Research, Product & Field Notes
Threat research from the open internet, what's new in Modat Magnify, and the news shaping how we build.
The New Magnify Platform Is Live Today
Modat has released a new Modat Magnify, built around how researchers pivot, with the API specification aligned to the interface so the Magnify Query Language is consistent across the platform.
Modat Featured in High-Level Thales Visit to HSD Campus
Modat joined a select group of cybersecurity innovators presenting to Thales' new leadership during a strategic visit to Security Delta (HSD) in The Hague.
Modat at FIRSTCON26: Connection, a Launch, and Research in the Field
Modat attended the 38th Annual FIRST Conference in Denver, where we announced native Passive DNS in Modat Magnify and spent five days with the global cybersecurity community.
Stadium of Shadows: Inside the IPTV Piracy World
On the night of June 11, a billion people watched the 2026 FIFA World Cup opening match, but millions did so through a shadow ecosystem of pirate panels, burner domains and rebranded apps, paying a fraction of what licensed broadcasters charge. The money flows to organised crime. In the days around kickoff, we went inside the infrastructure powering that parallel feed. This is what the pirate stadium looks like from the inside.
Modat adds Passive DNS to its Platform Magnify, Connecting Every Signal in a Single Investigation Graph
Modat launches native Passive DNS intelligence in Magnify, its internet intelligence platform, unifying IP, device fingerprint, certificate, and passive DNS into a single pivot-driven investigation flow. Security, threat intelligence, threat hunting, exposure management and fraud teams have long been forced to stitch together evidence across multiple tools. Magnify eliminates that gap.
Modat Magnify Integrates with EclecticIQ IntelligenceCenter to Enrich Threat Intelligence Workflows
Integration of Modat Magnify with EclecticIQ Intelligence Center™ enables security teams to validate indicators, uncover related infrastructure, and investigate with higher confidence, without leaving their platform.
Modat Welcomes Karen Sundermann as Head of Public Sector
Modat announces the appointment of Karen Sundermann as Head of Public Sector, bringing more than a decade of experience in cyber threat intelligence, data analytics, and public safety.
Modat MCP is Live: Query Magnify from Any AI Tool
Modat MCP is now live: query Modat Magnify directly from Claude, Cursor, or any MCP-compatible AI tool, bringing Device DNA, IP, DNS, and certificate intelligence into the AI workflow you already use.
Scammers Target Dutch Taxpayers in Seasonal Phishing Surge
Phishing attacks targeting Dutch taxpayers are evolving, using advanced techniques and fake Belastingdienst pages. Modat's findings highlight a shift to interactive scams, with a growing focus on stealing cryptocurrency and other high-value digital assets.
Beyond the Blackout Narrative: How Internet Infrastructure Is Reshaped During The Middle East Conflict
Internet "blackouts" during conflict are not full shutdowns but structural transformations. Analysis shows three patterns: Iran restricts access, Israel expands deceptive infrastructure, and Gulf states stabilise while redistributing systems.
Neutralizing the Watchdog: Automated Security Removal in a Modular Cryptomining Campaign
A cryptomining campaign recently uncovered by Modat, working alongside Recorded Future, demonstrates a high level of modular efficiency that poses a direct threat to organisational infrastructure.
Modat Magnify: Expanded Protocol Visibility and Large-Scale Investigation Tools
This release improves search precision, expands protocol visibility, and introduces tools for more efficient large-scale investigations: here's what's new in Modat Magnify.
Internet-Exposed RTSP: A Global Analysis
Nearly a million RTSP video services are exposed on the open internet, most without authentication. Of 973,819 active services across 210 countries, 8,074 streamed live video with zero credentials required, including thermal sensor arrays and systems co-located with SCADA dashboards.
Moltbot Unmasked: A Global Deployment Analysis
mDNS discovery, internet-facing control interfaces, and open directory leakage: an analysis of Moltbot deployment security across thousands of internet-exposed instances.
Modat Magnify: Deeper Investigation, Smarter Search
This release focuses on investigation depth, search precision, and analysis speed: here's what's new in Modat Magnify, from a unified IP detail view to certificate validity search.
Modat Magnify: Full Autocomplete and New Search Capabilities
Full autocomplete across all search types, expanded SSH search, banner hash search, stable HTTP fingerprinting, and more: here's what's new in this Modat Magnify release.
Modat Receives the ECSO "Cybersecurity Made in Europe" Label
Modat has officially obtained the "Cybersecurity Made in Europe" label from the European Cyber Security Organisation (ECSO), confirming that our company meets strict European criteria for trustworthiness, transparency, and data sovereignty.
Modat Magnify v1.4.0: New Detections, Search Enhancements & More
Version 1.4.0 brings some of your most requested features to Modat Magnify: a redesigned Query Guide, new tags and search operators, and a wave of new malware and OT detections.
Exposed to the Bare Bone: When Private Medical Scans Surface on the Internet
Over 1.2 million healthcare devices and systems are available on the open internet, exposing MRI scans, X-rays, and patient records due to misconfigurations and weak credentials.
Modat Magnify Feature Findings
Our Feature Finding series is designed to empower cybersecurity professionals to help them get ahead of cyber attacks. Our findings are done by our in-house research team using access to the largest Device DNA set available to find and then conduct further research.
Find What You Are Looking For: Introducing Modat Magnify
Stop searching and start finding. Modat Magnify gives you access to the largest internet 'Device DNA' dataset available: European-crafted, AI-powered, and research-driven.
Doors Wide Open: hundreds of thousands of employees exposed; thousands of organisations physically vulnerable
Research: 50K internet-exposed Access Management System misconfigurations detected across multiple industries and countries, indicating a global security issue.
Mopping up after leaky buckets: the rising tide of spilled secrets
An empirical analysis of secret leaks in cloud buckets and responsible disclosure outcomes. Most data leaks don't happen because of criminals breaking in: they happen because of misconfigurations, oversights, and lax system administration.
NIS2 - More than Compliance, It’s About Building Resiliency. Together, Making a Safer and Stronger EU
Part 1: NIS2's Duty of Care Requirements. Why the directive matters now, and how proactive scanning and clear asset visibility help CSIRTs build real cyber resiliency across the EU rather than just checking a compliance box.
Part 2 - NIS2 - More than Compliance, It’s About Building Resiliency. Together, Making a Safer and Stronger EU
Focusing on Four Areas within NIS2 - Duty of Care - benefiting CSIRTS: Monitoring of External Encryption Settings, Coordinate Vulnerability Disclosure, Proactive Scanning, and External Surface Auditing.
Knock, Knock, I'm Coming In. Addressing the Gray Area on the Ethics of Internet Scanning
If I leave my house unlocked and unprotected, is that an invitation for you to come in? A look at the ethics of internet scanning through the lens of a neighborhood, and why intent, not just action, is what matters.
PRESS RELEASE: Z-CERT Selects Modat to Strengthen Cybersecurity for Dutch Healthcare Organisations
Modat today announced a formal collaboration with Z-CERT, the national sectorial CERT for healthcare in the Netherlands.