Company Details
censysio
155
13,772
541514
www.censys.com
0
CEN_6052342
In-progress

Censys Company CyberSecurity Posture
www.censys.comCensys is the authority for Internet intelligence and insights. Delivering the most complete, accurate, and up-to-date global map of Internet infrastructure, Censys provides industry leading solutions for attack surface management, threat hunting, and proactive cyber defense. Global governments, Fortune 500 companies, and security providers around the world trust Censys to uncover risks faster, respond more effectively, and prevent breaches before they happen.
Company Details
censysio
155
13,772
541514
www.censys.com
0
CEN_6052342
In-progress
Between 700 and 749

Censys Global Score (TPRM)XXXX

Description: The Murdoc Botnet, targeting AVTECH IP cameras and Huawei HG532 routers through vulnerabilities, including CVE-2024-7029 and CVE-2017-17215, has compromised devices mainly in Malaysia, Thailand, Mexico, and Indonesia to create a Mirai botnet variant. Over 1300 IPs have been affected, and with the discovery of over 100 servers distributing Mirai malware, the scale of the issue is significant. The botnet leverages command-line injection and GTFOBins to load, execute, and manage payloads, potentially leading to widespread disruption and unauthorized access across a multitude of IoT devices, threatening the integrity and security of impacted systems.
Description: Threat actors are actively exploiting a recently fixed remote code execution vulnerability (CVE-2025-47812) in Wing FTP Server. The vulnerability allows attackers to inject arbitrary Lua code into user session files, potentially leading to total server compromise. Although the attack was spotted quickly and the machine isolated, the incident highlights the ongoing threat. Organizations are advised to update to version 7.4.4 to protect themselves.


Censys has 117.39% more incidents than the average of same-industry companies with at least one recorded incident.
Censys has 56.25% more incidents than the average of all companies with at least one recorded incident.
Censys reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 1 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.
Censys cyber incidents detection timeline including parent company and subsidiaries

Censys is the authority for Internet intelligence and insights. Delivering the most complete, accurate, and up-to-date global map of Internet infrastructure, Censys provides industry leading solutions for attack surface management, threat hunting, and proactive cyber defense. Global governments, Fortune 500 companies, and security providers around the world trust Censys to uncover risks faster, respond more effectively, and prevent breaches before they happen.

Palo Alto Networks, the global cybersecurity leader, is shaping the cloud-centric future with technology that is transforming the way people and organizations operate. Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. We help address the world's greatest s

CrowdStrike (Nasdaq: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data. Powered by the CrowdStrike Security Cloud and world-clas
.png)
Internet scanning services warn that hundreds of thousands of F5 systems are exposed online and may be vulnerable to compromise after the...
Master "Google Dorking" and advanced OSINT tools like Shodan and Censys to find hidden files, leaks, and key evidence for investigative...
New research from UC San Diego reveals that generic cybersecurity training often fails to capture people's attention.
US federal agencies face urgent warnings to tackle critical China-related zero-day vulnerabilities; learn how this cybersecurity threat...
Beijing [China] September 27 (ANI) The United States cybersecurity agency, “Cybersecurity and Infrastructure Security Agency” (CISA) has...
Greg talks with Silas Cutler, principal security researcher at Census, how ransomware attackers chain together overlooked vulnerabilities,...
Censys Inc, vendor of the popular Censys internet-mapping tool, has revealed that state-based actors are trying to abuse its services by...
Over 300000 internet-facing Plex Media Server instances are still vulnerable to attack via the critical CVE-2025-34158 vulnerability.
More than 10,000 organizations around the world are at risk from hackers after a serious security flaw was discovered in Microsoft's popular...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Censys is www.censys.com.
According to Rankiteo, Censys’s AI-generated cybersecurity score is 735, reflecting their Moderate security posture.
According to Rankiteo, Censys currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Censys is not certified under SOC 2 Type 1.
According to Rankiteo, Censys does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Censys is not listed as GDPR compliant.
According to Rankiteo, Censys does not currently maintain PCI DSS compliance.
According to Rankiteo, Censys is not compliant with HIPAA regulations.
According to Rankiteo,Censys is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Censys operates primarily in the Computer and Network Security industry.
Censys employs approximately 155 people worldwide.
Censys presently has no subsidiaries across any sectors.
Censys’s official LinkedIn profile has approximately 13,772 followers.
Censys is classified under the NAICS code 541514, which corresponds to Others.
Yes, Censys has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/censys.
Yes, Censys maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/censysio.
As of December 02, 2025, Rankiteo reports that Censys has experienced 2 cybersecurity incidents.
Censys has an estimated 2,876 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Vulnerability and Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with isolation of the affected machine, and remediation measures with update to wing ftp server v7.4.4..
Title: Murdoc Botnet Attack
Description: The Murdoc Botnet, targeting AVTECH IP cameras and Huawei HG532 routers through vulnerabilities, including CVE-2024-7029 and CVE-2017-17215, has compromised devices mainly in Malaysia, Thailand, Mexico, and Indonesia to create a Mirai botnet variant. Over 1300 IPs have been affected, and with the discovery of over 100 servers distributing Mirai malware, the scale of the issue is significant. The botnet leverages command-line injection and GTFOBins to load, execute, and manage payloads, potentially leading to widespread disruption and unauthorized access across a multitude of IoT devices, threatening the integrity and security of impacted systems.
Type: Botnet
Attack Vector: Vulnerability ExploitationCommand-line InjectionGTFOBins
Vulnerability Exploited: CVE-2024-7029CVE-2017-17215
Threat Actor: Murdoc Botnet
Motivation: Unauthorized Access and Disruption
Title: Exploitation of CVE-2025-47812 in Wing FTP Server
Description: Threat actors are actively exploiting a recently fixed remote code execution vulnerability (CVE-2025-47812) in Wing FTP Server, which allows attackers to execute arbitrary system commands with the privileges of the FTP service.
Date Detected: 2025-07-01
Date Publicly Disclosed: 2025-06-30
Type: Remote Code Execution
Attack Vector: Exploitation of vulnerability CVE-2025-47812
Vulnerability Exploited: CVE-2025-47812
Motivation: Unauthorized access and control
Common Attack Types: The most common types of attacks the company has faced is Ransomware.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through CVE-2024-7029CVE-2017-17215 and Anonymous FTP accounts or compromised credentials.

Data Compromised: IoT Device Data
Systems Affected: AVTECH IP camerasHuawei HG532 routers
Operational Impact: Widespread Disruption

Systems Affected: Wing FTP Server

Entity Type: Businesses, MSPs, Hosting Providers
Industry: Various

Containment Measures: Isolation of the affected machine
Remediation Measures: Update to Wing FTP Server v7.4.4
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Update to Wing FTP Server v7.4.4.
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by isolation of the affected machine.

Lessons Learned: Ensure timely updates and patches to software, monitor suspicious activities

Recommendations: Update to Wing FTP Server v7.4.4, monitor for suspicious activities, and implement robust security measures
Key Lessons Learned: The key lessons learned from past incidents are Ensure timely updates and patches to software, monitor suspicious activities.
Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: Update to Wing FTP Server v7.4.4, monitor for suspicious activities and and implement robust security measures.
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Huntress researchersDate Accessed: 2025-07-08.

Investigation Status: Ongoing

Entry Point: Cve-2024-7029, Cve-2017-17215,

Entry Point: Anonymous FTP accounts or compromised credentials
Backdoors Established: New users created for persistence

Root Causes: Exploitation of CVE-2025-47812 due to mishandling of null bytes in user and admin web interfaces
Corrective Actions: Update to Wing FTP Server v7.4.4, enhance monitoring and security measures
Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Update to Wing FTP Server v7.4.4, enhance monitoring and security measures.
Last Attacking Group: The attacking group in the last incident was an Murdoc Botnet.
Most Recent Incident Detected: The most recent incident detected was on 2025-07-01.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-06-30.
Most Significant Data Compromised: The most significant data compromised in an incident was IoT Device Data.
Most Significant System Affected: The most significant system affected in an incident was AVTECH IP camerasHuawei HG532 routers and .
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Isolation of the affected machine.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach was IoT Device Data.
Most Significant Lesson Learned: The most significant lesson learned from past incidents was Ensure timely updates and patches to software, monitor suspicious activities.
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Update to Wing FTP Server v7.4.4, monitor for suspicious activities and and implement robust security measures.
Most Recent Source: The most recent source of information about an incident is Huntress researchers.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Anonymous FTP accounts or compromised credentials.
.png)
A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipulation of the argument First Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the default configuration of this MCP server at the affected version (as of commit 2f3a5512 in September of 2025).
A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
A security flaw has been discovered in Qualitor 8.20/8.24. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing manipulation of the argument passageiros results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.