Skip to main content
Kaino.dev
Discover
Evals
News
Academics
Insights
Kaino.dev

Discover, evaluate, and compare AI tools, models, and agents.

Explore

  • Discover
  • Evaluations
  • News
  • Academics
  • Insights

Community

  • Twitter
  • YouTube
  • Instagram
Privacy PolicyTerms of Service

© 2026 Kaino.dev. All rights reserved.

Version 1.1.0
Censys Says Public AI Tool Exposures Rose More Than 60% in Nine Months · News · Kaino
Censys Says Public AI Tool Exposures Rose More Than 60% in Nine Months
Kaino
YesterdayJul 28, 2026, 12:00 AM0 views

Censys Says Public AI Tool Exposures Rose More Than 60% in Nine Months

Censys’ preview of its 2026 State of the Internet report says public exposures of AI and LLM tools grew from about 183,000 to more than 294,000 IP addresses in nine months. The company links the trend to a broader exposure-management problem as Verizon’s 2026 DBIR reports slower vulnerability remediation and more ex...

LLMsCensys

Censys reported that public exposures of AI and large language model tools increased by more than 60% over a nine-month period in a preview of its 2026 State of the Internet report.

AI tools are becoming more visible on the public internet

In its 2026 State of the Internet preview, Censys said it observed AI and LLM tool exposures rise from about 183,000 public IP addresses in October 2025 to more than 294,000 public IP addresses exposing one of 43 detected AI or LLM tools. The company framed the finding as part of a broader change in the internet’s exposed attack surface, alongside shifts in industrial control system exposure.

The Censys preview does not say that all exposed AI systems are compromised or vulnerable. Rather, its data points to a rapid increase in internet-visible services associated with AI development and deployment. For defenders, that distinction matters: an exposure may be intentional, misconfigured, unnecessary, or protected, but public reachability can still expand what an attacker can find and test.

Censys’ separate analysis, “You Can’t Out-Patch AI. You Can Out-Reduce It,” argues that organizations should focus not only on patching but also on reducing externally reachable systems. The company connects that recommendation to faster vulnerability discovery and exploitation workflows, while emphasizing that fewer exposed services can reduce the number of systems attackers are able to target.

Verizon reports slower remediation and more vulnerability exploitation

The 2026 Verizon Data Breach Investigations Report adds context to that argument. According to Verizon Business, vulnerability exploitation rose to 31% as an initial access vector in the 2026 DBIR dataset. Verizon also reported that the median time for full vulnerability resolution increased to 43 days, up from 32 days, and that only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025.

Tenable’s summary of the 2026 DBIR highlighted the same remediation trend, describing a combination of slower patching and faster exploitation pressure. Tenable also summarized Verizon’s finding that vulnerability exploitation became the leading initial access vector at 31%.

Those figures support a cautious conclusion: many organizations are taking longer to fully resolve known vulnerabilities at the same time that exploitation of vulnerabilities is playing a larger role in breaches. The sources do not show that AI is solely responsible for that change, but Censys and Tenable both point to AI-accelerated vulnerability discovery as a concern for security teams.

Exposure reduction becomes a practical control

Censys’ recommendation is to reduce unnecessary exposure before attackers can take advantage of it. That includes identifying internet-facing assets, removing systems that do not need to be public, tightening access controls, and continuously checking whether new services have become reachable.

For AI and LLM infrastructure, the same principles apply. Development tools, model-serving endpoints, dashboards, vector databases, APIs, and orchestration systems may be deployed quickly during experimentation. If they are left public without strong authentication, network restrictions, or monitoring, they can become part of an organization’s exposed surface.

The Censys data suggests that this category is growing quickly. The Verizon DBIR data suggests that remediation is not speeding up enough to offset vulnerability-driven risk. Taken together, the reports point to a practical security priority: organizations should know which AI-related services are visible from the internet and remove or restrict anything that does not need to be exposed.

That approach does not replace patching. Verizon’s DBIR numbers show that patching and full remediation remain central challenges. But Censys’ argument is that exposure reduction can limit the number of systems that need to survive the race between disclosure, discovery, and exploitation.

Key takeaways
  • 1

    Censys reported that public exposures of AI and large language model tools increased by more than 60% over a nine month period in a preview of its 2026 State of the Internet report.

  • 2

    The company framed the finding as part of a broader change in the internet’s exposed attack surface, alongside shifts in industrial control system exposure.

  • 3

    The Censys preview does not say that all exposed AI systems are compromised or vulnerable.

Continue reading

Latest from Kaino News

Story pulse

Freshness

Yesterday

Views

0

Reading

3 min

Byline

Kainotomic Team

Utilities

Topics

LLMsCensys

Sources

Reference material and original reporting used in this story.

Censys

Published Jul 28, 2026, 12:00 AM

View source