Skip to main content

Censys Release Notes for November 24, 2025

Related products:Censys SearchCensys Attack Surface Management (ASM)
  • November 24, 2025
  • 0 replies
  • 2 views

MattK_Censys
Forum|alt.badge.img+2

Summary

  • Added the ability to secure your Platform account with multi-factor authentication. Organization admins can enforce MFA for all members of their organization.
  • Use weekly collection digest emails to track changes to your saved Platform queries over time.
  • Two Rapid Response advisories for XWiki and FortiWeb issues.
  • Added fingerprints for Frigate NVR and XWiki and an ASM risk fingerprint for XWiki instances vulnerable to CVE-2025-24893.

Platform

  • You can now add another layer of security to your Platform account with multi-factor authentication (MFA) using an authenticator app.

    02884fd8fb3ff849a4e516f79476e7125271d1f3f03773bf11ae99b8fe76c5cd-mfa1.png
    • Configure your personal MFA settings in Settings > Account Management > Personal Settings > Security.
    • Organization admins can configure MFA enforcement for their organization in Settings > Account Management > Organization Settings > Security.
  • Use collection email notifications to receive weekly messages about updates to your collections. Emails are sent to the email address associated with your user account.

    8595af9f880a953bf25d6dd8ddd1b71e01acb31ab53ff7d14acee402e4ae9cfa-1.png

Rapid Response

The Censys Rapid Response team published information about and queries for the following issues.

New fingerprints

Added the following fingerprints.

Type Name Description Query
software Frigate NVR Frigate NVR system. Platform query
software XWiki This is an XWiki server. Platform query
risk Vulnerable XWiki [CVE-2025-24893] XWiki Platform is potentially vulnerable to an unauthenticated remote code execution flaw. If the SolrSearch macro is exposed, an unauthenticated attacker can inject a crafted request into the macro to achieve server-side code execution, which would allow full compromise of the XWiki instance. ASM query: risks.name: `Vulnerable XWiki [CVE-2025-24893]`