One $6 Frankfurt server received its first unsolicited packet 3.77 seconds after its listener opened, according to a write-up on dev.to. Ranked by events, addresses or networks, the same log puts a different port at the top each time.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
Plex Media Server 1.43.3 and Desktop 1.115.0 fix flaws that still carry no CVE IDs and no description, which leaves anyone running the server on a NAS waiting on a package manager while the patched builds are already public.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 67%
- Investor
- Investor 10%
Reality
- Evidence55
- Adoption40
- Hype gap+20
- Incentives
- Insufficient
- Confidence55
CVE-2026-91843 lets an attacker with no credentials run code as root through the login process, and Check Point has published indicators of compromise while saying it has seen no exploitation in the wild.
Perspective Coverage
4 publishers
- Builder
- Builder 16%
- Operator
- Operator 75%
- Investor
- Investor 9%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence78
Volexity dates UTA0565's exploitation to September 3 and 4, five to six days before it first reported the chain publicly, delivered from typosquats of China Digital Times and the Center for American Progress and ending in a new implant it calls CLEANGULP.
Reality
- Evidence72
- Adoption58
- Hype gap+8
- Incentives52
- Confidence64
CISA's exploited-vulnerability catalog now holds entries for LiteLLM, Kestra and Starlette, according to a dev.to writeup, and the quickstart docs for those tools still keep provider API keys in the process environment an attacker reads first.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+42
- Incentives32
- Confidence34
Mysterium VPN counted 36,769 self-hosted AI endpoints reachable from the public internet. Ollama is the only population where the scan can prove that nothing on the host asked for credentials.
Reality
- Evidence60
- Adoption70
- Hype gap+12
- Incentives70
- Confidence58
Censys counts more than 294,000 public IPs running one of 43 AI or LLM tools, up from roughly 183,000 in October 2025. The two platforms it names for growth, Langflow and LiteLLM, both carry KEV-listed flaws.
Reality
- Evidence44
- Adoption63
- Hype gap+16
- Incentives71
- Confidence50
CISA says attackers reached programmable logic controllers over the internet during July 2026, changed IP addresses and passwords, and left some utilities unable to monitor their own equipment. No actor has been named.
Reality
- Evidence58
- Adoption55
- Hype gap+6
- Incentives38
- Confidence52
July's intrusions into US water utilities did not need an exploit. They needed a PLC on a cellular modem with nothing in front of it, and CISA's August 21 guidance is an inventory job.
Reality
- Evidence62
- Adoption34
- Hype gap+14
- Incentives38
- Confidence55
The warning as relayed names no agency, no CVE and no actor, which leaves internet reachability as the only control operators can act on. Read access is described as preparation for writes.
Reality
- Evidence26
- Adoption21
- Hype gap+34
- Incentives52
- Confidence33
A Siemens-specific follow-up to the July PLC warning describes internet-wide discovery paired with AI-generated Python tooling that reads and writes ladder logic.
Reality
- Evidence58
- Adoption35
- Hype gap+15
- Incentives40
- Confidence55