Censys Finds AI/LLM Tool Exposures Up More Than 60%

Censys found Internet-exposed AI/LLM tools increased more than 60% in nine months, expanding organizations’ attack surfaces.

執筆者
Ken Underhill
Ken Underhill
Jul 23, 2026
3 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

The public Internet continues to evolve as AI deployments expand and global ICS exposure patterns change. 

Early findings from the 2026 Censys State of the Internet Report show Internet-exposed AI/LLM tools have risen more than 60% over the past nine months, expanding organizations’ attack surfaces.  

The annual report uses data from the Censys Internet Map and Censys Attack Research Center (ARC) to analyze evolving Internet infrastructure and security trends. 

Key takeaways from the early Censys findings

  • Internet-exposed AI/LLM tools increased more than 60% over the past nine months, reaching more than 294,000 public IP addresses.
  • Rapidly growing AI platforms such as Langflow and LiteLLM also carry high-risk vulnerabilities, including multiple CISA KEV-listed flaws.
  • Internet-exposed ICS hosts increased to approximately 138,000 globally, while Asia’s share of exposures continued to grow.
  • Approximately 70% of Internet-exposed ICS hosts remain on consumer and mobile networks despite shifting global deployment patterns.
  • The upcoming Censys report will examine Internet infrastructure trends, vulnerability remediation, AI exposure growth, and global ICS security.

Internet-exposed AI infrastructure continues to grow

Researchers identified more than 294,000 distinct public IP addresses exposing one of 43 AI and LLM tools, compared with approximately 183,000 in October 2025.

The research also found that some of the fastest-growing AI platforms are among the highest-risk deployments.

Langflow, an open-source framework for building AI workflows, grew 169% during the reporting period. 

Between 2024 and 2026, the platform accumulated 18 CVEs, including 14 vulnerabilities with CVSS scores above 8.0 and four entries in CISA’s KEV catalog. 

Multiple unauthenticated remote code execution (RCE) vulnerabilities increase the risk of compromise for Internet-exposed Langflow instances. 

LiteLLM also experienced rapid adoption, increasing 97% over the same period. 

Censys noted that the platform is affected by an actively exploited pre-authentication SQL injection vulnerability, CVE-2026-42208, which has been added to the CISA KEV catalog. 

Advertisement

Because LiteLLM functions as a unified LLM proxy, a successful compromise could expose API keys for multiple upstream AI model providers.

Global ICS exposure patterns continue to shift

Beyond AI adoption, Censys identified ongoing changes in the geographic distribution of Internet-exposed industrial control systems (ICS).

Researchers observed an average of approximately 138,000 Internet-exposed hosts running ICS services during early 2026, up from roughly 129,000 hosts reported in 2024.

North America continues to account for the largest share of global Internet-exposed ICS infrastructure, representing approximately 38% of observed systems. 

However, Asia’s footprint has expanded from 22.9% of global exposures in 2024 to 27% in 2026.

Europe, meanwhile, represents a smaller percentage of the global total than in previous years, declining from 36.1% in 2024 to 31.1% in 2026.

Although the geographic distribution has changed, Censys found that the underlying network environments hosting these systems have remained largely consistent. 

For the past two and a half years, approximately 70% of Internet-exposed ICS hosts have consistently appeared on consumer and mobile networks rather than enterprise environments.

The preliminary findings represent only a portion of the research included in the upcoming report.

According to Censys, the full 2026 State of the Internet Report will examine long-term trends across Internet infrastructure, including hosts, services, ports, protocols, certificate authorities, and end-of-life software. 

Researchers will also examine how quickly organizations patch Internet-exposed systems after new CVEs and CISA KEV additions. 

The report will also provide deeper analysis of Internet-exposed ICS environments and the rapid expansion of AI infrastructure, including technologies such as MCP servers, Ollama, Langflow, LiteLLM, and AI automation frameworks. 

Together, the findings are intended to provide organizations with a data-driven view of how Internet-facing technologies and attack surfaces continue to evolve as AI adoption accelerates.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。