Dive Brief: - North America accounts for the most internet-exposed industrial control systems (ICS) as of early 2026, with roughly 38% of all such devices located on the continent, according to the internet monitoring firm Censys. - Meanwhile, the number of publicly accessible AI tools is growing fast: Censys detected more than 294,000 IP addresses associated with AI services in early 2026, up from 183,000 in October 2025. - The data, from a preview of Censys’s annual internet exposure report, highlights the vast array of targets available to hackers who are intent on sabotaging critical infrastructure or subverting the AI tools on which companies increasingly rely. Dive Insight: Not only are AI services increasingly appearing on the public internet, but the products with the most significant vulnerabilities are the ones popping up most frequently. Censys detected 169% more instances of the AI agent-building tool Langflow over the past nine months, even as the software has accumulated 18 vulnerabilities (14 of them scored as high-severity, four of them seeing exploitation) since 2024. “Multiple unauthenticated remote code execution (RCE) vulnerabilities make any Internet-exposed instance a critical finding,” Censys said. The number of internet-exposed instances of another common AI tool, LiteLLM, nearly doubled during Censys’s observation window, even as hackers continue exploitating a pre-authentication SQL injection vulnerability. LiteLLM serves as a unified hub for connecting to commercial LLMs, meaning that a compromise of its data would expose a customer’s API keys for all of those services. The ICS landscape, as it appears in Censys’s data, is no less alarming. The number of internet-exposed ICS devices has grown from 129,000 in 2024 to 138,000 in early 2026, magnifying the danger facing communities around the world as the equipment powering their energy grids, hospitals and water supplies remain within easy reach of hackers. While the
The most vulnerable AI products are also some of the most commonly exposed online
Read the original article
cybersecuritydive.com →