← Back to feed
AI SecurityEmerging1 sourceSep 11, 2026 · 17:27via Security Affairs

The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet

Brief

Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate.

Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears quickly when the infrastructure itself is exposed to the public internet.

A new study from Mysterium VPN offers a useful snapshot of the problem. The researchers found 36,769 self-hosted AI endpoints across model servers, agent-building platforms and vector stores that were reachable and identifiable through a public internet scanning index.

“Only 2. 02% return an HTTP authentication challenge; for the overwhelming majority, there’s no network-layer gate whatsoever.” reads Mysterium VPN’s report .

Read more on Security Affairs→