Scan of 1 Million Exposed AI Services Reveals Dire Security — No Auth, Hardcoded Keys, Root Access
The Hacker News·medium signal
The Hacker News reports on a large-scale scan using certificate transparency logs that found over 1 million exposed AI services with catastrophic security hygiene. Many deployments had no authentication (disabled by default), hardcoded credentials, API keys in plaintext, and applications running as root. Claude-powered chatbots were found leaking API keys; n8n and Flowise agent platforms were internet-exposed without auth.