In episode 5 of Censys ARC Flash, Silas Cutler and Martijn Grooten discuss new MikroTik RouterOS vulnerabilities, NPS and the challenge of distinguishing legitimate infrastructure from threat activity, and how AI can turn seemingly ordinary Internet-connected cameras into useful intelligence sources.
Silas Cutler (00:07)
Thanks for joining. Hi, my name is Silas Cutler and I’m the host for today’s ARC Flash. Today I am joined by Martijn and Himaja. We have a lot of content to get through, but today I’m gonna kick it off by passing it over to Himaja, actually in preparation for the State of the Internet Report that we’ve been working on. Over to you.
Himaja Motheram (00:25)
Hello, Internet. Yes, my name is Himaja, and I’m a senior security researcher at Censys. And every year, what Censys does is we publish our annual State of the Internet Report, or SOTIR for abbreviations, and what this report does is it’s really where we take out our big telescope and we look at all of the data that we collect historically across the entire Internet, across all ports. And we answer some of the most ambitious research questions that we have all year. We look at really what are the broad trends and shapes of how the Internet is changing year over year and what continues to be something that we need to worry about and what is newly emerging in our scans that is new to worry about, and kind of taking that really big picture look at what is on the attack surface of the Internet.
And so in previous years, we’ve usually gone kind of very broad into one or two topics. This year is our probably biggest and most ambitious report. We actually designed this version of the report to be repeatable year over year. So we’re benchmarking security in various areas. and we’re we’re trying to look at like where is the needle actually moving? Like, are we getting better? Are we getting worse?
Himaja Motheram (01:45)
As a way to sort of escape this whole like hype cycle and news cycle where we’re looking at security stories like on the order of weeks or months. We’re taking a look at over two years of data in this report. It’s the most we’ve ever looked at, and we found some really interesting stuff. We look at why certain populations on the Internet, like industrial control systems, seem to not really be moving in exposure over years and years and years. And meanwhile, we see infrastructure related to AI and LLMs and and sort of the the orchestration layer of that infrastructure, you know, growing by two thirds in only nine months. So we’re seeing very different things across different parts of the Internet and it’s a very volatile place. So I highly recommend the report. It comes out on October 6th. It’s gonna be really good and I highly recommend pre registering so that you get it in your inbox when it lands and it’ll be really a fascinating read for anybody who’s an enterprise defender or just wants to know how the Internet has changed in the past two and a half years.
Pre-Register for the 2026 State of the Internet Report
Each year, Censys’ State of the Internet Report analyzes Internet-wide trends to identify meaningful shifts in the technologies, infrastructure, threats, and behaviors shaping the public Internet. Sign up to receive your copy as soon as it publishes on October 6.
Silas Cutler (02:47)
I’m really looking forward to it as well. And I think next time you and Emily are hosting again.
Himaja Motheram (02:52)
Yes, we’re gonna talk more about it on this webcast as well. But this is just a little teaser for people who want to know more about it.
Silas Cutler (02:58)
I’m super excited. Thank you so much for coming on.
Silas Cutler (03:00)
All right, that transition worked. I think this is the first time we’ve had someone come on for a short time. So this is exciting that things are holding together. All right, Martijn, let’s dive into it. So we’ve got a couple things to cover today. I know we wanna are gonna go through a couple of our reports that we’ve done over the past month, but I think it’s probably worth starting off talking about the MikroTik Zero day that came out over the weekend. I’ve only looked at this a little bit. What can you tell us so far about what’s been going on?
Martijn Grooten (03:25)
So MikroTik is a Latvian company, think, that makes routers, routers, depending on which side of the Atlantic Ocean you’re in. And they have their own operating system called Router OS. someone, well, no, not someone, SERT Poland, like the Polish National SERT, found a number of vulnerabilities, two of which are very critical. The first allows an unauthenticated user to access the operating system and the second one is a privilege escalation. So together they allow someone to completely take over that device. There are certain conditions need to be met.
Silas Cutler (04:10)
Yeah, it doesn’t sound entirely like like point and click to get full root. Like it seems like there’s some preconditions. Like I know SSH was part of the actual like attack chain.
Martijn Grooten (04:20)
Yes. I mean, the first precondition is that it’s only affecting version 7 of the operating system, which I believe is the latest version. And I had a quick look this morning and about one third of what we see in Censys runs version 7. So the older ones are lucky this time. Generally not a good idea to run older operating system software, but here you’re lucky. And you need to set up SSH, which is again about a third of that population that run SSH.
And then you need to have set up public key authentication in SSH. It’s a fairly standard way of using SSH. But again, you need to set that up. And then an adversary needs to know two things. They need to know your user name. And they need to know the RSA public key. And there’s some cryptography going on how the public key, which as the name suggests, is supposed to be public. Shouldn’t be an issue of someone as that but that allows someone to authenticate as that user and then they can use the auto vulnerability to run as root.
Silas Cutler (05:27)
Interesting. So I mean it there’s been some in attacks like this in the past that and I know some research I did for LABScon two years ago looked pretty closely at things like SSH public keys and while like while some people may see that as a bit of a challenging vector, places like GitHub actually expose your public keys. And so it’ll be interesting to see how like how broad exploitation actually becomes from this because there are ways to overcome some of those those technical challenges, but I suspect you know we’ll see more in the wild.
Martijn Grooten (05:56)
Yeah, given the conditions and given that you do need to have that public key and the username, this doesn’t feel like something that will be wormable or something where some entity persons mask against the internet and infects everything they see. But in more targeted attacks, think government hackers, this sounds extremely useful if that’s your job.
Silas Cutler (06:21)
I mean, that makes perfect sense though, also, because if you’re going to have to work target by target to compromise things, it’ll be the time that a nation state will invest in it. And secondarily they’ll be able to do the reconnaissance to find the keys.
Martijn Grooten (06:33)
Exactly.
Silas Cutler (06:34)
Yeah, I’m not sure if we put out a rapid response report on it, but that’ll be definitely one to watch for and just watch going forward. fantastic.
Martijn Grooten (06:38)
I think we did, yeah. Our customers should have known already.
Silas Cutler (06:48)
Yeah. it’s interesting. Like there I feel like some of the AI stories over the past week have overshadowed this story, but over the weekend there were definitely a couple people that were reaching out to me about it because cause of the infection like base as well. And MikroTik it’s a pretty it is a great option and like I used it for a little while in my lab.
Martijn Grooten (07:05)
Yeah, it’s widely used around the world. I had a look because Censys has a cool platform where you can look at these things. It’s most popular in Brazil, followed by think Indonesia, Bangladesh, India, and Iran. It’s interesting.
Silas Cutler (07:22)
Yeah, that’s a really cool footprint as well. And it is it is a Latvian company, I did check as well. So like it is pretty fantastic seeing also just as well some competitors in the space to to Cisco and and Fortinet.
Since the last time we had the ARC Flash, we’ve had a couple of blog posts come out. So we had one come out yeah, I did have one. Yeah, so Andrew put out one. It was the the not malware looking at — or sorry, he looked at the fake MP4 one that carried. You’re right, I did put out one. It was the the “Not Malware Nor Harmless” that was tracking NPS. I was really thrilled to get this out. This is what I actually have been slowly working on for a little while. It didn’t go super in depth into it, but NPS, along with like FRP and a couple of these other other tools that are fairly popular in with threat actors based out of the People’s Republic of China, they are main staple tools for a lot of folks, but out West we tend not to see these as often except during things like intrusions or when it’s linked by you know groups like CISA to Volt typhoon. But yeah these are they’re very mature proxy tools.
I will also fully admit I don’t know what NPS stands for. I have looked and I think it was even a comment that you added to my like Google Doc blog post draft of it. And I’m not sure if it’s like a linguistic thing or but I always hear it as like NPS the intranet proxy. Like noting that it’s designed to cross the barrier from Internet to intranet, but still would love to know if it’s a if it’s a native Chinese like acronym that I’m not familiar with. I’d love to know.
Martijn Grooten (08:57)
Sometimes Chinese people name these things based on what things sound like in Chinese. So NPS, that term might mean something in Chinese as a word or something like that. But yeah, it’s a question. I tend to leave comments on blog posts saying you need to spell out acronyms, but if you don’t know it, then you can’t do much. But it was an interesting blog post and I definitely recommend people read it.
Silas Cutler (09:26)
Yeah, thank you. I mean it’s it’s been really interesting because over the past year we have started adding more of these like they’re they’re complicated. And we even had a discussion early on about like does NPS constitute a threat within like in our scope of like threats at large? And it’s an interesting challenge because it sits within that dual purpose world quite heavily.
Martijn Grooten (09:47)
Yeah. And that’s obviously more and more of this and that’s, that’s going to be a challenge. I mean, VPN services to some extent, especially those using residential proxies kind of same thing. Like there’s a legitimate users use cases for these, at least non harmful ones. But they’re definitely being used by threat actors as well.
Silas Cutler (10:11)
Yeah, so that’s actually interesting because so I’ve got a talk coming up and jumping around from my org like pre-planned schedule slightly. For a long time they’ve, there was a boundary that I always heard, which was VPNs at large, typically commercial ones, tend not to include things like residential proxies or mobile exits. But it seems like that’s also been a trend that has been changing over the past couple of years as well. So it is definitely an interesting time in in terms of that space.
Martijn Grooten (10:40)
I think it also makes sense if you’re a VPN provider and all you’re doing is using AWS and local equivalents then everyone’s going to detect you and block that traffic.
Silas Cutler (10:52)
I also wonder if like some of that crackdown started because there’s a large like VPN user base that are, there are users that are looking to watch sport games that are no longer available like within their region. So I wonder if some of that crackdown came from like streaming companies starting to reduce like reducing the allow reducing data center streaming.
Martijn Grooten (11:13)
And as someone who has lived in different countries and moved around a bit, I definitely sympathize with people who are just frustrated by the fact that they don’t have access. And it’s often not even the case about not being able or willing to pay. There simply is no way to access a certain movie or sports event.
Silas Cutler (11:31)
Cut down by licensing. So we got time for one more little bit of a topic. Did you want to touch on the the camera work that you’ve done as well? Because that was a great blog post from a few months ago and love to talk more about it.
Martijn Grooten (11:46)
Yeah, this is my debut on the webcast, so I hadn’t been able to talk about that. It’s a fairly simple blog post. It was based on a report by Dutch intelligence, who basically noted that Russian hackers, Russian states hackers, were hacking cameras to get the images, and they used these images to kind of compile a picture. Traditionally, if you’re in Russia, you wanted to know about say military movement in Ukraine, and you wanted to hack a camera, then you would look for that one camera at the military base. But of course, it will have learned lessons. And these cameras, even if they’re connected to the internet, they’re extremely well guarded. So that’s probably gonna be really hard. But what instead they did in Ukraine, but also in other countries, including the Netherlands where it came from, is hacking kind of random cameras and using AI to combine the pictures from all these cameras to conclude things like military movements. And it might be a security camera at the petrol station, just showing a random regional road. Nothing exciting. You wouldn’t think this is at all of interest. And on its own, it probably isn’t. But if you add it up with 50 auto cameras like that, you can certainly see a picture.
Silas Cutler (13:15)
But I mean, like gas station cameras, especially at something like gas station, that’s an interesting relay point because if you’re doing things like content recognition and identifying and extracting the text from like license plates, being able to catalog, hey, we here are the people we’re seeing routinely travel this path, those are things that get built into like pattern of life analysis of individuals. And if you want to do like, if you’re trying to develop capabilities to track military like military equipment movement, the personnel are part of that as well. And tracking license plates and and the vehicles that goes down it, even if you have visibility into it, that’s a negative result sometimes. And that at least tells you we know movement’s not coming through this pathway. So it it’s interesting also because I’ve seen several different opportunistic camera enumeration tools that have been built. Like I have one that I built as a hobby after the story from Reuters back in January.
Silas Cutler (14:13)
And it’s like it proof of concept of the capability, but the limitation is of course, in the previous reporting that I’ve seen has been attackers using zero days for Hikvision and other camera brands in order to gain access and which is not something I’m doing as part of mine. I’m only relying on fully public access feeds.
Martijn Grooten (14:31)
Yeah, it’s probably a combination of that. Use public feeds or known vulnerabilities if you can. Use zero days if you really need to. And combination of that. And again, AI can really help sorting out large data sets.
Silas Cutler (14:50)
I imagine the AI also is extremely useful for overcoming the limitations of IP to geo like geolocation because the the geographic coordinates that that most places are gonna have for an IP address, I usually like by personally assume it’s going to be accurate, like roughly to the city, but I’m not going to expect that it’s going to be within a five foot marker of that dot.
Martijn Grooten (15:14)
Probably, mean, AI combined with other public data. There’s Google Street View and lots of other things. mean, Bellingcat has been doing that for years and AI just makes that work faster.
Silas Cutler (15:31)
Yeah, I can’t imagine what their spend is gonna be on Google Maps as result of it, because anytime I’ve hooked up an API key to Google Maps, it almost immediately becomes like a hundred dollar bill for me. But really cool stuff. Like it’ll be it’ll be interesting to see how this progresses. I think it’s definitely something that we’re gonna see other other entities getting involved in in the future, especially around military conflicts.
Martijn Grooten (15:52)
I think so too. And I think using AI to guard a lot of data, even if it’s just ordinary email account hacks to generate a fuller picture, that’s probably going to, we’re going to see a lot of that too.
Silas Cutler (16:05)
I agree. All right. Close us out. What are some talks that are coming up that that you’re gonna be presenting at so that folks can come in and see some of your great work?
Martijn Grooten (16:14)
I’ll be presenting in, I think, two weeks time in Munich at the Cybersecurity and AI Summit, I think it’s called. I’m talking a little bit about nation-state threats, including the thing that I just mentioned about AI. So that’s a bit of a teaser there. And I’ll be presenting at a few places in, if not mistaken, Helsinki and Barcelona, as well as online in the webinar on the State of the Internet Report that Himaja just talked presenting the work that my colleagues did today. It’s a little, little bit.
Silas Cutler (16:50)
Fantastic. All right, I think we will call to wrap for this week. Join us next month where we will be talking about the State of the Internet. Hope to see you soon.
Catch the Next Episode on Oct 7
Censys ARC Flash goes live once a month. Sign up to sit in on the next episode when it airs on September 9th to get the latest cybersecurity intelligence and ask your questions live.
References
- Critical vulnerabilities in MikroTik RouterOS are being actively exploited.
- The State of the Internet Is Changing: AI Exposures Surge While Global ICS Trends Shift
- 2026 State of the Internet: The Exposure Notification Gap in ICS Devices
- Neither Malware nor Harmless: Tracking the NPS Proxy Across the Internet
- The Video That Plays You: Fake MP4 File Carries Malicious Payload
- Inside Russia’s Camera-Hacking Espionage Campaign
- Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024
- What the ERMAC Source Leak Says About HookBot
- Mirai and Its Heirs: A Decade of Structural Neglect in IoT Security
- Rethink! Cloud & Data Security Summit 24-25 September 2026

