logo

A look at PolarEdge Adjacent Infrastructure

ID: 37ac720d-91a0-5d19-93a0-2d854d2b11ea

STIX ID: report--37ac720d-91a0-5d19-93a0-2d854d2b11ea

Feed Name: Censys Blog

Threat Score
25/100

Date Published: 2025-08-28

Date Updated: 2026-04-27

Author: Jean Pierre Ruiz Ocampo; The Censys Research Team

...
...

Censys ARC published a correction to prior PolarEdge research: the TLS certificate previously associated with PolarEdge also exists in older Mbed TLS (PolarSSL) releases, reducing confidence that the RPX server analyzed is uniquely tied to the actor. The team concludes the actor likely leverages known, exposed certificates to avoid unique fingerprints and that the RPX host was probably attacker infrastructure or a relay; the update emphasizes transparency and reproducibility in their reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.