September 8, 2026

Summary

  • Search results in the Platform web console now include an interactive world map showing the geographic distribution of hosts returned by your query.
  • Use the SentinelOne integration with the Censys Platform to bring Censys internet intelligence and Platform features to SentinelOne.
  • Added an ai label to ASM to surface AI-related assets.
  • Added nine new fingerprints to the Platform and five new risk fingerprints to ASM.

Platform

The new, interactive Host Distribution visualization.

  • When you search across hosts, a Host Distribution visualization is now shown at the top of the page. This map shows the geographic distribution of hosts returned by your search query.
    • Click Select Area to filter your results using the map.

A note containing Censys host enrichment added to a SentinelOne alert.

  • Use the new SentinelOne integration to:
    • Automatically or manually enrich IPs, web properties, and certificates in SentinelOne with Censys Platform data.
    • Initiate a Censys rescan of a host or web property.
    • Retrieve scan history for an IP address
    • Initiate a CensEye automated pivoting job to find assets related to an IP, web property, or certificate.
  • Host distribution visualization

ASM

  • Use the new ai label for host services and web entities to find exposed AI-related assets in your attack surface. This label includes services running the following:
    • Attu
    • AutoGPT
    • BentoML
    • Chat Nio
    • ChatGPT Next Web / NextChat
    • ChromaDB Admin
    • ClearML
    • ComfyUI
    • Dify
    • FastGPT
    • Flowise
    • Label Studio
    • Langflow
    • LibreChat
    • LiteLLM
    • MaxKB
    • MLflow
    • New API
    • Ollama
    • OpenClaw
    • One API
    • SillyTavern
    • Xinference

New fingerprints and risks

Added nine new fingerprints to the Platform and five new risk fingerprints to ASM.

Note that new ASM risk fingerprints may be disabled by default in your workspace. Reference your risk type configuration in the ASM web console to review new risk types.

New fingerprints

TypeNameDescriptionQuery
softwareIServIServ is a school and organization communication platform (mail, files, groupware).Platform query
softwareLiquidsoapAn Icecast input endpoint for the Liquidsoap streaming audio scripting language.Platform query
softwareSonicWall AnalyticsA centralized threat intelligence, management, and reporting engine designed to evaluate data collected across a network's firewall ecosystem.Platform query
softwareSonicWall AnalyzerA web-based traffic analytics and reporting software application designed to collect, monitor, and analyze log data and network traffic from SonicWall firewalls, secure remote access solutions, and backup products.Platform query
softwareSonicWall Global Management SystemA centralized management and reporting software solution used to monitor, configure, and manage multiple SonicWall security appliances from a single console.Platform query
hardwareZbtlink MQWrt RouterA networking device made by Shenzhen Zhibotong Electronics (operating as Zbtlink) that runs a custom, OpenWrt-based firmware known as MQWrt.Platform query
softwareDinkyA real-time data development platform for Apache Flink.Platform query
softwareRabbitMQManagement plugin UI for RabbitMQ, an open-source message broker.Platform query
softwareZimbra CollaborationAn email, calendar, and collaboration software system designed for enterprises.Platform query

New risks

NameDescriptionQuery
End-of-Life SonicWall Global Management SystemThis host runs SonicWall Global Management System (GMS), which SonicWall has declared end of life. Last Day of Order was 2025-10-01 and End of Support is 2026-09-30; the product is superseded by Network Security Manager (NSM). GMS is the management plane for an entire SonicWall firewall estate.
risks.name:`End-of-Life SonicWall Global Management System`
End-of-Life SonicWall AnalyzerThis host runs SonicWall Analyzer, which reached End of Support on 2020-04-24. It was superseded by SonicWall Analytics and ultimately by Network Security Manager (NSM). SonicWall no longer publishes documentation or updates for it.
risks.name:`End-of-Life SonicWall Analyzer`
End-of-Life SonicWall AnalyticsThis host runs SonicWall Analytics On-Prem, which SonicWall announced end of life on 2025-12-04. Last Order Day was 2026-01-31 and End of Support is 2028-01-31; the product is superseded by Network Security Manager (NSM).
risks.name:`End-of-Life SonicWall Analytics`
Vulnerable Cacti Server [CVE-2026-40079]Cacti 1.2.30 or prior is vulnerable to CVE-2026-40079, a command injection in lib/rrd.php. The escape_command() function is a no-op that returns its argument unchanged, so the command line built by rrdtool_function_graph() reaches shell_exec() unescaped; text_format values from graph templates, which may carry host variable substitutions, are the injection vector. Fixed in 1.2.31.
risks.name:`Vulnerable Cacti Server [CVE-2026-40079]`
Vulnerable Zimbra Collaboration Server [CVE-2026-73570]This Zimbra Collaboration server is running a version affected by CVE-2026-73570. An unauthenticated attacker can inject a forged record into the MTA log via SMTP command pipelining; zmswatch (Swatchdog) then interpolates the attacker-controlled service name unquoted into a Perl backtick, executing arbitrary commands as the zimbra user. Exploitation additionally requires the optional zimbra-snmp package to be installed with SNMP notifications enabled, which is not observable remotely, so this risk reflects the version only.
risks.name: `Vulnerable Zimbra Collaboration Server [CVE-2026-73570]`