What’s exposed
Researchers from Intruder scanned over 2 million hosts and found 1 million exposed AI services online. The findings are bad — most LLM deployments ship with insecure defaults, and many sit on the public internet with no authentication at all.
This isn’t a hypothetical risk. Real user data, internal company workflows, and production AI agents are accessible to anyone who knows where to look.
What the scan found
The investigation surfaced three categories of exposed services:
- Open chatbot interfaces — instances of self-hosted UIs like OpenUI exposing user conversation histories. Some allow jailbreaking the underlying model entirely.
- Agent management platforms —
n8nandFlowiseinstances exposed without authentication. Attackers reaching these can pivot into integrated third-party systems (Slack, Gmail, internal APIs) the agents are wired into. - Unsecured Ollama APIs — over 31% of Ollama servers queried responded without authentication. An attacker can pull model state, modify workflows, or use the host to redirect traffic.
Why this happens
The pattern across these projects is “insecure by design”:
- Fresh installs drop users straight into a high-privilege account with no auth required
- Setup guides recommend
docker runcommands that bind services to0.0.0.0instead of127.0.0.1 - Hardcoded credentials embedded in
docker-compose.ymlexamples, copy-pasted into production - Arbitrary code execution bugs found in popular AI projects within days of testing
The AI ecosystem is moving faster than its security model. Defaults built for “make it work” are getting deployed into “make it production”.
Defender checklist
If you run any LLM infrastructure, do these now:
- Audit your perimeter for these ports: Ollama on
11434, n8n on5678, Flowise on3000, OpenWebUI on8080 - Verify bind addresses: services should bind to
127.0.0.1(loopback) or an internal network — never0.0.0.0on a public host - Rotate any credentials from setup examples — assume anything in a public README is compromised
- Check Shodan/Censys for your own org’s IP ranges using these queries:
product:"Ollama",title:"n8n",http.title:"Flowise" - For Ollama specifically: set
OLLAMA_HOST=127.0.0.1and put a reverse proxy with auth in front if remote access is needed
Defender’s note: If you’re running self-hosted AI tools “for now while we evaluate them”, they’re production. Treat them that way from day one.
