EchelonGraph · Threat Intelligence
The State of Internet Exposure 2026
Inaugural Edition · What the whole internet can already see
An evidence-based field report drawn from public data and our own read-only probes — not a survey, not a forecast. We measured the externally-visible attack surface from the same vantage point an adversary uses, across 137 countries, over a five-week baseline window.
By the numbers — window 29 May – 28 June 2026
2,050
AI services confirmed active & open
of 82,416 discovered
21,299
hosts on CISA-KEV exploited vulns
of 36,416 CVE-exposed
6,607
open, unauthenticated databases
120 countries
2,571
exposed .env files
≈2,600 AWS keys
619
secrets in public Git repos
478 repositories
134
hijackable subdomains
dangling CNAME
340,552
CVEs tracked & enriched
1,621 CISA-KEV
137
countries observed
read-only, detect-only
What's inside — 15 chapters, ~128 pages
- Executive Summary
- Methodology & How We Found This
- The AI Attack Surface
- Known-Exploited Vulnerability Exposure
- Exposed Data Stores
- Secret Sprawl
- Subdomain Takeover
- The Vulnerability Landscape
- Trends & Trajectory
- Risk Analysis
- Mitigation & Remediation
- Gaps & What We're Not Seeing
- The CISO Playbook
- Past Mistakes & Lessons
- The Path Forward
How we found this. Every figure starts from public data — Certificate Transparency logs, public internet scan data, public source repositories, and public DNS. Where a public banner is not proof on its own, we confirm it with one read-only, signed probe of our own rather than report something we did not check; the exposed-data-store counts are verified that way. We never authenticate, never log in, and never read the contents of an exposed system. Findings are aggregated and host-redacted under a responsible-disclosure posture. This is an observational field report, not a penetration test, and the absence of a finding is not evidence of safety. Want to see your own exposure? Run the free Surface Scanner →