Vulnerable AI Tools and Industrial Control Systems Proliferate Online
Internet monitoring firm Censys reports a 60% surge in exposed AI services while critical infrastructure devices remain dangerously accessible to attackers.
The attack surface for critical infrastructure and AI systems is expanding rapidly, according to new internet exposure data from monitoring firm Censys. The company's preview of its annual report reveals both the growing prevalence of AI tools on public networks and the persistent vulnerability of industrial control systems that power essential services.
Censys detected more than 294,000 IP addresses associated with AI services in early 2026, representing a 60% increase from the 183,000 instances observed in October 2025. This growth comes as organizations deploy AI tools across their operations, often without adequate security controls.
The most vulnerable tools are spreading fastest
The data reveals a troubling pattern: AI products with serious security flaws are among those seeing the most rapid adoption. Censys tracked a 169% increase in internet-exposed instances of Langflow, an AI agent-building platform, over a nine-month period. During that same timeframe, Langflow accumulated 18 vulnerabilities, including 14 rated as high-severity and four actively exploited by attackers.
"Multiple unauthenticated remote code execution (RCE) vulnerabilities make any Internet-exposed instance a critical finding," Censys stated in its report.
LiteLLM, another widely deployed AI tool that serves as a unified gateway for connecting to commercial large language models, saw its internet-exposed instances nearly double. The platform continues to face exploitation of a pre-authentication SQL injection vulnerability. Because LiteLLM stores API keys for multiple LLM services, a successful compromise could expose credentials across a customer's entire AI infrastructure.
Industrial control systems remain exposed
The industrial control systems landscape presents equally serious concerns. Censys identified 138,000 internet-exposed ICS devices in early 2026, up from 129,000 in 2024. These systems control energy grids, hospitals, water treatment facilities, and other critical infrastructure.
North America accounts for approximately 38% of all internet-exposed industrial control systems, the largest share globally. Asia's portion has grown from 23% in 2024 to 27% in early 2026, while Europe's share declined slightly from 36% to 31%.
One persistent characteristic of the ICS environment raises additional red flags: roughly 70% of hosts running ICS devices and services globally have consistently been found on consumer and mobile networks over the past 2.5 years. Business networks and cloud platforms account for significantly smaller portions, at approximately 25% and 5% respectively.
Why it matters
The convergence of rapidly expanding AI adoption with inadequate security practices creates immediate risk for organizations. As companies integrate AI tools into core business processes, each vulnerable instance becomes a potential entry point for attackers seeking to steal proprietary data, compromise API credentials, or disrupt operations. Meanwhile, the continued exposure of industrial control systems on consumer-grade networks demonstrates that critical infrastructure operators have not yet implemented basic network segmentation practices, leaving essential services vulnerable to sabotage.
The findings were first reported by Censys in a preview of its annual internet exposure report.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call