# Latest Security Research

##### The Package That Never Shipped: Following a USPS Smishing Kit Through Censys DNS Data

##### MCP Servers on the Internet

##### Iran-Linked Operators Suspected in ATG Breaches

##### Password Manager Infrastructure in the Wild: Surveying Prevalence, Internet Footprint, and Exposure

##### The cPanel Situation Is…

##### Oluomo: Microsoft OAuth AiTM Phishing Using a Naturalization-Form Lure

##### Rhadamanthys and the Limits of Private Sector Operations

##### FTP Exposure Brief: Examining the 55-Year-Old Protocol Used by Millions

##### Iranian-Affiliated APT Targeting of Rockwell/Allen-Bradley PLCs

##### Hackers Are Attempting to Turn ComfyUI Servers Into a Cryptomining Proxy Botnet

##### Cutting Through the Noise: A Technique-Based Approach to Hunting Web-Delivered Malware

##### [April Fools] BrewJack: Censys Researchers Uncover First Malware Campaign Targeting IP over Avian Carriers

##### [April Fools] Introducing the Censys Host Feelings Score™

##### ICS & Iran, Part 2: Revisiting Exposure of Previously Targeted Devices

##### Under CTRL: Dissecting a Previously Undocumented Russian .Net Access Framework

Censys ARC threat and vulnerability research on adversary infrastructure, malware, exposures, and the trends shaping Internet visibility.
