ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Censys is the authority for Internet intelligence and insights. Delivering the most complete, accurate, and up-to-date global map of Internet infrastructure, Censys provides industry leading solutions for attack surface management, threat hunting, and proactive cyber defense. Global governments, Fortune 500 companies, and security providers around the world trust Censys to uncover risks faster, respond more effectively, and prevent breaches before they happen.

Censys A.I CyberSecurity Scoring

Censys

Company Details

Linkedin ID:

censysio

Employees number:

155

Number of followers:

13,772

NAICS:

541514

Industry Type:

Computer and Network Security

Homepage:

www.censys.com

IP Addresses:

0

Company ID:

CEN_6052342

Scan Status:

In-progress

AI scoreCensys Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/censysio.jpeg
Censys Computer and Network Security
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreCensys Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/censysio.jpeg
Censys Computer and Network Security
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Censys Company CyberSecurity News & History

Past Incidents
2
Attack Types
2
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
AVTECH and HuaweiRansomware10056/2017
Rankiteo Explanation :
Attack threatening the organization’s existence

Description: The Murdoc Botnet, targeting AVTECH IP cameras and Huawei HG532 routers through vulnerabilities, including CVE-2024-7029 and CVE-2017-17215, has compromised devices mainly in Malaysia, Thailand, Mexico, and Indonesia to create a Mirai botnet variant. Over 1300 IPs have been affected, and with the discovery of over 100 servers distributing Mirai malware, the scale of the issue is significant. The botnet leverages command-line injection and GTFOBins to load, execute, and manage payloads, potentially leading to widespread disruption and unauthorized access across a multitude of IoT devices, threatening the integrity and security of impacted systems.

Wing FTP ServerVulnerability2516/2025
Rankiteo Explanation :
Attack without any consequences

Description: Threat actors are actively exploiting a recently fixed remote code execution vulnerability (CVE-2025-47812) in Wing FTP Server. The vulnerability allows attackers to inject arbitrary Lua code into user session files, potentially leading to total server compromise. Although the attack was spotted quickly and the machine isolated, the incident highlights the ongoing threat. Organizations are advised to update to version 7.4.4 to protect themselves.

AVTECH and Huawei
Ransomware
Severity: 100
Impact: 5
Seen: 6/2017
Blog:
Rankiteo Explanation
Attack threatening the organization’s existence

Description: The Murdoc Botnet, targeting AVTECH IP cameras and Huawei HG532 routers through vulnerabilities, including CVE-2024-7029 and CVE-2017-17215, has compromised devices mainly in Malaysia, Thailand, Mexico, and Indonesia to create a Mirai botnet variant. Over 1300 IPs have been affected, and with the discovery of over 100 servers distributing Mirai malware, the scale of the issue is significant. The botnet leverages command-line injection and GTFOBins to load, execute, and manage payloads, potentially leading to widespread disruption and unauthorized access across a multitude of IoT devices, threatening the integrity and security of impacted systems.

Wing FTP Server
Vulnerability
Severity: 25
Impact: 1
Seen: 6/2025
Blog:
Rankiteo Explanation
Attack without any consequences

Description: Threat actors are actively exploiting a recently fixed remote code execution vulnerability (CVE-2025-47812) in Wing FTP Server. The vulnerability allows attackers to inject arbitrary Lua code into user session files, potentially leading to total server compromise. Although the attack was spotted quickly and the machine isolated, the incident highlights the ongoing threat. Organizations are advised to update to version 7.4.4 to protect themselves.

Ailogo

Censys Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Censys

Incidents vs Computer and Network Security Industry Average (This Year)

Censys has 117.39% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

Censys has 56.25% more incidents than the average of all companies with at least one recorded incident.

Incident Types Censys vs Computer and Network Security Industry Avg (This Year)

Censys reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 1 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.

Incident History — Censys (X = Date, Y = Severity)

Censys cyber incidents detection timeline including parent company and subsidiaries

Censys Company Subsidiaries

SubsidiaryImage

Censys is the authority for Internet intelligence and insights. Delivering the most complete, accurate, and up-to-date global map of Internet infrastructure, Censys provides industry leading solutions for attack surface management, threat hunting, and proactive cyber defense. Global governments, Fortune 500 companies, and security providers around the world trust Censys to uncover risks faster, respond more effectively, and prevent breaches before they happen.

Loading...
similarCompanies

Censys Similar Companies

Palo Alto Networks

Palo Alto Networks, the global cybersecurity leader, is shaping the cloud-centric future with technology that is transforming the way people and organizations operate. Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. We help address the world's greatest s

CrowdStrike

CrowdStrike (Nasdaq: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data. Powered by the CrowdStrike Security Cloud and world-clas

newsone

Censys CyberSecurity News

October 17, 2025 07:00 AM
Looming threat after major F5 breach: hundreds of thousands of systems found exposed

Internet scanning services warn that hundreds of thousands of F5 systems are exposed online and may be vulnerable to compromise after the...

October 14, 2025 07:00 AM
Advanced search engine alchemy: Exposing hidden data with dorking, Shodan, and Censys

Master "Google Dorking" and advanced OSINT tools like Shodan and Censys to find hidden files, leaks, and key evidence for investigative...

October 09, 2025 07:00 AM
Why cybersecurity training isn’t enough to stop phishing hacks

New research from UC San Diego reveals that generic cybersecurity training often fails to capture people's attention.

September 28, 2025 07:00 AM
US Cybersecurity Alert: Federal Agencies Must Address China Zero-Day Vulnerabilities

US federal agencies face urgent warnings to tackle critical China-related zero-day vulnerabilities; learn how this cybersecurity threat...

September 27, 2025 07:00 AM
China-linked hackers exploit zero-day flaws, CISA warns of national security threat

Beijing [China] September 27 (ANI) The United States cybersecurity agency, “Cybersecurity and Infrastructure Security Agency” (CISA) has...

September 25, 2025 07:00 AM
Censys’ Silas Cutler on how adversaries chain vulns together for big attacks

Greg talks with Silas Cutler, principal security researcher at Census, how ransomware attackers chain together overlooked vulnerabilities,...

September 03, 2025 07:00 AM
Internet mapping and research outfit Censys reveals state-based abuse, harassment

Censys Inc, vendor of the popular Censys internet-mapping tool, has revealed that state-based actors are trying to abuse its services by...

August 27, 2025 07:00 AM
300k+ Plex Media Server instances still vulnerable to attack via CVE-2025-34158

Over 300000 internet-facing Plex Media Server instances are still vulnerable to attack via the critical CVE-2025-34158 vulnerability.

July 23, 2025 07:00 AM
Thousands of companies at risk from Microsoft Sharepoint security flaw

More than 10,000 organizations around the world are at risk from hackers after a serious security flaw was discovered in Microsoft's popular...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Censys CyberSecurity History Information

Official Website of Censys

The official website of Censys is www.censys.com.

Censys’s AI-Generated Cybersecurity Score

According to Rankiteo, Censys’s AI-generated cybersecurity score is 735, reflecting their Moderate security posture.

How many security badges does Censys’ have ?

According to Rankiteo, Censys currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Censys have SOC 2 Type 1 certification ?

According to Rankiteo, Censys is not certified under SOC 2 Type 1.

Does Censys have SOC 2 Type 2 certification ?

According to Rankiteo, Censys does not hold a SOC 2 Type 2 certification.

Does Censys comply with GDPR ?

According to Rankiteo, Censys is not listed as GDPR compliant.

Does Censys have PCI DSS certification ?

According to Rankiteo, Censys does not currently maintain PCI DSS compliance.

Does Censys comply with HIPAA ?

According to Rankiteo, Censys is not compliant with HIPAA regulations.

Does Censys have ISO 27001 certification ?

According to Rankiteo,Censys is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Censys

Censys operates primarily in the Computer and Network Security industry.

Number of Employees at Censys

Censys employs approximately 155 people worldwide.

Subsidiaries Owned by Censys

Censys presently has no subsidiaries across any sectors.

Censys’s LinkedIn Followers

Censys’s official LinkedIn profile has approximately 13,772 followers.

NAICS Classification of Censys

Censys is classified under the NAICS code 541514, which corresponds to Others.

Censys’s Presence on Crunchbase

Yes, Censys has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/censys.

Censys’s Presence on LinkedIn

Yes, Censys maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/censysio.

Cybersecurity Incidents Involving Censys

As of December 02, 2025, Rankiteo reports that Censys has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Censys has an estimated 2,876 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Censys ?

Incident Types: The types of cybersecurity incidents that have occurred include Vulnerability and Ransomware.

How does Censys detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with isolation of the affected machine, and remediation measures with update to wing ftp server v7.4.4..

Incident Details

Can you provide details on each incident ?

Incident : Botnet

Title: Murdoc Botnet Attack

Description: The Murdoc Botnet, targeting AVTECH IP cameras and Huawei HG532 routers through vulnerabilities, including CVE-2024-7029 and CVE-2017-17215, has compromised devices mainly in Malaysia, Thailand, Mexico, and Indonesia to create a Mirai botnet variant. Over 1300 IPs have been affected, and with the discovery of over 100 servers distributing Mirai malware, the scale of the issue is significant. The botnet leverages command-line injection and GTFOBins to load, execute, and manage payloads, potentially leading to widespread disruption and unauthorized access across a multitude of IoT devices, threatening the integrity and security of impacted systems.

Type: Botnet

Attack Vector: Vulnerability ExploitationCommand-line InjectionGTFOBins

Vulnerability Exploited: CVE-2024-7029CVE-2017-17215

Threat Actor: Murdoc Botnet

Motivation: Unauthorized Access and Disruption

Incident : Remote Code Execution

Title: Exploitation of CVE-2025-47812 in Wing FTP Server

Description: Threat actors are actively exploiting a recently fixed remote code execution vulnerability (CVE-2025-47812) in Wing FTP Server, which allows attackers to execute arbitrary system commands with the privileges of the FTP service.

Date Detected: 2025-07-01

Date Publicly Disclosed: 2025-06-30

Type: Remote Code Execution

Attack Vector: Exploitation of vulnerability CVE-2025-47812

Vulnerability Exploited: CVE-2025-47812

Motivation: Unauthorized access and control

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Ransomware.

How does the company identify the attack vectors used in incidents ?

Identification of Attack Vectors: The company identifies the attack vectors used in incidents through CVE-2024-7029CVE-2017-17215 and Anonymous FTP accounts or compromised credentials.

Impact of the Incidents

What was the impact of each incident ?

Incident : Botnet CEN001013025

Data Compromised: IoT Device Data

Systems Affected: AVTECH IP camerasHuawei HG532 routers

Operational Impact: Widespread Disruption

Incident : Remote Code Execution CEN429071125

Systems Affected: Wing FTP Server

Which entities were affected by each incident ?

Incident : Botnet CEN001013025

Entity Type: IoT Devices

Location: MalaysiaThailandMexicoIndonesia

Incident : Remote Code Execution CEN429071125

Entity Type: Businesses, MSPs, Hosting Providers

Industry: Various

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Remote Code Execution CEN429071125

Containment Measures: Isolation of the affected machine

Remediation Measures: Update to Wing FTP Server v7.4.4

Data Breach Information

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Update to Wing FTP Server v7.4.4.

How does the company handle incidents involving personally identifiable information (PII) ?

Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by isolation of the affected machine.

Lessons Learned and Recommendations

What lessons were learned from each incident ?

Incident : Remote Code Execution CEN429071125

Lessons Learned: Ensure timely updates and patches to software, monitor suspicious activities

What recommendations were made to prevent future incidents ?

Incident : Remote Code Execution CEN429071125

Recommendations: Update to Wing FTP Server v7.4.4, monitor for suspicious activities, and implement robust security measures

What are the key lessons learned from past incidents ?

Key Lessons Learned: The key lessons learned from past incidents are Ensure timely updates and patches to software, monitor suspicious activities.

What recommendations has the company implemented to improve cybersecurity ?

Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: Update to Wing FTP Server v7.4.4, monitor for suspicious activities and and implement robust security measures.

References

Where can I find more information about each incident ?

Incident : Remote Code Execution CEN429071125

Source: Huntress researchers

Date Accessed: 2025-07-08

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Huntress researchersDate Accessed: 2025-07-08.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Remote Code Execution CEN429071125

Investigation Status: Ongoing

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : Botnet CEN001013025

Entry Point: Cve-2024-7029, Cve-2017-17215,

Incident : Remote Code Execution CEN429071125

Entry Point: Anonymous FTP accounts or compromised credentials

Backdoors Established: New users created for persistence

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Remote Code Execution CEN429071125

Root Causes: Exploitation of CVE-2025-47812 due to mishandling of null bytes in user and admin web interfaces

Corrective Actions: Update to Wing FTP Server v7.4.4, enhance monitoring and security measures

What corrective actions has the company taken based on post-incident analysis ?

Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Update to Wing FTP Server v7.4.4, enhance monitoring and security measures.

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an Murdoc Botnet.

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2025-07-01.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-06-30.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident was IoT Device Data.

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was AVTECH IP camerasHuawei HG532 routers and .

Response to the Incidents

What containment measures were taken in the most recent incident ?

Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Isolation of the affected machine.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach was IoT Device Data.

Lessons Learned and Recommendations

What was the most significant lesson learned from past incidents ?

Most Significant Lesson Learned: The most significant lesson learned from past incidents was Ensure timely updates and patches to software, monitor suspicious activities.

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Update to Wing FTP Server v7.4.4, monitor for suspicious activities and and implement robust security measures.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is Huntress researchers.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.

Initial Access Broker

What was the most recent entry point used by an initial access broker ?

Most Recent Entry Point: The most recent entry point used by an initial access broker was an Anonymous FTP accounts or compromised credentials.

cve

Latest Global CVEs (Not Company-Specific)

Description

A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipulation of the argument First Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 3.3
Severity: LOW
AV:N/AC:L/Au:M/C:N/I:P/A:N
cvss3
Base: 2.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 4.8
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the default configuration of this MCP server at the affected version (as of commit 2f3a5512 in September of 2025).

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security flaw has been discovered in Qualitor 8.20/8.24. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing manipulation of the argument passageiros results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 6.5
Severity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=censysio' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge