Tens of Thousands of Data Pipeline Services Exposed Publicly, Scan Finds
A ZoomEye scan conducted on 22 September 2026 found over 45,000 ClickHouse instances, nearly 16,000 Cassandra nodes, and thousands of InfluxDB, MQTT, and Elasticsearch services reachable on public interfaces. Many of these services — including ClickHouse and older InfluxDB deployments — do not require authentication by default, leaving sensitive data directly accessible. MQTT brokers without access controls pose an additional risk, as they can be exploited not just to read device data but also to inject commands into connected IoT fleets. These data pipeline services are typically managed by engineering teams rather than security teams, meaning they often fall outside formal security asset inventories. The findings highlight a systemic gap where infrastructure critical to organisational operations is routinely left exposed due to default configurations and unclear ownership.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in