HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

36,769 Self‑Hosted AI Endpoints Found Exposed on the Internet, Only 2% Protected by Authentication

A scan by Mysterium VPN uncovered 36,769 publicly reachable AI model servers and vector stores, with just 2 % presenting an HTTP authentication gate. The finding highlights a systemic access‑control gap that can undermine audit readiness and continuous control assurance.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

36,769 Self‑Hosted AI Endpoints Exposed on the Internet, Only 2 % Protected by Authentication

What Happened — Researchers from Mysterium VPN scanned public‑internet indexes and identified 36,769 reachable AI endpoints (model servers, agent‑building platforms, vector stores). Only about 2 % returned an HTTP 401/403 response, meaning the overwhelming majority were accessible without any network‑layer authentication.

Why It Matters for Trust & Control Assurance

  • Lack of authentication violates the core control objective of enforcing access controls for AI services; continuous discovery can surface this gap before it becomes a breach.
  • Unauthenticated endpoints enable resource‑abuse and potential data leakage, eroding the evidentiary trail needed for audit readiness.
  • Mapping these misconfigurations to a control‑assurance platform provides defensible evidence that satisfies multiple frameworks (e.g., NIST CSF 2.0).

Who Is Affected – Enterprises running self‑hosted large language models, AI platform vendors, cloud‑infrastructure teams, and any organization that deploys local model‑serving stacks.

Recommended Actions

  1. Inventory every AI model‑serving, agent‑building, and vector‑store instance.
  2. Enforce network‑layer authentication (API keys, OAuth, mutual TLS) and restrict inbound traffic via firewalls or zero‑trust controls.
  3. Integrate automated endpoint discovery into your continuous control‑assurance program to generate audit‑ready evidence.
  4. Document configuration changes and access‑control settings for future assessments. Source: SecurityAffairs article

Technical Notes – The exposure stems from misconfiguration (absence of authentication) rather than a specific CVE. No vulnerability was actively exploited; researchers only queried a scanning index and verified HTTP response codes. Affected data could include proprietary model binaries, prompts, and any documents processed by the exposed services. Source: same as above

📰 Original Source
https://securityaffairs.com/198898/ai/the-ai-supply-chain-has-a-security-problem-and-much-of-it-is-sitting-on-the-open-internet.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →