
Most organizations do not have a complete picture of what is reachable from the Internet. A router, a camera system, a data warehouse, a building access controller — any one of these could be answering requests from anywhere in the world right now, and your security team might not know. Attackers scan for these services systematically, every day.
Censys continuously maps the entire Internet. Each new scanner adds one more type of service to that map, so when it shows up on your attack surface, or a supplier’s, you know before an attacker does.
22 new protocol and endpoint scanners added in September

Six new scanners are spotlighted below. See the full list in our Release Notes.
Please Note: Common Deployment Sectors reflects typical industry use, not observed host data.
Cisco SD-WAN: 11,180 control planes reachable, org name included
Category: Networking Infrastructure
Common Deployment Sectors: Financial Services, Government, Telecom
vdaemon is the control-plane process behind Cisco’s SD-WAN Manager and Controller, which pushes routing and security policy to every branch office in a company’s network. Censys counts 11,180 of these services reachable from the Internet today, and an unauthenticated exchange with the service reveals the customer’s organization name, device identifier, and site ID before anyone has logged in.
CISA added exploited Cisco SD-WAN privilege escalation flaws to its Known Exploited Vulnerabilities catalog (Security Affairs), and Cisco Talos confirmed active exploitation of an authentication-bypass flaw in SD-WAN Manager and Controller (Talos Intelligence).
This is an active KEV entry with ongoing exploitation behind it. If you run Cisco SD-WAN, confirm your control planes aren’t reachable from the open Internet.
Platform Query: host.services.protocol:"CISCO_SDWAN_VDAEMON"
FSC3000: the controller deciding who can pump fuel
Category: Industrial Control Systems (ICS/OT)
Common Deployment Sectors: Retail, Critical Infrastructure
The FSC3000 authorizes fuel cards, drives the dispensers, and holds transaction and inventory totals at a fueling site. Its console banner discloses the site’s identity without a login, putting the system that decides who can pump fuel within reach of anyone scanning the Internet.
No active campaign has been tied to this exposure yet, but fuel infrastructure is a documented target for criminal and state-linked actors alike. If you operate fueling sites, confirm this controller isn’t reachable from the open Internet.
Platform Query: host.services.protocol:"OPW_FSC3000"
C-Nord: an alarm station that discloses who’s holding the keys
Category: IoT / Surveillance
Common Deployment Sectors: Government, Real Estate / Facilities
C-Nord’s security center is the central station alarm-monitoring companies use to track armed and disarmed status and intrusion events. An unauthenticated read from its inter-module bus can return live alarm status, event history, and in some cases a keyholder’s name, the kind of detail a monitoring station never meant to hand to a stranger.
There’s no known exploitation here yet, but a leaked keyholder name or arm/disarm status has obvious value to anyone casing a property. If you run or monitor alarm systems, this is worth checking regardless.
Platform Query: host.services.protocol:"CNORD_SECURITY_CENTER"
Hikvision DVR/NVR management: one daemon, an entire camera fleet
Category: IoT / Surveillance
Common Deployment Sectors: Retail, Real Estate / Facilities, Government
DNVRS-Webs is the management daemon Hikvision DVRs and NVRs use for remote configuration and video access. Hikvision’s device-management software has drawn serious findings in the last year, including a maximum-severity, unauthenticated remote code execution flaw in its HikCentral platform (Web Asha Technologies). Internet exposure puts a site’s entire camera fleet within reach of anyone scanning for it.
If this shows up in your footprint, confirm it isn’t reachable from the open Internet.
Platform Query: host.services.protocol:"HIKVISION_DNVRS"
STOMP: the messaging layer ransomware already knows how to exploit
Category: Enterprise IT & Communications Infrastructure
Common Deployment Sectors: Financial Services, Retail
STOMP is a text-based messaging protocol that brokers like Apache ActiveMQ and RabbitMQ use to move data between applications. These brokers have one of the most exploited track records in enterprise messaging software: CISA added an Apache ActiveMQ remote-code-execution flaw (CVE-2026-34197) to its Known Exploited Vulnerabilities catalog in April 2026 (BleepingComputer), and ransomware actors, including LockBit, have used earlier ActiveMQ flaws to gain RDP access and deploy ransomware (GBHackers). Apache disclosed a STOMP-specific denial-of-service flaw (CVE-2026-53916) in its security advisories this year.
If STOMP shows up in your footprint, confirm which broker is behind it and whether it’s patched. This protocol family has a multi-year history as a ransomware entry point.
Platform Query: host.services.protocol:"STOMP"
Pigeonhole: the engine that decides where your email goes
Category: Messaging Infrastructure
Common Deployment Sectors: Telecom, Higher Education
Pigeonhole is the mail-filtering engine that email providers and enterprises run to sort and route incoming messages. An Internet-facing instance gives an attacker a foothold into the infrastructure that decides where your email ends up.
Dovecot’s security team patched a crash-triggering bug in how Pigeonhole handles incoming mail-filter connections (Dovecot Security), and a later advisory fixed a stack buffer underflow in how Pigeonhole compiles submitted filter scripts (Full Disclosure).
If Pigeonhole shows up in your footprint, confirm it’s running a patched Dovecot release before exposing it further.
Platform Query: host.services.protocol:"PIGEONHOLE"
Check your attack surface
The full list of all 22 scanners is in our Release Notes. Run any of the queries above in the Censys Platform to see global exposure.

