logo

Internet Archaeology: A Decade of Defaced Routers?

ID: a83d33a6-7d6f-5c26-afc6-5d2041d32ec4

STIX ID: report--a83d33a6-7d6f-5c26-afc6-5d2041d32ec4

Feed Name: Censys Blog

Threat Score
45/100

Date Published: 2025-09-03

Date Updated: 2026-04-27

Author: Ivonne Francia; Emily Austin

...
...

This report examines ~330 Ubiquiti devices exhibiting persistent “HACKED-ROUTER-HELP” defacement banners (variants dating to 2016), links likely causes to default/weak/reused credentials and exploitation of an arbitrary file upload vulnerability associated with the MF worm/CVE-2015-9266, and maps affected hosts by service, country, and ASN; it also notes a 75% reduction in visible defacements from Jan 2022–Aug 2025 but highlights that several hundred potentially long-lived compromises—primarily on consumer/residential ISPs—remain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.