSH issues fixed together: CVE-2026-67279 (RouterOS enters the SSH connection protocol after a client rekey without authentication, letting an unauthenticated client write/overwrite files in the managed file namespace), CVE-2026-86060 (an argument-injection flaw in the SSH login helper allows changing the trusted policy mask, leading to privilege escalation), and CVE-2026-67276 (7.x only -- RSA public-key comparison omits the exponent, letting an attacker who knows an authorized key's modulus forge a valid signature with exponent 1 and open a session as that user). Fixed in 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). | |
Censys ARC Rapid Response
The Censys ARC team published information about the following issues.
- Sept 28 Advisory: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution [CVE-2026-88771, CVE-2026-88772]
- The following queries can be used to identify exposed instances. Not all of these services are necessarily vulnerable.
- Oct 2 Advisory: Fortinet FortiMail Path Traversal Vulnerability [CVE-2026-10426]
- The following queries can be used to identify exposed instances. Not all of these services are necessarily vulnerable.
