logo

Databases. EXPOSED! (Redis)

ID: ab80c34e-43b8-525d-9629-bc4f50b12adc

STIX ID: report--ab80c34e-43b8-525d-9629-bc4f50b12adc

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2022-09-19

Date Updated: 2026-04-27

...
...

*Executive summary:* Censys analyzed 350,675 Internet-accessible Redis services and found 39,405 (11%) unauthenticated instances, observed geographic and AS-level distributions of exposed data, and identified widespread attempts to exploit Redis's ability to write files (via CONFIG and SAVE) to drop malicious cronjobs and SSH keys; a one-time scan found the 'backup1' key on approximately 15,526 hosts (about 49% of sampled unauthenticated servers), indicating large-scale exploitation attempts though not confirming successful compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.