Provider of Attack Surface Discovery (ASD), Attack Surface Management (ASM) and CTI solutions. Scanning at Internet-scale since 2017 - contact at onyphe dot io

Joined March 2016
351 Photos and videos
Pinned Tweet
29 Dec 2025
๐Ÿ“ฃ ANNOUNCEMENT: we have reached the 2,100 scanned ports milestone, at Internet scale with a weekly refresh rate. Next step: 5,000 ports, weekly refresh. Then 10,000 by end of next year. We will be the competitor number 1 to @censysio in 2026. #ASM #CTI #ASD
2
5
1,005
@onyphe.io retweeted
Well, at the roots, Internet was built decentralized. All these points are about centralization. Who knows what a #SPOF is in 2026?
May 20
software engineering in 2026: - your package manager is compromised - your cloud provider blocks your account - github itself is hacked software is solved
1
2
309
Very nice talk by @WeynsMaarten at this year's @Botconf about #DDoS for hire infrastructures exploiting weaknesses in monitoring solutions. Number of exposed #Netdata or #Prometheus instances is quite crazy. Happy to share our data with TUDelft, like we already did in the past.
2
278
We're thrilled to announce that we'll be at the @Botconf in Reims starting tomorrow until April 17th. And we're very proud to be one of its gold sponsors ๐Ÿ˜Š Looking forward to seeing you there!
2
165
Trรจs heureux de vous annoncer que nous serons ร  la Botconf qui se tiendra ร  Reims cette semaine, du 14 au 17 avril. Et trรจs fiers dโ€™en รชtre lโ€™un des sponsors goldย ๐Ÿ˜Š Hรขte de vous y retrouverย !
2
182
๐Ÿ“ฃ We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #Citrix product: CVE-2026-3055: remote unauthenticated memory reading #CitrixBleed3 ๐Ÿ’ฅNearly 19k unique IP running a vulnerable version search.onyphe.io/search?q=caโ€ฆ
1
2
5
477
@onyphe.io retweeted
And you had coinbase in Septembre 2025 on this domain, Cc @onyphe :
๐Ÿšจ ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐—ฑ๐—ฒ๐—ฟ๐˜€ โ€“ ๐—ฆ๐—ต๐—ถ๐—ป๐˜†๐—›๐˜‚๐—ป๐˜๐—ฒ๐—ฟ๐˜€ ๐—œ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—”๐—น๐—ฒ๐—ฟ๐˜ ReliaQuest Threat Research has identified a newly registered domain: ๐˜€๐˜๐—ฟ๐˜†๐—ธ๐—ฒ๐—ฟ[.]๐—ฝ๐—ฎ๐˜€๐˜€๐—ธ๐—ฒ๐˜†๐˜€๐—ฒ๐˜๐˜‚๐—ฝ[.]๐—ฐ๐—ผ๐—บ, attempting to exploit confusion around Strykerโ€™s current situation. Link: reliaquest.com/blog/threat-sโ€ฆ Further investigation reveals two additional organizations being targeted: ๐˜€๐˜„๐—ถ๐—ป๐—ฒ๐—ฟ๐˜๐—ผ๐—ป[.]๐—ฝ๐—ฎ๐˜€๐˜€๐—ธ๐—ฒ๐˜†๐˜€๐—ฒ๐˜๐˜‚๐—ฝ[.]๐—ฐ๐—ผ๐—บ ๐—ฐ๐—ฏ๐—ถ[.]๐—ฝ๐—ฎ๐˜€๐˜€๐—ธ๐—ฒ๐˜†๐˜€๐—ฒ๐˜๐˜‚๐—ฝ[.]๐—ฐ๐—ผ๐—บ โš ๏ธ Defenders are strongly advised to: - Monitor the generic, non-brand domains listed in the IOCs. - Deploy defensive threat monitoring queries immediately to detect potential activity. Letโ€™s stay ahead of adversaries.๐Ÿค #Cybersecurity #ThreatIntel #ShinyHunters
2
4
652
We are experiencing an availability issue on our search platform. Currently investigating, will let you know. Thank you for your patience.
1
190
Our hosting provider is experiencing an issue, we will keep you posted.
1
112
Service is partially restored (not all data is available) but main issue is not fixed yet by our hosting provider.
113
@onyphe.io retweeted
I deleted the previous tweet to avoid confusion. It was incorrect.
1
5
635
You mean like this: onyphe -search 'category:ctiscan ip.asn:"AS20473" cert.fingerprint.sha256:"8521f42ce73b1646ccf6d85d876e40662fd0560aeded05ce62b94e5e30233cbe" | uniq ip.dest'
๐Ÿ†• Quick Pivot on UNC6201 infrastructure with @TeamCymru Scout! @Mandiant shared a GRIMBOLT C2: 149.248.11.71 in their latest blog on UNC6201 (cloud.google.com/blog/topicsโ€ฆ) Using Scout, I found 2 more IPs using the same certificate, ASN, and open ports 140.82.18.134 66.42.111.219
3
4
1,219
๐Ÿ The new year has already begun, so itโ€™s time to look back on 2025 and list what weโ€™ve accomplished at @onyphe. Itโ€™s also time to talk about upcoming developments. And once again, theyโ€™re ambitious, as they are every year for us. Blog article: blog.onyphe.io/en/retrospectโ€ฆ

3
84
๐Ÿ La nouvelle annรฉe est dรฉjร  entamรฉe, cโ€™est le moment de revenir sur 2025 et de lister ce que nous avons fait chez @onyphe. Cโ€™est รฉgalement le moment de parler des รฉvolutions ร  venir. Et cโ€™est encore une fois ambitieux, comme chaque annรฉe chez nous: blog.onyphe.io/rtrospective-โ€ฆ

2
134
๐Ÿ“ฃ Just added 400 new ports to scan ๐Ÿ‘€ Total: 3,000 ports - weekly refresh #ASM #Internet #Scanner
3
3
263
๐Ÿ“ฃ UPDATE: now scanning 2,600 ports, weekly refresh.
29 Dec 2025
๐Ÿ“ฃ ANNOUNCEMENT: we have reached the 2,100 scanned ports milestone, at Internet scale with a weekly refresh rate. Next step: 5,000 ports, weekly refresh. Then 10,000 by end of next year. We will be the competitor number 1 to @censysio in 2026. #ASM #CTI #ASD
3
189
onyphe -search 'category:ctiscan app.device:c2 -dayago:0 | uniq ip.dest | addcount | fields count' | tail -n 1 {"count":236} #C2 #CTI #ThreatHunting
2
170
๐Ÿ“ฃ We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #n8n product: CVE-2026-21858: unauthenticated remote code execution #Ni8mare search.onyphe.io/search?q=caโ€ฆ
3
535
@onyphe.io retweeted
๐Ÿคก CVE-2026-21877 - 10.0 CVSS for AUTHENTICATED Remote code execution in @n8n_io, what a joke.... This is the reason there are so many real risks to be found because of stupid scoring frameworks and compliance requirements
29
58
484
78,567
Incident is resolved.
We are experiencing a production incident, our Web site or APIs may not be available to all. Will keep you posted as soon as it is resolved. Thanks for your patience.
1
185
We are experiencing a production incident, our Web site or APIs may not be available to all. Will keep you posted as soon as it is resolved. Thanks for your patience.
281