The State of the Internet Is Changing: AI Exposures Surge While Global ICS Trends Shift Internet-exposed AI/LLM tool infrastructure has surged over 60% in the past nine months, with more than 294,000 distinct IPs now exposing one of 43 detected tools, up from ~183,000 in October 2025, according to the Censys 2026 State of the Internet Report preview. The highest-risk products, including Langflow (169% growth, 18 CVEs) and LiteLLM (97% growth, actively exploited CVE-2026-42208), are among the fastest growing. Meanwhile, global ICS exposures rose to an average of 138,000 hosts in early 2026, with Asia's share expanding from 22.9% to 27% and Europe's declining from 36.1% to 31.1%, while North America remains the leader at 38%. The Internet is constantly evolving. New technologies emerge, infrastructure shifts, software ages, and global adoption patterns change. Some of these changes introduce new security risks, while others reveal broader shifts in how the Internet itself is built and used. The Censys State of the Internet Report https://censys.com/reports/2025-sotir/ is our annual assessment of how the public Internet is evolving. It draws on continuous observations from the Censys Internet Map and Censys ARC’s Internet measurement and security research to examine the technologies, infrastructure, and long-term trends shaping today’s Internet. The 2026 Censys State of the Internet Report , publishing this fall, expands on that research with new analysis of the technologies, infrastructure, and security trends shaping the Internet today. As a preview, we’re sharing several early findings from this year’s report, including the rapid growth of Internet-exposed AI infrastructure and shifting global trends in Internet-exposed industrial control systems ICS . AI Adoption Is Accelerating — And So Are Internet Exposures AI/LLM tool exposures have risen over 60% in the past 9 months . Over 294,000 distinct IPs now expose one of 43 detected AI/LLM tools to the public Internet, up from ~183,000 in October 2025. What’s more, the highest-risk AI/LLM products are also among the fastest growing. For example, Langflow grew 169% in the last nine months, and it has accumulated 18 CVEs in 2024-2026 14 with a CVSS score above 8.0 , including 4 CISA KEV entries. Multiple unauthenticated remote code execution RCE vulnerabilities make any Internet-exposed instance a critical finding. Similarly, LiteLLM nearly doubled +97% in the 9-month timeframe, and it has an actively exploited pre-auth SQL injection CVE-2026-42208, CISA KEV ; as a unified LLM proxy, a single compromise exposes API keys for every upstream model provider. Get the 2026 State of the Internet Report as soon as it publishes Coming this Fall. Pre-register now to stay on top of the latest Internet intelligence. The Global Distribution of Internet-Exposed ICS Continues to Shift Censys observes an average of 138,000 distinct hosts running ICS services and tooling exposed on the Internet in early 2026, up from about 129,000 in 2024. As of 2026, North America continues to lead in exposures, representing roughly 38% of the global ICS landscape . While this is consistent with past findings, we note that Asia’s ICS footprint has expanded from 22.9% of exposures in 2024 to 27% in 2026. In contrast, Europe’s ICS exposure represents slightly less of the global total, from 36.1% in 2024 to 31.1% in 2026 . While the geography of exposed ICS devices has shifted over time, the types of networks where we observe them has remained remarkably stable. Roughly 70% of hosts running ICS devices and services globally are consistently found on consumer and mobile networks for the last 2.5 years. What to Expect in the 2026 Censys State of the Internet Report These findings are just a preview of this year’s report. The full 2026 Censys State of the Internet Report explores how the Internet is evolving through Internet measurement and security research from the Censys ARC team. This year’s report will provide in-depth explorations and analyses of the following: The Internet at Large The Censys Internet Map enables us to continuously measure the Internet at global scale. We’ll examine emerging trends across hosts, services, networks, and geographies, and explore what infrastructure choices—from ports and protocols to certificate authorities and end-of-life software—reveal about how the Internet is evolving. The Internet’s Response to Emerging Vulnerabilities A longitudinal study of how software ecosystems respond to vulnerability disclosures, including CVEs and additions to CISA’s Known Exploited Vulnerabilities KEV catalog. We’ll examine how quickly observable Internet exposure changes following disclosure—and where exposure persists despite continued advisories and active exploitation. Industrial Control Systems and Critical Infrastructure An updated assessment of Internet-exposed ICS, including how global exposures have shifted over the past 2.5 years across geographic regions and network types. AI Infrastructure and Internet Exposure An analysis of Internet-exposed AI infrastructure—including MCP servers, Ollama, Langflow, LiteLLM, and AI automation frameworks—examining adoption trends, geographic distribution, and how their Internet presence has evolved over time. Pre-Register for the 2026 State of the Internet Report The Internet and its threats are constantly evolving. Understanding how Internet-facing technologies and exposures change over time helps security teams anticipate emerging risks. To stay on top of the latest Internet intelligence, trends, and insights, pre-register for the 2026 Censys State of the Internet Report https://info.censys.com/-state-of-the-internet-2026 . You’ll receive a copy as soon as it publishes this fall.