A security scan by Intruder of 2 million hosts containing 1 million exposed AI services has revealed unprecedented security vulnerabilities, with researchers calling AI infrastructure the most vulnerable software category they have ever investigated. The assessment found that 31% of over 5,200 Ollama API servers responded to prompts without authentication, while over 90 exposed agent management platforms were discovered across government, marketing, and finance sectors. Critical security failures include hardcoded credentials in setup files, applications running as root, and one exposed instance revealing a user's complete LLM conversation history and API keys in plaintext. The findings indicate AI developers have abandoned established security practices in favor of rapid deployment, with authentication disabled by default and 518 instances wrapping frontier models from major providers like Anthropic, Google, and OpenAI left exposed to potential exploitation.
Aug 7, 2026 · 2 sources
Aug 10, 2026 · 2 sources
Aug 10, 2026 · 3 sources
Aug 10, 2026 · 8 sources
Story comments
Loading comments…