Where the Panels Live: Network Footprint Patterns of Exposed AI Gateways After the CISA Advisory
AA26-251A describes centralized routing infrastructure with real-time health monitoring and automated failover between pathways. That kind of orchestration leaves patterns in where and how the panels are hosted. External asset data can outline those patterns.
Transport distribution
In our check on 2026-09-22, title="new-api" && port=443 matched 13,170 assets. The remainder of the 56,800-title match therefore runs on other ports or plain HTTP, a footprint consistent with quickly deployed panels that never went through a formal deployment process.
Host distribution
A country-scoped query, title="new-api" && country="US", matched 23,038 assets. Panels concentrate where hosting is cheap and where operators expect less friction. No single hosting footprint is inherent to the abuse; the advisory instead describes deliberate distribution across providers to avoid single-point detection.
Reading the footprint safely
Treat hosting location as a routing fact, not an attribution signal.
Compare port and protocol distributions across time, not just totals.
Use org/ASN views to cluster related panels for correlation with internal abuse reports.
Limitations
Port and country counts describe indexed assets on one date. Panels behind CDNs, reverse proxies or shared hosts may not resolve to their actual operator. The advisory's routing-system description covers native APIs, cloud providers, aggregators, relays and vendor account pools, some of which leave no public panel at all.
References
- CISA Advisory AA26-251A: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
- ZoomEye: https://www.zoomeye.ai
Top comments (0)