Who's Knocking on Your Door? An Analysis of Exposed Services and Their Risks
ID: badb8397-556b-54e7-9393-336d38185523
STIX ID: report--badb8397-556b-54e7-9393-336d38185523
Feed Name: Censys Blog
Date Published: 2025-11-07
Date Updated: 2026-04-27
Author: Jean Pierre Ruiz Ocampo; Jonas Gyllenhammar
This report analyzes automated internet scanning and exploitation of exposed services, showing concrete examples: SSH brute-force intrusions that install persistent keys and attempt environment fingerprinting, HTTP/HTTPS command-injection and remote code execution probes that stage Mirai-style ELF droppers, and out‑of‑band (OAST) blind-RCE tests via Java expression injection. The document includes observed IoCs (source and infrastructure IPs, malicious request patterns and payload URLs), measurements of time-to-first-probe, and a prioritized incident response and long-term mitigation plan (blocklists, hardening SSH/web apps, WAF tuning, egress restrictions, and continuous ASM).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
