<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>NuClide Research, Engagement records</title><description>Per-instance engagement records across commercial, government, university, K-12, and critical-infrastructure sectors.</description><link>https://nuclide-research.com/</link><language>en-us</language><item><title>Cat-29 Argo Workflows: :2746 probe sweep, 2026-06-07</title><link>https://nuclide-research.com/cases/case-studies--commercial--cat29-argo-2746-2026-06-07/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--cat29-argo-2746-2026-06-07/</guid><description>Lane 1A of the 9-item 2026-06-07 plan. Goal: test whether port 2746 hosts an unauthenticated Shodan-dark tier among Argo Workflows operators whose :443 surface is gated by IAP/AzureAD. Method: parallel curl probes (5-second timeout) against https://&lt;ip&gt;:2746/api/v1/version for all 156 IPs surfaced via the ssl:&quot;Argo Workflows&quot; Shodan dork during the 2026-05-3…</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--cat29-argo-2746-2026-06-07.png&quot; alt=&quot;Cat-29 Argo Workflows: :2746 probe sweep, 2026-06-07&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Lane 1A of the 9-item 2026-06-07 plan. Goal: test whether port 2746 hosts an unauthenticated Shodan-dark tier among Argo Workflows operators whose :443 surface is gated by IAP/AzureAD. Method: parallel curl probes (5-second timeout) against https://&amp;lt;ip&amp;gt;:2746/api/v1/version for all 156 IPs surfaced via the ssl:&amp;quot;Argo Workflows&amp;quot; Shodan dork during the 2026-05-3…&lt;/p&gt;
&lt;p&gt;Lane 1A of the 9-item 2026-06-07 plan. Goal: test whether port 2746 hosts an unauthenticated Shodan-dark tier among Argo Workflows operators whose :443 surface is gated by IAP/AzureAD. Method: parallel curl probes (5-second timeout) against https://&amp;lt;ip&amp;gt;:2746/api/v1/version for all 156 IPs surfaced via the ssl:&amp;quot;Argo Workflows&amp;quot; Shodan dork during the 2026-05-31 Cat-29 survey. Result: 156/156 connection timeouts. Zero HTTP responses on :2746.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--cat29-argo-2746-2026-06-07/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--cat29-argo-2746-2026-06-07.png" length="0" type="image/png"/></item><item><title>DMARC Funding-Stage Proxy — Full-Registry Sweep N=410</title><link>https://nuclide-research.com/cases/case-studies--commercial--dmarc-funding-stage-proxy-2026-06-07/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--dmarc-funding-stage-proxy-2026-06-07/</guid><description>Date: 2026-06-07. Cohort: full NuClide AI-infrastructure vendor registry (MASTER-port-vendor-registry.csv, 435 vendor names, 410 unique apex domains resolved after dedup and OSS filtering). Probe: dig +short TXT dmarc.&lt;domain&gt;. Fully passive otherwise.</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--dmarc-funding-stage-proxy-2026-06-07.png&quot; alt=&quot;DMARC Funding-Stage Proxy — Full-Registry Sweep N=410&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Date: 2026-06-07. Cohort: full NuClide AI-infrastructure vendor registry (MASTER-port-vendor-registry.csv, 435 vendor names, 410 unique apex domains resolved after dedup and OSS filtering). Probe: dig +short TXT dmarc.&amp;lt;domain&amp;gt;. Fully passive otherwise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--dmarc-funding-stage-proxy-2026-06-07/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--dmarc-funding-stage-proxy-2026-06-07.png" length="0" type="image/png"/></item><item><title>MCP Servers and CrewAI — Negative Results with Methodology Value</title><link>https://nuclide-research.com/cases/case-studies--commercial--mcp-crewai-negative-results-2026-06-07/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--mcp-crewai-negative-results-2026-06-07/</guid><description>Two attempted same-day surveys produced no actionable findings — but the failure modes are themselves research-program-relevant. Both reveal classes of AI/LLM infrastructure that are not surveyable with the population-Shodan methodology that worked for the chat-UI / RAG / observability / autonomous-agent platform surveys.</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--mcp-crewai-negative-results-2026-06-07.png&quot; alt=&quot;MCP Servers and CrewAI — Negative Results with Methodology Value&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Two attempted same-day surveys produced no actionable findings — but the failure modes are themselves research-program-relevant. Both reveal classes of AI/LLM infrastructure that are not surveyable with the population-Shodan methodology that worked for the chat-UI / RAG / observability / autonomous-agent platform surveys.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--mcp-crewai-negative-results-2026-06-07/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--mcp-crewai-negative-results-2026-06-07.png" length="0" type="image/png"/></item><item><title>LibreChat Verification Deep-Dive — Notable Findings Re-Profiled</title><link>https://nuclide-research.com/cases/case-studies--commercial--librechat-deep-dive-verification-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--librechat-deep-dive-verification-2026-06-06/</guid><description>Deeper verification on the six notable finding clusters surfaced in the LibreChat population survey. Restraint maintained throughout: no registration, no LLM invocation, no account creation. Methods used: /api/config, /api/endpoints, PTR lookup, TLS cert inspection, WHOIS, marketing-site cross-reference.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--librechat-deep-dive-verification-2026-06-06.png&quot; alt=&quot;LibreChat Verification Deep-Dive — Notable Findings Re-Profiled&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Deeper verification on the six notable finding clusters surfaced in the LibreChat population survey. Restraint maintained throughout: no registration, no LLM invocation, no account creation. Methods used: /api/config, /api/endpoints, PTR lookup, TLS cert inspection, WHOIS, marketing-site cross-reference.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--librechat-deep-dive-verification-2026-06-06/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--librechat-deep-dive-verification-2026-06-06.png" length="0" type="image/png"/></item><item><title>Unauthenticated ML Training Server — velutina-service.ch</title><link>https://nuclide-research.com/cases/case-studies--commercial--velutina-service-ch-unauth-ml-training-server-2026-06-01/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--velutina-service-ch-unauth-ml-training-server-2026-06-01/</guid><description>JAXEN returned 185.66.109.62 under a passive Shodan query for exposed AI/ML infrastructure on Swiss hosting ranges. The Shodan record showed:</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--velutina-service-ch-unauth-ml-training-server-2026-06-01.png&quot; alt=&quot;Unauthenticated ML Training Server — velutina-service.ch&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;JAXEN returned 185.66.109.62 under a passive Shodan query for exposed AI/ML infrastructure on Swiss hosting ranges. The Shodan record showed:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--velutina-service-ch-unauth-ml-training-server-2026-06-01/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--velutina-service-ch-unauth-ml-training-server-2026-06-01.png" length="0" type="image/png"/></item><item><title>Dark-Tier Probe Result (Option A) — 2026-05-31</title><link>https://nuclide-research.com/cases/case-studies--commercial--argo-workflows-darktier-2026-05-31/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--argo-workflows-darktier-2026-05-31/</guid><description>&lt;!-- ksat-tag:auto-generated:start --&gt;
## DCWF KSAT coverage</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--argo-workflows-darktier-2026-05-31.png&quot; alt=&quot;Dark-Tier Probe Result (Option A) — 2026-05-31&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- ksat-tag:auto-generated:start --&amp;gt;
## DCWF KSAT coverage&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--argo-workflows-darktier-2026-05-31/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--argo-workflows-darktier-2026-05-31.png" length="0" type="image/png"/></item><item><title>NCKU Edge Host: a Kubernetes Control Plane Behind a MikroTik Gateway</title><link>https://nuclide-research.com/cases/case-studies--universities--ncku-140116247125-edge-kubesphere-2026-05-31/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--ncku-140116247125-edge-kubesphere-2026-05-31/</guid><description>A single handed-over IP resolved into an NCKU lab&apos;s internet edge: a MikroTik
RouterOS gateway DNAT-forwarding to an internal network, with eighteen services
reachable through it. The headline exposure is not an AI service. It is a
KubeSphere v3.1.0 Kubernetes management console, branded &quot;ECPaaS,&quot; reachable on
tcp/23180, leaking its version, its unchanged de…</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--ncku-140116247125-edge-kubesphere-2026-05-31.png&quot; alt=&quot;NCKU Edge Host: a Kubernetes Control Plane Behind a MikroTik Gateway&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;A single handed-over IP resolved into an NCKU lab&amp;#39;s internet edge: a MikroTik
RouterOS gateway DNAT-forwarding to an internal network, with eighteen services
reachable through it. The headline exposure is not an AI service. It is a
KubeSphere v3.1.0 Kubernetes management console, branded &amp;quot;ECPaaS,&amp;quot; reachable on
tcp/23180, leaking its version, its unchanged de…&lt;/p&gt;
&lt;p&gt;A single handed-over IP resolved into an NCKU lab&amp;#39;s internet edge: a MikroTik
RouterOS gateway DNAT-forwarding to an internal network, with eighteen services
reachable through it. The headline exposure is not an AI service. It is a
KubeSphere v3.1.0 Kubernetes management console, branded &amp;quot;ECPaaS,&amp;quot; reachable on
tcp/23180, leaking its version, its unchanged default JWT secret, and its preset
usernames in the page source. Alongside it sits a Django app running with
DEBUG=True in production. The assessment is a clean example of a curated AI-port
scanner reporting &amp;quot;no AI service&amp;quot; on a host that is, in fact, badly exposed.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--ncku-140116247125-edge-kubesphere-2026-05-31/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--ncku-140116247125-edge-kubesphere-2026-05-31.png" length="0" type="image/png"/></item><item><title>Voice/Audio AI re-run: Category 17, 2026-05-29</title><link>https://nuclide-research.com/cases/case-studies--commercial--voice-audio-ai-rerun-2026-05-29/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--voice-audio-ai-rerun-2026-05-29/</guid><description>Fifteen dorks. Twenty-eight candidates. Six confirmed unauthenticated voice
services across five hosts. One four-service stacked host. Four false positives
killed at the verification stage, including a would-be remote-code-execution
finding that turned out to be an LLM relay server.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--voice-audio-ai-rerun-2026-05-29.png&quot; alt=&quot;Voice/Audio AI re-run: Category 17, 2026-05-29&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Fifteen dorks. Twenty-eight candidates. Six confirmed unauthenticated voice
services across five hosts. One four-service stacked host. Four false positives
killed at the verification stage, including a would-be remote-code-execution
finding that turned out to be an LLM relay server.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--voice-audio-ai-rerun-2026-05-29/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--voice-audio-ai-rerun-2026-05-29.png" length="0" type="image/png"/></item><item><title>Zep CE: empty default api_secret accepts a zero-entropy credential</title><link>https://nuclide-research.com/cases/case-studies--commercial--zep-ce-empty-apisecret-finding-2026-05-29/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--zep-ce-empty-apisecret-finding-2026-05-29/</guid><description>Code-level finding from the agent-memory pre-assessment
(data/platform-intel/agent-memory-osint-2026-05-29.md). Labeled per
case-studies/FINDING-TEMPLATE.md. This is a platform finding, not a host
case study: no live target has been touched.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--zep-ce-empty-apisecret-finding-2026-05-29.png&quot; alt=&quot;Zep CE: empty default api_secret accepts a zero-entropy credential&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Code-level finding from the agent-memory pre-assessment
(data/platform-intel/agent-memory-osint-2026-05-29.md). Labeled per
case-studies/FINDING-TEMPLATE.md. This is a platform finding, not a host
case study: no live target has been touched.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--zep-ce-empty-apisecret-finding-2026-05-29/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--zep-ce-empty-apisecret-finding-2026-05-29.png" length="0" type="image/png"/></item><item><title>Apptica — Production Data Lake Exposed via Unauthenticated ClickHouse</title><link>https://nuclide-research.com/cases/case-studies--commercial--apptica-clickhouse-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--apptica-clickhouse-2026-05-28/</guid><description>Apptica is a commercial app store intelligence platform offering revenue estimates, download data, keyword rankings, and advertising intelligence for mobile apps across iOS and Android. Their product — described as &quot;Ad Intelligence&quot; and &quot;Market Intelligence&quot; — is built on the data stored in this database.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--apptica-clickhouse-2026-05-28.png&quot; alt=&quot;Apptica — Production Data Lake Exposed via Unauthenticated ClickHouse&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Apptica is a commercial app store intelligence platform offering revenue estimates, download data, keyword rankings, and advertising intelligence for mobile apps across iOS and Android. Their product — described as &amp;quot;Ad Intelligence&amp;quot; and &amp;quot;Market Intelligence&amp;quot; — is built on the data stored in this database.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--apptica-clickhouse-2026-05-28/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--apptica-clickhouse-2026-05-28.png" length="0" type="image/png"/></item><item><title>DataV / Skillmine Technology — Multi-Party Data Breach via Unauthenticated ClickHouse</title><link>https://nuclide-research.com/cases/case-studies--commercial--datav-skillmine-clickhouse-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--datav-skillmine-clickhouse-2026-05-28/</guid><description>DataV is a no-code AI analytics and data visualization platform built and operated by Skillmine Technology Consulting Private Limited (Mumbai). The platform allows customers to upload CSV and Excel files, connect SQL databases, run ML predictions, and build dashboards. Per their website, DataV serves organizations across BFSI, healthcare, IT services, automo…</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--datav-skillmine-clickhouse-2026-05-28.png&quot; alt=&quot;DataV / Skillmine Technology — Multi-Party Data Breach via Unauthenticated ClickHouse&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;DataV is a no-code AI analytics and data visualization platform built and operated by Skillmine Technology Consulting Private Limited (Mumbai). The platform allows customers to upload CSV and Excel files, connect SQL databases, run ML predictions, and build dashboards. Per their website, DataV serves organizations across BFSI, healthcare, IT services, automo…&lt;/p&gt;
&lt;p&gt;DataV is a no-code AI analytics and data visualization platform built and operated by Skillmine Technology Consulting Private Limited (Mumbai). The platform allows customers to upload CSV and Excel files, connect SQL databases, run ML predictions, and build dashboards. Per their website, DataV serves organizations across BFSI, healthcare, IT services, automotive, and e-commerce.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--datav-skillmine-clickhouse-2026-05-28/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--datav-skillmine-clickhouse-2026-05-28.png" length="0" type="image/png"/></item><item><title>Sanio AI — Collision AgentOS / Walmart Pipeline Exposure</title><link>https://nuclide-research.com/cases/case-studies--commercial--sanio-ai-collision-agentos-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--sanio-ai-collision-agentos-2026-05-28/</guid><description>Surface identified in session 43 (cat-06 stragglers survey) via Shodan dork port:7777 http.html:&quot;agno&quot;. Prior session confirmed the host as unauth Agno on port 7777 with road collision data in scope. This session ran five parallel agents for full stack enumeration.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--sanio-ai-collision-agentos-2026-05-28.png&quot; alt=&quot;Sanio AI — Collision AgentOS / Walmart Pipeline Exposure&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Surface identified in session 43 (cat-06 stragglers survey) via Shodan dork port:7777 http.html:&amp;quot;agno&amp;quot;. Prior session confirmed the host as unauth Agno on port 7777 with road collision data in scope. This session ran five parallel agents for full stack enumeration.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--sanio-ai-collision-agentos-2026-05-28/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--sanio-ai-collision-agentos-2026-05-28.png" length="0" type="image/png"/></item><item><title>Snap-E Cabs — ScyllaDB Default Credentials + Unauthenticated REST API</title><link>https://nuclide-research.com/cases/case-studies--commercial--snapecabs-scylladb-341319052-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--snapecabs-scylladb-341319052-2026-05-28/</guid><description>Snap-E Cabs, a BSE-listed Indian EV ride-hailing operator (600+ vehicles, Kolkata), runs a ScyllaDB cluster on GCP with the CQL port accepting default cassandra/cassandra credentials and the admin REST API exposed with zero authentication — giving any actor full read/write access to 431,808 driver safety events, 245 live auth tokens, biometric face ROI data,…</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--snapecabs-scylladb-341319052-2026-05-28.png&quot; alt=&quot;Snap-E Cabs — ScyllaDB Default Credentials + Unauthenticated REST API&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Snap-E Cabs, a BSE-listed Indian EV ride-hailing operator (600+ vehicles, Kolkata), runs a ScyllaDB cluster on GCP with the CQL port accepting default cassandra/cassandra credentials and the admin REST API exposed with zero authentication — giving any actor full read/write access to 431,808 driver safety events, 245 live auth tokens, biometric face ROI data,…&lt;/p&gt;
&lt;p&gt;Snap-E Cabs, a BSE-listed Indian EV ride-hailing operator (600+ vehicles, Kolkata), runs a ScyllaDB cluster on GCP with the CQL port accepting default cassandra/cassandra credentials and the admin REST API exposed with zero authentication — giving any actor full read/write access to 431,808 driver safety events, 245 live auth tokens, biometric face ROI data, real-time vehicle GPS, and live video stream session management.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--snapecabs-scylladb-341319052-2026-05-28/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--snapecabs-scylladb-341319052-2026-05-28.png" length="0" type="image/png"/></item><item><title>Argo Workflows — Pre-Assessment OSINT Brief (2026-05-27)</title><link>https://nuclide-research.com/cases/case-studies--commercial--argo-workflows-osint-pre-assessment-2026-05-27/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--argo-workflows-osint-pre-assessment-2026-05-27/</guid><description>Intelligence gathered before the population scan to fine-tune dork selection, fingerprint design, verification methodology, and scope. Not a survey — a survey prep document. The scan chain runs after this.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--argo-workflows-osint-pre-assessment-2026-05-27.png&quot; alt=&quot;Argo Workflows — Pre-Assessment OSINT Brief (2026-05-27)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Intelligence gathered before the population scan to fine-tune dork selection, fingerprint design, verification methodology, and scope. Not a survey — a survey prep document. The scan chain runs after this.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--argo-workflows-osint-pre-assessment-2026-05-27/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--argo-workflows-osint-pre-assessment-2026-05-27.png" length="0" type="image/png"/></item><item><title>Cat-06 Stragglers: Agno Auth-Off-Default, GPT Researcher 14 Unauth, Walmart Temporal Exposure</title><link>https://nuclide-research.com/cases/case-studies--commercial--agno-gptresearcher-agentgpt-cat06-stragglers-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--agno-gptresearcher-agentgpt-cat06-stragglers-2026-05-26/</guid><description>Agno ships with no authentication. The playground server (uvicorn, port 7777) returns full agent manifests and run histories to any caller. Three confirmed Agno deployments expose AI agents with live database, email, call-transcript, and document access.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--agno-gptresearcher-agentgpt-cat06-stragglers-2026-05-26.png&quot; alt=&quot;Cat-06 Stragglers: Agno Auth-Off-Default, GPT Researcher 14 Unauth, Walmart Temporal Exposure&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Agno ships with no authentication. The playground server (uvicorn, port 7777) returns full agent manifests and run histories to any caller. Three confirmed Agno deployments expose AI agents with live database, email, call-transcript, and document access.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--agno-gptresearcher-agentgpt-cat06-stragglers-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--agno-gptresearcher-agentgpt-cat06-stragglers-2026-05-26.png" length="0" type="image/png"/></item><item><title>BackGround Studio CRM — Credential Leak, DatingUser Records in Redis</title><link>https://nuclide-research.com/cases/case-studies--commercial--background-studio-crm-redisinsight-chain-b-65-21-151-67-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--background-studio-crm-redisinsight-chain-b-65-21-151-67-2026-05-26/</guid><description>The Redis password was in the GUI. It worked. One key. 99 users in a dating platform sorted set.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--background-studio-crm-redisinsight-chain-b-65-21-151-67-2026-05-26.png&quot; alt=&quot;BackGround Studio CRM — Credential Leak, DatingUser Records in Redis&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;The Redis password was in the GUI. It worked. One key. 99 users in a dating platform sorted set.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--background-studio-crm-redisinsight-chain-b-65-21-151-67-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--background-studio-crm-redisinsight-chain-b-65-21-151-67-2026-05-26.png" length="0" type="image/png"/></item><item><title>CampusIRIS Dev Environment — Credential Leak via RedisInsight, Student Data Schema Exposed</title><link>https://nuclide-research.com/cases/case-studies--commercial--campusiris-redisinsight-chain-b-150-230-235-79-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--campusiris-redisinsight-chain-b-150-230-235-79-2026-05-26/</guid><description>RedisInsight left the Redis password in plain sight. The password worked. Behind it: 115 keys of a multi-tenant school SaaS, student attendance records, 24k session IDs, and tenant database connection strings.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--campusiris-redisinsight-chain-b-150-230-235-79-2026-05-26.png&quot; alt=&quot;CampusIRIS Dev Environment — Credential Leak via RedisInsight, Student Data Schema Exposed&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;RedisInsight left the Redis password in plain sight. The password worked. Behind it: 115 keys of a multi-tenant school SaaS, student attendance records, 24k session IDs, and tenant database connection strings.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--campusiris-redisinsight-chain-b-150-230-235-79-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--campusiris-redisinsight-chain-b-150-230-235-79-2026-05-26.png" length="0" type="image/png"/></item><item><title>CMS Production Redis — RedisInsight Credential Leak, Chain B</title><link>https://nuclide-research.com/cases/case-studies--commercial--cms-prod-redis-redisinsight-chain-b-3521076182-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--cms-prod-redis-redisinsight-chain-b-3521076182-2026-05-26/</guid><description>RedisInsight 2.36.0 at port 8001 requires no authentication. GET /api/databases returns the Redis AUTH password in plaintext. AUTH confirms on port 6379. Keyspace: 154 keys. Apollo GraphQL dev-api: full introspection unauth, getCustomUsersCsv executed without credential and returned a live GCS signed URL, 8,650 artist records returned unauth, sendPushNotificationsToUsers schema maps platform-wide push. APAC node 34.87.179.212 firewalled on all ports.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--cms-prod-redis-redisinsight-chain-b-3521076182-2026-05-26.png&quot; alt=&quot;CMS Production Redis — RedisInsight Credential Leak, Chain B&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;RedisInsight 2.36.0 at port 8001 requires no authentication. GET /api/databases returns the Redis AUTH password in plaintext. AUTH confirms on port 6379. Keyspace: 154 keys. Apollo GraphQL dev-api: full introspection unauth, getCustomUsersCsv executed without credential and returned a live GCS signed URL, 8,650 artist records returned unauth, sendPushNotificationsToUsers schema maps platform-wide push. APAC node 34.87.179.212 firewalled on all ports.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--cms-prod-redis-redisinsight-chain-b-3521076182-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--cms-prod-redis-redisinsight-chain-b-3521076182-2026-05-26.png" length="0" type="image/png"/></item><item><title>CPAC Strapi CMS — Production API Surface Enumeration</title><link>https://nuclide-research.com/cases/case-studies--commercial--cpac-scg-strapi-api-cpac-co-th-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--cpac-scg-strapi-api-cpac-co-th-2026-05-26/</guid><description>Second node in the CPAC chain. The primary finding is in cpacredis-redisinsight-chain-b-178.128.84.65-2026-05-26.md. The Redis credential prefix cpacredis pivoted to cpac.co.th, which resolved to a Strapi CMS instance serving the CPAC website backend. This document covers the Strapi surface.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--cpac-scg-strapi-api-cpac-co-th-2026-05-26.png&quot; alt=&quot;CPAC Strapi CMS — Production API Surface Enumeration&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Second node in the CPAC chain. The primary finding is in cpacredis-redisinsight-chain-b-178.128.84.65-2026-05-26.md. The Redis credential prefix cpacredis pivoted to cpac.co.th, which resolved to a Strapi CMS instance serving the CPAC website backend. This document covers the Strapi surface.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--cpac-scg-strapi-api-cpac-co-th-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--cpac-scg-strapi-api-cpac-co-th-2026-05-26.png" length="0" type="image/png"/></item><item><title>cpacredis — RedisInsight Credential Leak on Fleet Telematics Platform</title><link>https://nuclide-research.com/cases/case-studies--commercial--cpacredis-redisinsight-chain-b-1781288465-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--cpacredis-redisinsight-chain-b-1781288465-2026-05-26/</guid><description>RedisInsight at :8001 requires no authentication. The stored Redis password cpacredis0242 appears in plaintext in the /api/databases response. Behind that credential: a Thai Ready Mix concrete fleet telematics platform, with 5,348 vehicle records and 206 driver status records containing Thai national ID numbers (บัตรประชาชน).</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--cpacredis-redisinsight-chain-b-1781288465-2026-05-26.png&quot; alt=&quot;cpacredis — RedisInsight Credential Leak on Fleet Telematics Platform&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;RedisInsight at :8001 requires no authentication. The stored Redis password cpacredis0242 appears in plaintext in the /api/databases response. Behind that credential: a Thai Ready Mix concrete fleet telematics platform, with 5,348 vehicle records and 206 driver status records containing Thai national ID numbers (บัตรประชาชน).&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--cpacredis-redisinsight-chain-b-1781288465-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--cpacredis-redisinsight-chain-b-1781288465-2026-05-26.png" length="0" type="image/png"/></item><item><title>difinance.online — RedisInsight Credential Leak on Telegram DeFi Bot</title><link>https://nuclide-research.com/cases/case-studies--commercial--difinance-telegram-bot-redisinsight-3112997101-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--difinance-telegram-bot-redisinsight-3112997101-2026-05-26/</guid><description>RedisInsight on port 8001 required no authentication. GET /api/databases returned the full Redis connection object, including the password Sq3QmHxJCPn5Dt4LzAaNRg in plaintext. The credential gave direct AUTH access to Redis 7.2.4. The instance held aiogram FSM state for a Telegram bot and Celery queue bindings — infrastructure for a DeFi financial services b…</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--difinance-telegram-bot-redisinsight-3112997101-2026-05-26.png&quot; alt=&quot;difinance.online — RedisInsight Credential Leak on Telegram DeFi Bot&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;RedisInsight on port 8001 required no authentication. GET /api/databases returned the full Redis connection object, including the password Sq3QmHxJCPn5Dt4LzAaNRg in plaintext. The credential gave direct AUTH access to Redis 7.2.4. The instance held aiogram FSM state for a Telegram bot and Celery queue bindings — infrastructure for a DeFi financial services b…&lt;/p&gt;
&lt;p&gt;RedisInsight on port 8001 required no authentication. GET /api/databases returned the full Redis connection object, including the password Sq3QmHxJCPn5Dt4LzAaNRg in plaintext. The credential gave direct AUTH access to Redis 7.2.4. The instance held aiogram FSM state for a Telegram bot and Celery queue bindings — infrastructure for a DeFi financial services bot operating under the domain difinance.online.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--difinance-telegram-bot-redisinsight-3112997101-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--difinance-telegram-bot-redisinsight-3112997101-2026-05-26.png" length="0" type="image/png"/></item><item><title>EPOLCA — RedisInsight Credential Leak on Industrial Simulation Demo Server</title><link>https://nuclide-research.com/cases/case-studies--commercial--epolca-redisinsight-chain-b-116203208124-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--epolca-redisinsight-chain-b-116203208124-2026-05-26/</guid><description>RedisInsight exposed the Redis password for an ePolca production planning demo server on Hetzner DE; AUTH succeeded and revealed six keys covering factory simulation results, KPI states, and production orders — all scoped to the EPOLCA_DEMOS namespace.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--epolca-redisinsight-chain-b-116203208124-2026-05-26.png&quot; alt=&quot;EPOLCA — RedisInsight Credential Leak on Industrial Simulation Demo Server&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;RedisInsight exposed the Redis password for an ePolca production planning demo server on Hetzner DE; AUTH succeeded and revealed six keys covering factory simulation results, KPI states, and production orders — all scoped to the EPOLCA_DEMOS namespace.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--epolca-redisinsight-chain-b-116203208124-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--epolca-redisinsight-chain-b-116203208124-2026-05-26.png" length="0" type="image/png"/></item><item><title>Evolution API WhatsApp Broker — RedisInsight Open, 117 Keys Including WhatsApp Session State and Lead Phone Numbers</title><link>https://nuclide-research.com/cases/case-studies--commercial--n8n-redis-redisinsight-192169812-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--n8n-redis-redisinsight-192169812-2026-05-26/</guid><description>Brazilian WhatsApp automation SaaS bmaconnect.com.br runs RedisInsight 2.42.0 with no authentication on port 8001, exposing full read/write access to Redis 7.4.7 (n8n-redis-1). 117 keys confirmed: 7 Evolution API WhatsApp session hashes (208KB to 1.16MB), 108 Brazilian phone number conversation queues across 5 named operator clients, and an n8n scheduling key with unresolved lead-number expression. Evolution API 2.3.7 on port 8080 enforces auth on instance management. n8n 1.122.5 (development mode) proxied via ia.bmaconnect.com.br. Second server at 179.190.63.39 for api./zion-teste. subdomains. 90 unique Brazilian phone numbers exposed in key names.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--n8n-redis-redisinsight-192169812-2026-05-26.png&quot; alt=&quot;Evolution API WhatsApp Broker — RedisInsight Open, 117 Keys Including WhatsApp Session State and Lead Phone Numbers&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Brazilian WhatsApp automation SaaS bmaconnect.com.br runs RedisInsight 2.42.0 with no authentication on port 8001, exposing full read/write access to Redis 7.4.7 (n8n-redis-1). 117 keys confirmed: 7 Evolution API WhatsApp session hashes (208KB to 1.16MB), 108 Brazilian phone number conversation queues across 5 named operator clients, and an n8n scheduling key with unresolved lead-number expression. Evolution API 2.3.7 on port 8080 enforces auth on instance management. n8n 1.122.5 (development mode) proxied via ia.bmaconnect.com.br. Second server at 179.190.63.39 for api./zion-teste. subdomains. 90 unique Brazilian phone numbers exposed in key names.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--n8n-redis-redisinsight-192169812-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--n8n-redis-redisinsight-192169812-2026-05-26.png" length="0" type="image/png"/></item><item><title>Cat-04 Stragglers: Prefect Auth-Off-Default, Dask University Clusters, ClearML Ransomed ES</title><link>https://nuclide-research.com/cases/case-studies--commercial--prefect-dask-clearml-cat04-stragglers-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--prefect-dask-clearml-cat04-stragglers-2026-05-26/</guid><description>Prefect workflow orchestration is auth-off-default. /api/admin/settings is world-readable on all instances. /api/flows/filter and /api/deployments/filter return complete workflow inventories without credentials. Nine of fifteen sampled instances returned full unauth access; extrapolated across 66 confirmed live instances, 40 are likely unauth.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--prefect-dask-clearml-cat04-stragglers-2026-05-26.png&quot; alt=&quot;Cat-04 Stragglers: Prefect Auth-Off-Default, Dask University Clusters, ClearML Ransomed ES&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Prefect workflow orchestration is auth-off-default. /api/admin/settings is world-readable on all instances. /api/flows/filter and /api/deployments/filter return complete workflow inventories without credentials. Nine of fifteen sampled instances returned full unauth access; extrapolated across 66 confirmed live instances, 40 are likely unauth.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--prefect-dask-clearml-cat04-stragglers-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--prefect-dask-clearml-cat04-stragglers-2026-05-26.png" length="0" type="image/png"/></item><item><title>ORES CRM (CloudWorks/ows.vn) — Redis Stack Open, 17,337 Chatbot Conversation Records, Multi-Channel Social PII</title><link>https://nuclide-research.com/cases/case-studies--commercial--vietnamese-chatbot-crm-redis-stack-12521222737-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--vietnamese-chatbot-crm-redis-stack-12521222737-2026-05-26/</guid><description>ORES, a Vietnamese AI-chatbot CRM SaaS built by CloudWorks (ows.vn), runs Redis Stack at 125.212.227.37 without authentication. Two RediSearch indexes expose 34 channel accounts and 17,337 conversation records. Key names confirm multi-channel routing across Zalo, Facebook Page, Zalo OA, and Pancake. The account:index schema stores a token field: OAuth credentials for each connected social channel. The host is the backend for my.ores.vn, proxied through ssl-proxy2.ows.vn at the adjacent IP 125.212.227.40. ASN: AS7552 Viettel Group, Vietnam.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--vietnamese-chatbot-crm-redis-stack-12521222737-2026-05-26.png&quot; alt=&quot;ORES CRM (CloudWorks/ows.vn) — Redis Stack Open, 17,337 Chatbot Conversation Records, Multi-Channel Social PII&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;ORES, a Vietnamese AI-chatbot CRM SaaS built by CloudWorks (ows.vn), runs Redis Stack at 125.212.227.37 without authentication. Two RediSearch indexes expose 34 channel accounts and 17,337 conversation records. Key names confirm multi-channel routing across Zalo, Facebook Page, Zalo OA, and Pancake. The account:index schema stores a token field: OAuth credentials for each connected social channel. The host is the backend for my.ores.vn, proxied through ssl-proxy2.ows.vn at the adjacent IP 125.212.227.40. ASN: AS7552 Viettel Group, Vietnam.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--vietnamese-chatbot-crm-redis-stack-12521222737-2026-05-26/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--vietnamese-chatbot-crm-redis-stack-12521222737-2026-05-26.png" length="0" type="image/png"/></item><item><title>Airbnb Tenant Agent — CORS Wildcard and Open Booking Thread State</title><link>https://nuclide-research.com/cases/case-studies--commercial--airbnb-tenant-agent-cors-462248676-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--airbnb-tenant-agent-cors-462248676-2026-05-25/</guid><description>A LangGraph-backed Airbnb booking agent on Hetzner Nuremberg exposes thread creation, thread state reads, and agent execution with no authentication. CORS wildcard headers mean any browser origin can invoke the agent. WhatsApp guest communications are the data class at risk.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--airbnb-tenant-agent-cors-462248676-2026-05-25.png&quot; alt=&quot;Airbnb Tenant Agent — CORS Wildcard and Open Booking Thread State&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A LangGraph-backed Airbnb booking agent on Hetzner Nuremberg exposes thread creation, thread state reads, and agent execution with no authentication. CORS wildcard headers mean any browser origin can invoke the agent. WhatsApp guest communications are the data class at risk.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--airbnb-tenant-agent-cors-462248676-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--airbnb-tenant-agent-cors-462248676-2026-05-25.png" length="0" type="image/png"/></item><item><title>Airbnb Tenant Agent — CORS Wildcard and No Auth on a Live WhatsApp Booking Bot</title><link>https://nuclide-research.com/cases/case-studies--commercial--airbnb-tenant-agent-cors-whatsapp-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--airbnb-tenant-agent-cors-whatsapp-2026-05-25/</guid><description>An Airbnb property manager&apos;s WhatsApp booking bot runs on LangGraph with no authentication and a wildcard CORS policy. Thread state from real guest conversations is readable without credentials. The agent is named &apos;Airbnb Tenant Agent&apos; and is active.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--airbnb-tenant-agent-cors-whatsapp-2026-05-25.png&quot; alt=&quot;Airbnb Tenant Agent — CORS Wildcard and No Auth on a Live WhatsApp Booking Bot&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;An Airbnb property manager&amp;#39;s WhatsApp booking bot runs on LangGraph with no authentication and a wildcard CORS policy. Thread state from real guest conversations is readable without credentials. The agent is named &amp;#39;Airbnb Tenant Agent&amp;#39; and is active.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--airbnb-tenant-agent-cors-whatsapp-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--airbnb-tenant-agent-cors-whatsapp-2026-05-25.png" length="0" type="image/png"/></item><item><title>Airbnb Tenant Agent — CORS Wildcard on a WhatsApp Booking Assistant</title><link>https://nuclide-research.com/cases/case-studies--commercial--airbnb-tenant-agent-langgraph-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--airbnb-tenant-agent-langgraph-2026-05-25/</guid><description>An Airbnb property host&apos;s WhatsApp booking assistant runs LangGraph with CORS Access-Control-Allow-Origin: * and no authentication on any endpoint. Any webpage can create threads and read guest booking conversations. The WhatsApp webhook service runs on the same host.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--airbnb-tenant-agent-langgraph-2026-05-25.png&quot; alt=&quot;Airbnb Tenant Agent — CORS Wildcard on a WhatsApp Booking Assistant&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;An Airbnb property host&amp;#39;s WhatsApp booking assistant runs LangGraph with CORS Access-Control-Allow-Origin: * and no authentication on any endpoint. Any webpage can create threads and read guest booking conversations. The WhatsApp webhook service runs on the same host.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--airbnb-tenant-agent-langgraph-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--airbnb-tenant-agent-langgraph-2026-05-25.png" length="0" type="image/png"/></item><item><title>ArtsyPetz CrewAI Stack: Langfuse LLM Observability Open Registration, Multi-Service Stack Exposed</title><link>https://nuclide-research.com/cases/case-studies--commercial--artsypetz-crewai-langfuse-unauth-147-182-219-125-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--artsypetz-crewai-langfuse-unauth-147-182-219-125-2026-05-25/</guid><description>A multi-service AI stack at 147.182.219.125 exposes Langfuse 3.88.1 LLM observability with open self-registration. ClickHouse 25.7.1.3997, GlitchTip, and MinIO run on the same host with auth enforced. A CrewAI social content generation service is present on ports 8001 and 9002. The operator is an indie developer running ArtsyPetz (pet portrait e-commerce) alongside a social media growth tool in development.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--artsypetz-crewai-langfuse-unauth-147-182-219-125-2026-05-25.png&quot; alt=&quot;ArtsyPetz CrewAI Stack: Langfuse LLM Observability Open Registration, Multi-Service Stack Exposed&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A multi-service AI stack at 147.182.219.125 exposes Langfuse 3.88.1 LLM observability with open self-registration. ClickHouse 25.7.1.3997, GlitchTip, and MinIO run on the same host with auth enforced. A CrewAI social content generation service is present on ports 8001 and 9002. The operator is an indie developer running ArtsyPetz (pet portrait e-commerce) alongside a social media growth tool in development.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--artsypetz-crewai-langfuse-unauth-147-182-219-125-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--artsypetz-crewai-langfuse-unauth-147-182-219-125-2026-05-25.png" length="0" type="image/png"/></item><item><title>Assistent Tècnic Intel·ligent (ATI) — Vite Dev Server in Production, 211-Tenant Platform</title><link>https://nuclide-research.com/cases/case-studies--commercial--ati-docu-companion-langgraph-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--ati-docu-companion-langgraph-2026-05-25/</guid><description>A Catalan multi-tenant AI customer support platform runs a Vite development server in production on one of three Hetzner nodes, exposing full TypeScript source code. All three nodes share unauthenticated LangGraph agent endpoints and Qdrant databases holding 121 customer conversations and 377 tenant knowledge-base documents.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--ati-docu-companion-langgraph-2026-05-25.png&quot; alt=&quot;Assistent Tècnic Intel·ligent (ATI) — Vite Dev Server in Production, 211-Tenant Platform&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A Catalan multi-tenant AI customer support platform runs a Vite development server in production on one of three Hetzner nodes, exposing full TypeScript source code. All three nodes share unauthenticated LangGraph agent endpoints and Qdrant databases holding 121 customer conversations and 377 tenant knowledge-base documents.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--ati-docu-companion-langgraph-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--ati-docu-companion-langgraph-2026-05-25.png" length="0" type="image/png"/></item><item><title>Collector Scraper API — AI-Powered PII Extraction Service, Unauthenticated</title><link>https://nuclide-research.com/cases/case-studies--commercial--collector-scraper-api-langgraph-pii-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--collector-scraper-api-langgraph-pii-2026-05-25/</guid><description>Two Scaleway nodes in Paris run an unauthenticated API built to extract emails, phone numbers, and coordinates from business directory listings. No authentication on the extraction endpoint.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--collector-scraper-api-langgraph-pii-2026-05-25.png&quot; alt=&quot;Collector Scraper API — AI-Powered PII Extraction Service, Unauthenticated&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Two Scaleway nodes in Paris run an unauthenticated API built to extract emails, phone numbers, and coordinates from business directory listings. No authentication on the extraction endpoint.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--collector-scraper-api-langgraph-pii-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--collector-scraper-api-langgraph-pii-2026-05-25.png" length="0" type="image/png"/></item><item><title>CrewAI SOP RAG Agent: Multi-Agent Standard Operating Procedure System Open Without Authentication</title><link>https://nuclide-research.com/cases/case-studies--commercial--crewai-sop-rag-agent-unauth-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--crewai-sop-rag-agent-unauth-2026-05-25/</guid><description>A multi-agent CrewAI system on Azure exposes its full API without authentication. All nine endpoints are open. POST /upload allows unauthenticated file ingestion into the SOP database. POST /query runs the full agent pipeline against stored documents. The agent roster and workflow configuration are enumerable without credentials.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--crewai-sop-rag-agent-unauth-2026-05-25.png&quot; alt=&quot;CrewAI SOP RAG Agent: Multi-Agent Standard Operating Procedure System Open Without Authentication&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A multi-agent CrewAI system on Azure exposes its full API without authentication. All nine endpoints are open. POST /upload allows unauthenticated file ingestion into the SOP database. POST /query runs the full agent pipeline against stored documents. The agent roster and workflow configuration are enumerable without credentials.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--crewai-sop-rag-agent-unauth-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--crewai-sop-rag-agent-unauth-2026-05-25.png" length="0" type="image/png"/></item><item><title>Demant Semantic Kernel Agent Platform: Five Production Agents Open Without Authentication</title><link>https://nuclide-research.com/cases/case-studies--commercial--demant-semantic-kernel-agents-unauth-172-205-127-109-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--demant-semantic-kernel-agents-unauth-172-205-127-109-2026-05-25/</guid><description>A Microsoft Semantic Kernel agent hosting platform at 172.205.127.109 exposes five production agents without authentication. Agent names, system prompts, and plugin bindings name Demant, a Danish hearing technology company. POST /agents/execute runs any agent against the knowledge base without credentials. POST /agents/create and DELETE /agents/{id} are open.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--demant-semantic-kernel-agents-unauth-172-205-127-109-2026-05-25.png&quot; alt=&quot;Demant Semantic Kernel Agent Platform: Five Production Agents Open Without Authentication&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A Microsoft Semantic Kernel agent hosting platform at 172.205.127.109 exposes five production agents without authentication. Agent names, system prompts, and plugin bindings name Demant, a Danish hearing technology company. POST /agents/execute runs any agent against the knowledge base without credentials. POST /agents/create and DELETE /agents/{id} are open.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--demant-semantic-kernel-agents-unauth-172-205-127-109-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--demant-semantic-kernel-agents-unauth-172-205-127-109-2026-05-25.png" length="0" type="image/png"/></item><item><title>Docu Companion / ATI — Vite Dev Server and 211 Tenant Knowledge Bases Open on a Three-Node Hetzner Cluster</title><link>https://nuclide-research.com/cases/case-studies--commercial--docu-companion-ati-vite-dev-production-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--docu-companion-ati-vite-dev-production-2026-05-25/</guid><description>A Catalan-language multi-tenant AI customer support platform runs a Vite development server in production on one node, exposing full TypeScript source. All three Hetzner nodes share an unauthenticated Qdrant stack holding 211 tenant knowledge bases, 377 business documents, and 121 user conversations. Agent invocation endpoints are fully open.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--docu-companion-ati-vite-dev-production-2026-05-25.png&quot; alt=&quot;Docu Companion / ATI — Vite Dev Server and 211 Tenant Knowledge Bases Open on a Three-Node Hetzner Cluster&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A Catalan-language multi-tenant AI customer support platform runs a Vite development server in production on one node, exposing full TypeScript source. All three Hetzner nodes share an unauthenticated Qdrant stack holding 211 tenant knowledge bases, 377 business documents, and 121 user conversations. Agent invocation endpoints are fully open.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--docu-companion-ati-vite-dev-production-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--docu-companion-ati-vite-dev-production-2026-05-25.png" length="0" type="image/png"/></item><item><title>Assistent Tècnic Intel·ligent — Vite Dev Server in Production Exposes Source Code Across a 211-Tenant Platform</title><link>https://nuclide-research.com/cases/case-studies--commercial--docu-companion-vite-dev-server-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--docu-companion-vite-dev-server-2026-05-25/</guid><description>A Catalan AI document platform running across three Hetzner nodes exposes its full TypeScript source code via a Vite development server left running in production. All agent endpoints, 121 user conversations, and 211 tenant knowledge bases are accessible without authentication.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--docu-companion-vite-dev-server-2026-05-25.png&quot; alt=&quot;Assistent Tècnic Intel·ligent — Vite Dev Server in Production Exposes Source Code Across a 211-Tenant Platform&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A Catalan AI document platform running across three Hetzner nodes exposes its full TypeScript source code via a Vite development server left running in production. All agent endpoints, 121 user conversations, and 211 tenant knowledge bases are accessible without authentication.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--docu-companion-vite-dev-server-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--docu-companion-vite-dev-server-2026-05-25.png" length="0" type="image/png"/></item><item><title>CloudCentric / BizCentric — ERPNext/Frappe Multi-Tenant Redis Cache: LDAP Settings Keys Exposed, 27 Tenants</title><link>https://nuclide-research.com/cases/case-studies--commercial--erpnext-frappe-ldap-redis-cache-21247228104-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--erpnext-frappe-ldap-redis-cache-21247228104-2026-05-25/</guid><description>CloudCentric runs a shared Redis Stack instance at 212.47.228.104 (Scaleway, Paris) as the document cache for a multi-tenant ERPNext/Frappe deployment. No authentication. DBSIZE 2,716. Two LDAP Settings document cache keys are present with TTL -1 (persistent). The LDAP Settings doctype in Frappe stores the bind DN, bind password, and LDAP server URL. Key names are readable without auth. Values were not read per restraint ethic. 27 tenant subdomains identified from Redis job queue keys.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--erpnext-frappe-ldap-redis-cache-21247228104-2026-05-25.png&quot; alt=&quot;CloudCentric / BizCentric — ERPNext/Frappe Multi-Tenant Redis Cache: LDAP Settings Keys Exposed, 27 Tenants&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;CloudCentric runs a shared Redis Stack instance at 212.47.228.104 (Scaleway, Paris) as the document cache for a multi-tenant ERPNext/Frappe deployment. No authentication. DBSIZE 2,716. Two LDAP Settings document cache keys are present with TTL -1 (persistent). The LDAP Settings doctype in Frappe stores the bind DN, bind password, and LDAP server URL. Key names are readable without auth. Values were not read per restraint ethic. 27 tenant subdomains identified from Redis job queue keys.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--erpnext-frappe-ldap-redis-cache-21247228104-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--erpnext-frappe-ldap-redis-cache-21247228104-2026-05-25.png" length="0" type="image/png"/></item><item><title>FAIS MCP Server: Dual-Node Workflow Tool API Open Without Authentication</title><link>https://nuclide-research.com/cases/case-studies--commercial--fais-mcp-server-unauth-4-187-183-11-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--fais-mcp-server-unauth-4-187-183-11-2026-05-25/</guid><description>Two identical FAIS MCP Server instances on Azure Pune expose their full tool API without authentication. Three workflow tools are open on both nodes: GetAllWorkflows, GetWorkflowConfiguration, and GetWorkflowLogsByTransaction. Any caller can enumerate organizations, retrieve workflow configurations, and query execution logs by workflow and transaction ID.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--fais-mcp-server-unauth-4-187-183-11-2026-05-25.png&quot; alt=&quot;FAIS MCP Server: Dual-Node Workflow Tool API Open Without Authentication&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Two identical FAIS MCP Server instances on Azure Pune expose their full tool API without authentication. Three workflow tools are open on both nodes: GetAllWorkflows, GetWorkflowConfiguration, and GetWorkflowLogsByTransaction. Any caller can enumerate organizations, retrieve workflow configurations, and query execution logs by workflow and transaction ID.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--fais-mcp-server-unauth-4-187-183-11-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--fais-mcp-server-unauth-4-187-183-11-2026-05-25.png" length="0" type="image/png"/></item><item><title>Chinese Financial LangGraph Agent — Credit Reports, Loans, and an Open Session Store</title><link>https://nuclide-research.com/cases/case-studies--commercial--langgraph-financial-agent-1-15-66-80-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--langgraph-financial-agent-1-15-66-80-2026-05-25/</guid><description>A Chinese financial services multi-agent system on LangGraph runs credit report and loan extraction workflows in development mode with no authentication. The agent session store is accessible via Redis Commander on port 8081.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--langgraph-financial-agent-1-15-66-80-2026-05-25.png&quot; alt=&quot;Chinese Financial LangGraph Agent — Credit Reports, Loans, and an Open Session Store&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A Chinese financial services multi-agent system on LangGraph runs credit report and loan extraction workflows in development mode with no authentication. The agent session store is accessible via Redis Commander on port 8081.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--langgraph-financial-agent-1-15-66-80-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--langgraph-financial-agent-1-15-66-80-2026-05-25.png" length="0" type="image/png"/></item><item><title>MikroWizard — Unauthenticated Redis Session Store, 2,940 Active MikroTik Router Management Sessions</title><link>https://nuclide-research.com/cases/case-studies--commercial--mikrowizard-session-store-redis-889910230-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--mikrowizard-session-store-redis-889910230-2026-05-25/</guid><description>MikroWizard router management platform at 88.99.102.30 (Hetzner Frankfurt) runs Redis 7.4.7 on port 6379 with no authentication. DBSIZE: 2,940 keys, all named mikrowizard::UUID. Session TTL: 29 days. Any actor with network access can read all active session identifiers directly from the data layer. The application layer at port 80 serves the MikroWizard Angular UI.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--mikrowizard-session-store-redis-889910230-2026-05-25.png&quot; alt=&quot;MikroWizard — Unauthenticated Redis Session Store, 2,940 Active MikroTik Router Management Sessions&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;MikroWizard router management platform at 88.99.102.30 (Hetzner Frankfurt) runs Redis 7.4.7 on port 6379 with no authentication. DBSIZE: 2,940 keys, all named mikrowizard::UUID. Session TTL: 29 days. Any actor with network access can read all active session identifiers directly from the data layer. The application layer at port 80 serves the MikroWizard Angular UI.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--mikrowizard-session-store-redis-889910230-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--mikrowizard-session-store-redis-889910230-2026-05-25.png" length="0" type="image/png"/></item><item><title>n8n 1.120.0: Legacy REST API Open, Production Billing Backup Workflow Exposed</title><link>https://nuclide-research.com/cases/case-studies--commercial--n8n-legacy-rest-unauth-38-102-86-8-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--n8n-legacy-rest-unauth-38-102-86-8-2026-05-25/</guid><description>n8n 1.120.0 on port 5678 at 38.102.86.8 exposes its legacy /rest/ API without authentication. A single active production workflow — billing-backup-to-s3 — is enumerable, including node type and tags. The newer /api/v1/ path enforces auth; the /rest/ path does not.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--n8n-legacy-rest-unauth-38-102-86-8-2026-05-25.png&quot; alt=&quot;n8n 1.120.0: Legacy REST API Open, Production Billing Backup Workflow Exposed&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;n8n 1.120.0 on port 5678 at 38.102.86.8 exposes its legacy /rest/ API without authentication. A single active production workflow — billing-backup-to-s3 — is enumerable, including node type and tags. The newer /api/v1/ path enforces auth; the /rest/ path does not.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--n8n-legacy-rest-unauth-38-102-86-8-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--n8n-legacy-rest-unauth-38-102-86-8-2026-05-25.png" length="0" type="image/png"/></item><item><title>NextHello CrewAI CRM: 59-Endpoint Operational API Open Without Authentication, Live API Keys</title><link>https://nuclide-research.com/cases/case-studies--commercial--nexthello-crewai-whatsapp-unauth-132-145-158-151-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--nexthello-crewai-whatsapp-unauth-132-145-158-151-2026-05-25/</guid><description>A CrewAI-based WhatsApp CRM platform at 132.145.158.151 exposes 59 endpoints without authentication. All operational POST endpoints accept requests without credentials. People Data Labs, HeyGen, and ElevenLabs API keys are live. A WhatsApp bridge with persisted session credentials is disconnected; reconnect enables message delivery to any phone number. The admin data layer is gated.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--nexthello-crewai-whatsapp-unauth-132-145-158-151-2026-05-25.png&quot; alt=&quot;NextHello CrewAI CRM: 59-Endpoint Operational API Open Without Authentication, Live API Keys&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A CrewAI-based WhatsApp CRM platform at 132.145.158.151 exposes 59 endpoints without authentication. All operational POST endpoints accept requests without credentials. People Data Labs, HeyGen, and ElevenLabs API keys are live. A WhatsApp bridge with persisted session credentials is disconnected; reconnect enables message delivery to any phone number. The admin data layer is gated.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--nexthello-crewai-whatsapp-unauth-132-145-158-151-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--nexthello-crewai-whatsapp-unauth-132-145-158-151-2026-05-25.png" length="0" type="image/png"/></item><item><title>SerGoGram Flowise + Weaviate: IT Credentials from German Blood Donation Organization in Open Vector Store</title><link>https://nuclide-research.com/cases/case-studies--commercial--sergogram-flowise-weaviate-unauth-37-60-255-27-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--sergogram-flowise-weaviate-unauth-37-60-255-27-2026-05-25/</guid><description>A Flowise instance at 37.60.255.27 exposes an unauthenticated Weaviate vector store containing internal IT documentation from a German blood donation organization. The corpus includes plaintext server credentials, internal IP addresses, server names, BitLocker PINs, and blood donation operational data. A second tenant&apos;s customer support documents occupy the same instance.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--sergogram-flowise-weaviate-unauth-37-60-255-27-2026-05-25.png&quot; alt=&quot;SerGoGram Flowise + Weaviate: IT Credentials from German Blood Donation Organization in Open Vector Store&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A Flowise instance at 37.60.255.27 exposes an unauthenticated Weaviate vector store containing internal IT documentation from a German blood donation organization. The corpus includes plaintext server credentials, internal IP addresses, server names, BitLocker PINs, and blood donation operational data. A second tenant&amp;#39;s customer support documents occupy the same instance.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--sergogram-flowise-weaviate-unauth-37-60-255-27-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--sergogram-flowise-weaviate-unauth-37-60-255-27-2026-05-25.png" length="0" type="image/png"/></item><item><title>Simón Movilidad / Finanzauto — Full Picture: Traccar 6.12.2, 28,323 Open GPS Records, CAS Default Config</title><link>https://nuclide-research.com/cases/case-studies--commercial--simon-movilidad-redis-stack-fleet-pii-19021728217-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--simon-movilidad-redis-stack-fleet-pii-19021728217-2026-05-25/</guid><description>Simón Movilidad runs Traccar 6.12.2 (GPS fleet tracking) with Redis Stack as the live device state store. The Redis instance at qa.simonmovilidad.com is open without auth: 28,323 GPS device records, keyed by IMEI, each containing plate, name, phone, email. Tenant: Finanzauto S.A. BIC (Colombian vehicle financing). Finanzauto&apos;s admision subdomain runs Apereo CAS SSO with the default-config HTML comment in production.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--simon-movilidad-redis-stack-fleet-pii-19021728217-2026-05-25.png&quot; alt=&quot;Simón Movilidad / Finanzauto — Full Picture: Traccar 6.12.2, 28,323 Open GPS Records, CAS Default Config&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Simón Movilidad runs Traccar 6.12.2 (GPS fleet tracking) with Redis Stack as the live device state store. The Redis instance at qa.simonmovilidad.com is open without auth: 28,323 GPS device records, keyed by IMEI, each containing plate, name, phone, email. Tenant: Finanzauto S.A. BIC (Colombian vehicle financing). Finanzauto&amp;#39;s admision subdomain runs Apereo CAS SSO with the default-config HTML comment in production.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--simon-movilidad-redis-stack-fleet-pii-19021728217-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--simon-movilidad-redis-stack-fleet-pii-19021728217-2026-05-25.png" length="0" type="image/png"/></item><item><title>Stock.ai (EMOR AI) — Partial-Auth Failure, Open Vector Store, and Third-Party Research Leak</title><link>https://nuclide-research.com/cases/case-studies--commercial--stock-ai-emor-ai-langgraph-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--stock-ai-emor-ai-langgraph-2026-05-25/</guid><description>An Indian fintech startup&apos;s LangGraph stock analysis app authenticates the list layer but leaves individual resource endpoints wide open. 62 proprietary Arihant Capital analyst reports are accessible without auth through a co-deployed Weaviate instance.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--stock-ai-emor-ai-langgraph-2026-05-25.png&quot; alt=&quot;Stock.ai (EMOR AI) — Partial-Auth Failure, Open Vector Store, and Third-Party Research Leak&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;An Indian fintech startup&amp;#39;s LangGraph stock analysis app authenticates the list layer but leaves individual resource endpoints wide open. 62 proprietary Arihant Capital analyst reports are accessible without auth through a co-deployed Weaviate instance.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--stock-ai-emor-ai-langgraph-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--stock-ai-emor-ai-langgraph-2026-05-25.png" length="0" type="image/png"/></item><item><title>Stock.ai (EMOR AI) — Partial-Auth Failure, Open Weaviate, and 62 Proprietary Analyst Reports</title><link>https://nuclide-research.com/cases/case-studies--commercial--stock-ai-emor-partial-auth-20193252230-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--stock-ai-emor-partial-auth-20193252230-2026-05-25/</guid><description>EMOR AI&apos;s unreleased Stock.ai product exposes a Weaviate vector database, individual API resource endpoints, and 62+ proprietary Arihant Capital equity analyst reports. The developer implemented JWT and Google OAuth but left individual resource endpoints unprotected. A reused HR/resume Azure OpenAI subscription confirms operator identity.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--stock-ai-emor-partial-auth-20193252230-2026-05-25.png&quot; alt=&quot;Stock.ai (EMOR AI) — Partial-Auth Failure, Open Weaviate, and 62 Proprietary Analyst Reports&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;EMOR AI&amp;#39;s unreleased Stock.ai product exposes a Weaviate vector database, individual API resource endpoints, and 62+ proprietary Arihant Capital equity analyst reports. The developer implemented JWT and Google OAuth but left individual resource endpoints unprotected. A reused HR/resume Azure OpenAI subscription confirms operator identity.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--stock-ai-emor-partial-auth-20193252230-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--stock-ai-emor-partial-auth-20193252230-2026-05-25.png" length="0" type="image/png"/></item><item><title>Stock.ai — Partial-Auth Failure Exposes 62 Arihant Capital Reports and User Data</title><link>https://nuclide-research.com/cases/case-studies--commercial--stock-ai-emor-partial-auth-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--stock-ai-emor-partial-auth-2026-05-25/</guid><description>An Indian fintech startup&apos;s stock research assistant exposes 62 proprietary Arihant Capital analyst reports and user conversation history. The developer built JWT authentication and left the individual resource endpoints unprotected.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--stock-ai-emor-partial-auth-2026-05-25.png&quot; alt=&quot;Stock.ai — Partial-Auth Failure Exposes 62 Arihant Capital Reports and User Data&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;An Indian fintech startup&amp;#39;s stock research assistant exposes 62 proprietary Arihant Capital analyst reports and user conversation history. The developer built JWT authentication and left the individual resource endpoints unprotected.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--stock-ai-emor-partial-auth-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--stock-ai-emor-partial-auth-2026-05-25.png" length="0" type="image/png"/></item><item><title>Vantage Coach — Healthcare CRM Agent With Voice Endpoints, No Auth</title><link>https://nuclide-research.com/cases/case-studies--commercial--vantage-coach-healthcare-langgraph-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--vantage-coach-healthcare-langgraph-2026-05-25/</guid><description>A pharmaceutical sales rep AI assistant runs LangGraph on two DigitalOcean nodes with no authentication. The agent has declared access to a healthcare client database. Voice endpoints accept unauthenticated audio and return agent-processed responses. Client records including doctor names, specializations, visit history, and treatment discussion notes are accessible to any caller with a valid organization ID.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--vantage-coach-healthcare-langgraph-2026-05-25.png&quot; alt=&quot;Vantage Coach — Healthcare CRM Agent With Voice Endpoints, No Auth&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A pharmaceutical sales rep AI assistant runs LangGraph on two DigitalOcean nodes with no authentication. The agent has declared access to a healthcare client database. Voice endpoints accept unauthenticated audio and return agent-processed responses. Client records including doctor names, specializations, visit history, and treatment discussion notes are accessible to any caller with a valid organization ID.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--vantage-coach-healthcare-langgraph-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--vantage-coach-healthcare-langgraph-2026-05-25.png" length="0" type="image/png"/></item><item><title>Vantage Coach — Pharmaceutical CRM with Healthcare Client Records and Voice Endpoints Open</title><link>https://nuclide-research.com/cases/case-studies--commercial--vantage-coach-pharma-crm-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--vantage-coach-pharma-crm-2026-05-25/</guid><description>A pharmaceutical sales representative AI tool on two DigitalOcean nodes exposes a healthcare client database, conversation history, and voice endpoints without authentication. The OpenAPI spec explicitly describes access to doctor names, hospitals, visit dates, and medication discussion records.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--vantage-coach-pharma-crm-2026-05-25.png&quot; alt=&quot;Vantage Coach — Pharmaceutical CRM with Healthcare Client Records and Voice Endpoints Open&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A pharmaceutical sales representative AI tool on two DigitalOcean nodes exposes a healthcare client database, conversation history, and voice endpoints without authentication. The OpenAPI spec explicitly describes access to doctor names, hospitals, visit dates, and medication discussion records.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--vantage-coach-pharma-crm-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--vantage-coach-pharma-crm-2026-05-25.png" length="0" type="image/png"/></item><item><title>Vantage Coach — Pharma CRM Agent, Open Voice Endpoints, Healthcare Client Records</title><link>https://nuclide-research.com/cases/case-studies--commercial--vantage-coach-pharma-crm-voice-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--vantage-coach-pharma-crm-voice-2026-05-25/</guid><description>A Spanish-language pharmaceutical CRM AI agent runs on two DigitalOcean nodes with no authentication. The agent has tool access to a healthcare client database. Voice endpoints accept audio queries against that database without credentials.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--vantage-coach-pharma-crm-voice-2026-05-25.png&quot; alt=&quot;Vantage Coach — Pharma CRM Agent, Open Voice Endpoints, Healthcare Client Records&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A Spanish-language pharmaceutical CRM AI agent runs on two DigitalOcean nodes with no authentication. The agent has tool access to a healthcare client database. Voice endpoints accept audio queries against that database without credentials.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--vantage-coach-pharma-crm-voice-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--vantage-coach-pharma-crm-voice-2026-05-25.png" length="0" type="image/png"/></item><item><title>wuji Sleep Doctor — WeChat Health Data and 9,244 Request Logs Exposed on Tencent Cloud</title><link>https://nuclide-research.com/cases/case-studies--commercial--wuji-sleep-doctor-health-data-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--wuji-sleep-doctor-health-data-2026-05-25/</guid><description>A Chinese sleep health application on Tencent Cloud exposes per-user sleep sensor data by WeChat openid and serves 9,244 logged API requests without authentication. The service runs as root with log file paths disclosed.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--wuji-sleep-doctor-health-data-2026-05-25.png&quot; alt=&quot;wuji Sleep Doctor — WeChat Health Data and 9,244 Request Logs Exposed on Tencent Cloud&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A Chinese sleep health application on Tencent Cloud exposes per-user sleep sensor data by WeChat openid and serves 9,244 logged API requests without authentication. The service runs as root with log file paths disclosed.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--wuji-sleep-doctor-health-data-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--wuji-sleep-doctor-health-data-2026-05-25.png" length="0" type="image/png"/></item><item><title>Chinese Sleep Doctor App — WeChat Health Data Open by Design, 9,244 Request Logs Exposed</title><link>https://nuclide-research.com/cases/case-studies--commercial--wuji-sleep-doctor-health-data-82156182216-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--wuji-sleep-doctor-health-data-82156182216-2026-05-25/</guid><description>A Chinese WeChat Mini Program backend for sleep health diagnostics runs on TencentCloud Beijing with no authentication. Sleep sensor data is accessible by WeChat openid. 9,244 request logs containing user identifiers, health responses, and client IPs are readable without credentials.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--wuji-sleep-doctor-health-data-82156182216-2026-05-25.png&quot; alt=&quot;Chinese Sleep Doctor App — WeChat Health Data Open by Design, 9,244 Request Logs Exposed&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A Chinese WeChat Mini Program backend for sleep health diagnostics runs on TencentCloud Beijing with no authentication. Sleep sensor data is accessible by WeChat openid. 9,244 request logs containing user identifiers, health responses, and client IPs are readable without credentials.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--wuji-sleep-doctor-health-data-82156182216-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--wuji-sleep-doctor-health-data-82156182216-2026-05-25.png" length="0" type="image/png"/></item><item><title>wuji Sleep Doctor — Chinese Health Data by WeChat OpenID, 9,244 Request Logs Open</title><link>https://nuclide-research.com/cases/case-studies--commercial--wuji-sleep-doctor-langgraph-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--wuji-sleep-doctor-langgraph-2026-05-25/</guid><description>A Chinese sleep health WeChat Mini Program backend runs a LangGraph Sleep Doctor service with no authentication on any endpoint. Sleep sensor data (AHI, heart rate, HRV, sleep stages) is accessible by WeChat openid alone. A 36.9MB request log containing 9,244 entries — including user identifiers, request bodies, response bodies, and client IPs — is served at /api/monitor/logs without auth. The service runs as root.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--wuji-sleep-doctor-langgraph-2026-05-25.png&quot; alt=&quot;wuji Sleep Doctor — Chinese Health Data by WeChat OpenID, 9,244 Request Logs Open&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A Chinese sleep health WeChat Mini Program backend runs a LangGraph Sleep Doctor service with no authentication on any endpoint. Sleep sensor data (AHI, heart rate, HRV, sleep stages) is accessible by WeChat openid alone. A 36.9MB request log containing 9,244 entries — including user identifiers, request bodies, response bodies, and client IPs — is served at /api/monitor/logs without auth. The service runs as root.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--wuji-sleep-doctor-langgraph-2026-05-25/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--wuji-sleep-doctor-langgraph-2026-05-25.png" length="0" type="image/png"/></item><item><title>ClimateGPT Stack — Unauth vLLM + Opik + Streamlit</title><link>https://nuclide-research.com/cases/case-studies--commercial--climategpt-opik-vllm-2026-05-22/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--climategpt-opik-vllm-2026-05-22/</guid><description>Surfaced during Session 30 Agenta survey (S30). The /opik/api/v1/projects endpoint returned HTTP 200 unauthenticated — a candidate, per Insight #16. The candidate was passed to this assessment for data-layer verification.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--climategpt-opik-vllm-2026-05-22.png&quot; alt=&quot;ClimateGPT Stack — Unauth vLLM + Opik + Streamlit&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Surfaced during Session 30 Agenta survey (S30). The /opik/api/v1/projects endpoint returned HTTP 200 unauthenticated — a candidate, per Insight #16. The candidate was passed to this assessment for data-layer verification.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--climategpt-opik-vllm-2026-05-22/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--climategpt-opik-vllm-2026-05-22.png" length="0" type="image/png"/></item><item><title>Langfuse Postgres Cert Pivot — Data Tier Survey + CygnusAlpha Production Finding</title><link>https://nuclide-research.com/cases/case-studies--commercial--langfuse-postgres-cert-pivot-2026-05-22/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--langfuse-postgres-cert-pivot-2026-05-22/</guid><description>The survey started as an Insight #20 exercise: data-tier ports adjacent to confirmed AI services are an independent exposure class. The dork ssl.cert.subject.cn:langfuse port:5432 was surfaced during the Agenta survey (Session 30) via the TLS-CN attack class (Insight #46). Eleven hits.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--langfuse-postgres-cert-pivot-2026-05-22.png&quot; alt=&quot;Langfuse Postgres Cert Pivot — Data Tier Survey + CygnusAlpha Production Finding&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;The survey started as an Insight #20 exercise: data-tier ports adjacent to confirmed AI services are an independent exposure class. The dork ssl.cert.subject.cn:langfuse port:5432 was surfaced during the Agenta survey (Session 30) via the TLS-CN attack class (Insight #46). Eleven hits.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--langfuse-postgres-cert-pivot-2026-05-22/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--langfuse-postgres-cert-pivot-2026-05-22.png" length="0" type="image/png"/></item><item><title>116.202.28.181 — Pantaflow Live Transcription Server</title><link>https://nuclide-research.com/cases/case-studies--commercial--pantaflow-live-transcription-2026-05-22/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--pantaflow-live-transcription-2026-05-22/</guid><description>&lt;!-- ksat-tag:auto-generated:start --&gt;
## DCWF KSAT coverage</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--pantaflow-live-transcription-2026-05-22.png&quot; alt=&quot;116.202.28.181 — Pantaflow Live Transcription Server&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- ksat-tag:auto-generated:start --&amp;gt;
## DCWF KSAT coverage&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--pantaflow-live-transcription-2026-05-22/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--pantaflow-live-transcription-2026-05-22.png" length="0" type="image/png"/></item><item><title>PromptLayer — Marker-Build Assessment</title><link>https://nuclide-research.com/cases/case-studies--commercial--promptlayer-marker-build-2026-05-22/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--promptlayer-marker-build-2026-05-22/</guid><description>PromptLayer was queued for its first population survey: http.title:&quot;PromptLayer&quot;
(6 hits) and ssl.cert.subject.cn:promptlayer (10 hits). The discovery stage
could not run — both Shodan API keys on rooster return 401 Unauthorized, and
the ledger holds zero pre-harvested PromptLayer hosts, so there was no fallback
corpus. JAXEN, VisorSD, VisorGoose and VisorPl…</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--promptlayer-marker-build-2026-05-22.png&quot; alt=&quot;PromptLayer — Marker-Build Assessment&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;PromptLayer was queued for its first population survey: http.title:&amp;quot;PromptLayer&amp;quot;
(6 hits) and ssl.cert.subject.cn:promptlayer (10 hits). The discovery stage
could not run — both Shodan API keys on rooster return 401 Unauthorized, and
the ledger holds zero pre-harvested PromptLayer hosts, so there was no fallback
corpus. JAXEN, VisorSD, VisorGoose and VisorPl…&lt;/p&gt;
&lt;p&gt;PromptLayer was queued for its first population survey: http.title:&amp;quot;PromptLayer&amp;quot;
(6 hits) and ssl.cert.subject.cn:promptlayer (10 hits). The discovery stage
could not run — both Shodan API keys on rooster return 401 Unauthorized, and
the ledger holds zero pre-harvested PromptLayer hosts, so there was no fallback
corpus. JAXEN, VisorSD, VisorGoose and VisorPlus&amp;#39;s hunt path are all
Shodan-gated and were blocked at the same point.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--promptlayer-marker-build-2026-05-22/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--promptlayer-marker-build-2026-05-22.png" length="0" type="image/png"/></item><item><title>117.50.80.181 — TCI Kindergarten ASR / Speech-Assessment Platform</title><link>https://nuclide-research.com/cases/case-studies--k12--cn-tci-kindergarten-asr/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--k12--cn-tci-kindergarten-asr/</guid><description>117.50.80.181:8001 runs the &quot;TCI ASR Service&quot; v3.0.0, a Chinese kindergarten classroom speech-assessment platform. The processing tier has no authentication. An unauthenticated internet caller can submit audio to the platform&apos;s automatic-speech-recognition, speaker-diarization, and voiceprint-registration pipeline. The same endpoints carry an arbitrary-path…</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--k12--cn-tci-kindergarten-asr.png&quot; alt=&quot;117.50.80.181 — TCI Kindergarten ASR / Speech-Assessment Platform&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; K-12&lt;/p&gt;
&lt;p&gt;117.50.80.181:8001 runs the &amp;quot;TCI ASR Service&amp;quot; v3.0.0, a Chinese kindergarten classroom speech-assessment platform. The processing tier has no authentication. An unauthenticated internet caller can submit audio to the platform&amp;#39;s automatic-speech-recognition, speaker-diarization, and voiceprint-registration pipeline. The same endpoints carry an arbitrary-path…&lt;/p&gt;
&lt;p&gt;117.50.80.181:8001 runs the &amp;quot;TCI ASR Service&amp;quot; v3.0.0, a Chinese kindergarten classroom speech-assessment platform. The processing tier has no authentication. An unauthenticated internet caller can submit audio to the platform&amp;#39;s automatic-speech-recognition, speaker-diarization, and voiceprint-registration pipeline. The same endpoints carry an arbitrary-path file-existence oracle through an unsanitised ffmpeg -i call. The platform&amp;#39;s data class is kindergarten-age children&amp;#39;s classroom audio and the voiceprint biometrics of children and teachers.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--k12--cn-tci-kindergarten-asr/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--k12--cn-tci-kindergarten-asr.png" length="0" type="image/png"/></item><item><title>Embedding Services Survey — Tier-2 Cloud (2026-05-21)</title><link>https://nuclide-research.com/cases/case-studies--commercial--embedding-tier2-2026-05-21/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--embedding-tier2-2026-05-21/</guid><description>&lt;!-- ksat-tag:auto-generated:start --&gt;
## DCWF KSAT coverage</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--embedding-tier2-2026-05-21.png&quot; alt=&quot;Embedding Services Survey — Tier-2 Cloud (2026-05-21)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- ksat-tag:auto-generated:start --&amp;gt;
## DCWF KSAT coverage&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--embedding-tier2-2026-05-21/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--embedding-tier2-2026-05-21.png" length="0" type="image/png"/></item><item><title>NIS/YP Internet Exposure — hpc.psy.ntu.edu.tw</title><link>https://nuclide-research.com/cases/case-studies--universities--hpc-psy-ntu-edu-tw/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--hpc-psy-ntu-edu-tw/</guid><description>NTU&apos;s Psychology HPC node ran NIS (YP) — a 1980s LAN credential distribution protocol — fully exposed to the internet at time of observation. yppasswdd, ypserv, and fypxfrd were all registered in the portmapper table and reachable from external IP space. NIS has no transport authentication. An attacker who knows the NIS domain name can:</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--hpc-psy-ntu-edu-tw.png&quot; alt=&quot;NIS/YP Internet Exposure — hpc.psy.ntu.edu.tw&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;NTU&amp;#39;s Psychology HPC node ran NIS (YP) — a 1980s LAN credential distribution protocol — fully exposed to the internet at time of observation. yppasswdd, ypserv, and fypxfrd were all registered in the portmapper table and reachable from external IP space. NIS has no transport authentication. An attacker who knows the NIS domain name can:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--hpc-psy-ntu-edu-tw/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--hpc-psy-ntu-edu-tw.png" length="0" type="image/png"/></item><item><title>sakura.mit.edu — MIT Research Compute Node</title><link>https://nuclide-research.com/cases/case-studies--universities--sakura-mit-edu/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--sakura-mit-edu/</guid><description>34 exposed ports. Services running concurrently on this single host:</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--sakura-mit-edu.png&quot; alt=&quot;sakura.mit.edu — MIT Research Compute Node&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;34 exposed ports. Services running concurrently on this single host:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--sakura-mit-edu/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--sakura-mit-edu.png" length="0" type="image/png"/></item><item><title>University AI Infrastructure Exposures</title><link>https://nuclide-research.com/cases/case-studies--universities/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities/</guid><description>Unauthenticated Ollama, Open WebUI, JupyterHub, and LiteLLM instances discovered on university networks worldwide. Organized by country / state.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities.png&quot; alt=&quot;University AI Infrastructure Exposures&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Other&lt;/p&gt;
&lt;p&gt;Unauthenticated Ollama, Open WebUI, JupyterHub, and LiteLLM instances discovered on university networks worldwide. Organized by country / state.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities.png" length="0" type="image/png"/></item><item><title>University AI Infrastructure Exposure: Global Overview</title><link>https://nuclide-research.com/cases/case-studies--universities--overview/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--overview/</guid><description>Full sweep of all 10,224 recognized universities worldwide (Hipo dataset, 202 countries). Two lanes ran:</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--overview.png&quot; alt=&quot;University AI Infrastructure Exposure: Global Overview&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;Full sweep of all 10,224 recognized universities worldwide (Hipo dataset, 202 countries). Two lanes ran:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--overview/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--overview.png" length="0" type="image/png"/></item><item><title>Chinese commercial Claude-reseller ecosystem: 32 pooled Anthropic accounts across six relays, ~13.92B tokens served via claude-relay-service OSS</title><link>https://nuclide-research.com/cases/case-studies--commercial--claude-relay-chinese-reseller-2026-05-19/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--claude-relay-chinese-reseller-2026-05-19/</guid><description>A pivot off the LiteLLM UNAUTHFUNCTIONAL cohort from the same-day safety/guardrail survey surfaced an upstream apibase at 43.167.216.195:38762 (Tencent Cloud Singapore / Aceville Pte Ltd). That upstream returned a JSON stats schema unique to the claude-relay-service OSS project. A targeted Shodan dork on the schema&apos;s load-bearing tokens (availableAccounts +…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--claude-relay-chinese-reseller-2026-05-19.png&quot; alt=&quot;Chinese commercial Claude-reseller ecosystem: 32 pooled Anthropic accounts across six relays, ~13.92B tokens served via claude-relay-service OSS&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A pivot off the LiteLLM UNAUTHFUNCTIONAL cohort from the same-day safety/guardrail survey surfaced an upstream apibase at 43.167.216.195:38762 (Tencent Cloud Singapore / Aceville Pte Ltd). That upstream returned a JSON stats schema unique to the claude-relay-service OSS project. A targeted Shodan dork on the schema&amp;#39;s load-bearing tokens (availableAccounts +…&lt;/p&gt;
&lt;p&gt;A pivot off the LiteLLM UNAUTHFUNCTIONAL cohort from the same-day safety/guardrail survey surfaced an upstream apibase at 43.167.216.195:38762 (Tencent Cloud Singapore / Aceville Pte Ltd). That upstream returned a JSON stats schema unique to the claude-relay-service OSS project. A targeted Shodan dork on the schema&amp;#39;s load-bearing tokens (availableAccounts + thirdPartyMaxConcurrent) surfaced five additional hosts running the same OSS. The six visible relays collectively pool 32 paid Anthropic accounts and have served approximately 13.92 billion tokens of Claude inference across 430,000 successful API requests. The OSS substrate (github.com/Wei-Shaw/claude-relay-service, 11.8K stars, MIT) is documented in Chinese only and explicitly marketed for 拼车 (carpool) account-sharing. The maintainer operates a commercial brand at pincc.ai with the slogan &amp;quot;Claude Code Max 20X, saves 60%+.&amp;quot; The Go-rewrite successor sub2api has 21,800 stars and 8,105 Shodan-indexed deployments, suggesting the visible Claude Relay v1 population is the long tail of operators who left /health open, not the deployed base.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--claude-relay-chinese-reseller-2026-05-19/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--claude-relay-chinese-reseller-2026-05-19.png" length="0" type="image/png"/></item><item><title>LLM Orchestration Re-Run — 2026-05-19</title><link>https://nuclide-research.com/cases/case-studies--commercial--llm-orchestration-rerun-2026-05-19/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--llm-orchestration-rerun-2026-05-19/</guid><description>Per the standing methodology — the manual → productize → re-run loop. The first run was 2026-05-15. Since then:</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--llm-orchestration-rerun-2026-05-19.png&quot; alt=&quot;LLM Orchestration Re-Run — 2026-05-19&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Per the standing methodology — the manual → productize → re-run loop. The first run was 2026-05-15. Since then:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--llm-orchestration-rerun-2026-05-19/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--llm-orchestration-rerun-2026-05-19.png" length="0" type="image/png"/></item><item><title>sub2api — Population survey: 7,720 indexed hosts, auth-on-default at scale, zero pool-leak</title><link>https://nuclide-research.com/cases/case-studies--commercial--sub2api-population-2026-05-19/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--sub2api-population-2026-05-19/</guid><description>&lt;!-- ksat-tag:auto-generated:start --&gt;
## DCWF KSAT coverage</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--sub2api-population-2026-05-19.png&quot; alt=&quot;sub2api — Population survey: 7,720 indexed hosts, auth-on-default at scale, zero pool-leak&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- ksat-tag:auto-generated:start --&amp;gt;
## DCWF KSAT coverage&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--sub2api-population-2026-05-19/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--sub2api-population-2026-05-19.png" length="0" type="image/png"/></item><item><title>.edu LLM infrastructure dork-map — 1,584 verified-dork × hostname:.edu sweep (2026-05-19)</title><link>https://nuclide-research.com/cases/case-studies--universities--edu-llm-infra-sweep-2026-05-19/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--edu-llm-infra-sweep-2026-05-19/</guid><description>The repo&apos;s 1,629-dork verified Shodan catalog (29 categories, hand-curated and FP-tested across 50+ prior commercial surveys) was scoped to hostname:.edu and run through shodan count (free per query, no scan credit). After dropping 45 dorks that already had a hostname: filter, 1,584 scoped queries ran in 48 minutes with a 1.2s rate-limit. 382 dorks (24%) ret…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--edu-llm-infra-sweep-2026-05-19.png&quot; alt=&quot;.edu LLM infrastructure dork-map — 1,584 verified-dork × hostname:.edu sweep (2026-05-19)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;The repo&amp;#39;s 1,629-dork verified Shodan catalog (29 categories, hand-curated and FP-tested across 50+ prior commercial surveys) was scoped to hostname:.edu and run through shodan count (free per query, no scan credit). After dropping 45 dorks that already had a hostname: filter, 1,584 scoped queries ran in 48 minutes with a 1.2s rate-limit. 382 dorks (24%) ret…&lt;/p&gt;
&lt;p&gt;The repo&amp;#39;s 1,629-dork verified Shodan catalog (29 categories, hand-curated and FP-tested across 50+ prior commercial surveys) was scoped to hostname:.edu and run through shodan count (free per query, no scan credit). After dropping 45 dorks that already had a hostname: filter, 1,584 scoped queries ran in 48 minutes with a 1.2s rate-limit. 382 dorks (24%) returned ≥1 hit, 1,143 returned 0, 59 errored (3.7% rate-limit blip). The data-mapping output establishes which platform classes have material .edu exposure surface, what populations to expect at Stage 1 verify, and which dork classes are productive vs noise on the academic surface.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--edu-llm-infra-sweep-2026-05-19/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--edu-llm-infra-sweep-2026-05-19.png" length="0" type="image/png"/></item><item><title>University of Arizona: Branded &quot;U of A GenAI&quot; — Open WebUI v0.7.2 with University-OIDC + Auth-On</title><link>https://nuclide-research.com/cases/case-studies--universities--us--az-arizona/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--az-arizona/</guid><description>The University of Arizona operates a branded institutional Open WebUI service at genai.arizona.edu (128.196.254.101). The deployment is reachable on port 80 (reverse-proxied; Open WebUI&apos;s typical :3000 not directly exposed). /api/config returned Open WebUI v0.7.2 with name: &quot;U of A GenAI (Open WebUI)&quot; — customized service title — and an OIDC backend identifi…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--az-arizona.png&quot; alt=&quot;University of Arizona: Branded &amp;quot;U of A GenAI&amp;quot; — Open WebUI v0.7.2 with University-OIDC + Auth-On&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;The University of Arizona operates a branded institutional Open WebUI service at genai.arizona.edu (128.196.254.101). The deployment is reachable on port 80 (reverse-proxied; Open WebUI&amp;#39;s typical :3000 not directly exposed). /api/config returned Open WebUI v0.7.2 with name: &amp;quot;U of A GenAI (Open WebUI)&amp;quot; — customized service title — and an OIDC backend identifi…&lt;/p&gt;
&lt;p&gt;The University of Arizona operates a branded institutional Open WebUI service at genai.arizona.edu (128.196.254.101). The deployment is reachable on port 80 (reverse-proxied; Open WebUI&amp;#39;s typical :3000 not directly exposed). /api/config returned Open WebUI v0.7.2 with name: &amp;quot;U of A GenAI (Open WebUI)&amp;quot; — customized service title — and an OIDC backend identified as &amp;quot;University of Arizona&amp;quot;. Signup is closed (enablesignup: false). Properly configured institutional LLM service with institutional OIDC integration; documented here as a wave-2 cohort exemplar of correct deployment posture.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--az-arizona/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--az-arizona.png" length="0" type="image/png"/></item><item><title>San Diego Supercomputer Center: Public Ollama on `compute.cloud.sdsc.edu` — 53-Model Inventory + `:cloud`-suffix Cloud-Proxy Class</title><link>https://nuclide-research.com/cases/case-studies--universities--us--ca-sdsc/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--ca-sdsc/</guid><description>The San Diego Supercomputer Center (SDSC) operates a publicly-reachable Ollama 0.20.4 instance at 132-249-238-182.compute.cloud.sdsc.edu (132.249.238.182). /api/tags returns 53 models. The first entry in the model list is gemini-3-flash-preview:cloud with remotemodel:&quot;gemini-3-flash-preview&quot; and remotehost pointing to a Google API endpoint — Ollama&apos;s cloud-p…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--ca-sdsc.png&quot; alt=&quot;San Diego Supercomputer Center: Public Ollama on `compute.cloud.sdsc.edu` — 53-Model Inventory + `:cloud`-suffix Cloud-Proxy Class&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;The San Diego Supercomputer Center (SDSC) operates a publicly-reachable Ollama 0.20.4 instance at 132-249-238-182.compute.cloud.sdsc.edu (132.249.238.182). /api/tags returns 53 models. The first entry in the model list is gemini-3-flash-preview:cloud with remotemodel:&amp;quot;gemini-3-flash-preview&amp;quot; and remotehost pointing to a Google API endpoint — Ollama&amp;#39;s cloud-p…&lt;/p&gt;
&lt;p&gt;The San Diego Supercomputer Center (SDSC) operates a publicly-reachable Ollama 0.20.4 instance at 132-249-238-182.compute.cloud.sdsc.edu (132.249.238.182). /api/tags returns 53 models. The first entry in the model list is gemini-3-flash-preview:cloud with remotemodel:&amp;quot;gemini-3-flash-preview&amp;quot; and remotehost pointing to a Google API endpoint — Ollama&amp;#39;s cloud-proxy configuration class is OBSERVED on this host. SSH (OpenSSH 8.9p1 Ubuntu) is the only other open port.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--ca-sdsc/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--ca-sdsc.png" length="0" type="image/png"/></item><item><title>Stanford University: Streamlit app on `sr24-0915fd81a9.stanford.edu:8501` (DHCP / dynamic host; framework confirmed)</title><link>https://nuclide-research.com/cases/case-studies--universities--us--ca-stanford/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--ca-stanford/</guid><description>Stanford University surfaces a Streamlit application at sr24-0915fd81a9.stanford.edu (128.12.168.8:8501). Hostname pattern (sr24-{hex-id}.stanford.edu) suggests a dynamically-assigned campus subnet host — likely a personal device on Stanford&apos;s wireless or residential network. Streamlit framework confirmed via /stcore/health returning ok; &lt;title&gt;Streamlit&lt;/ti…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--ca-stanford.png&quot; alt=&quot;Stanford University: Streamlit app on `sr24-0915fd81a9.stanford.edu:8501` (DHCP / dynamic host; framework confirmed)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;Stanford University surfaces a Streamlit application at sr24-0915fd81a9.stanford.edu (128.12.168.8:8501). Hostname pattern (sr24-{hex-id}.stanford.edu) suggests a dynamically-assigned campus subnet host — likely a personal device on Stanford&amp;#39;s wireless or residential network. Streamlit framework confirmed via /stcore/health returning ok; &amp;lt;title&amp;gt;Streamlit&amp;lt;/ti…&lt;/p&gt;
&lt;p&gt;Stanford University surfaces a Streamlit application at sr24-0915fd81a9.stanford.edu (128.12.168.8:8501). Hostname pattern (sr24-{hex-id}.stanford.edu) suggests a dynamically-assigned campus subnet host — likely a personal device on Stanford&amp;#39;s wireless or residential network. Streamlit framework confirmed via /stcore/health returning ok; &amp;lt;title&amp;gt;Streamlit&amp;lt;/title&amp;gt; default (no app-level customization). Per restraint ethic, the WebSocket session that would reveal app content was not established.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--ca-stanford/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--ca-stanford.png" length="0" type="image/png"/></item><item><title>UCLA: Multi-Service AI Stack on `ai.idre.ucla.edu` — Open WebUI Signup-Open + LDAP + LiteLLM Dual-Exposed</title><link>https://nuclide-research.com/cases/case-studies--universities--us--ca-ucla/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--ca-ucla/</guid><description>UCLA&apos;s Institute for Digital Research and Education (IDRE) runs a multi-service LLM stack at ai.idre.ucla.edu (128.97.60.220, Los Angeles). Three distinct services on three ports: Open WebUI v0.9.1 on :3000 with enablesignup: true and enableldap: true (signup-open class observed; LDAP federation observed), and LiteLLM Proxy v1.83.4 served twice — once direct…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--ca-ucla.png&quot; alt=&quot;UCLA: Multi-Service AI Stack on `ai.idre.ucla.edu` — Open WebUI Signup-Open + LDAP + LiteLLM Dual-Exposed&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;UCLA&amp;#39;s Institute for Digital Research and Education (IDRE) runs a multi-service LLM stack at ai.idre.ucla.edu (128.97.60.220, Los Angeles). Three distinct services on three ports: Open WebUI v0.9.1 on :3000 with enablesignup: true and enableldap: true (signup-open class observed; LDAP federation observed), and LiteLLM Proxy v1.83.4 served twice — once direct…&lt;/p&gt;
&lt;p&gt;UCLA&amp;#39;s Institute for Digital Research and Education (IDRE) runs a multi-service LLM stack at ai.idre.ucla.edu (128.97.60.220, Los Angeles). Three distinct services on three ports: Open WebUI v0.9.1 on :3000 with enablesignup: true and enableldap: true (signup-open class observed; LDAP federation observed), and LiteLLM Proxy v1.83.4 served twice — once directly via uvicorn on :8000 and once nginx-fronted on :80 — with /openapi.json, /public/providers, and /public/litellmmodelcostmap returning 200 unauth (info-disclosure class observed; content endpoints /v1/ correctly enforce authentication).&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--ca-ucla/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--ca-ucla.png" length="0" type="image/png"/></item><item><title>Red Rocks Community College: Open WebUI v0.9.2 on `datalab02.rrcc.edu` — Auth-On + LDAP (First Community College in Survey)</title><link>https://nuclide-research.com/cases/case-studies--universities--us--co-red-rocks/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--co-red-rocks/</guid><description>Red Rocks Community College runs an Open WebUI instance at datalab02.rrcc.edu (164.47.99.16:8080). /api/config returned Open WebUI v0.9.2 with enablesignup: false (auth-on; no signup-open class) and enableldap: true (LDAP federation backend enabled). Properly configured closed-enrollment deployment. First community college observed in the NuClide .edu LLM-in…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--co-red-rocks.png&quot; alt=&quot;Red Rocks Community College: Open WebUI v0.9.2 on `datalab02.rrcc.edu` — Auth-On + LDAP (First Community College in Survey)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;Red Rocks Community College runs an Open WebUI instance at datalab02.rrcc.edu (164.47.99.16:8080). /api/config returned Open WebUI v0.9.2 with enablesignup: false (auth-on; no signup-open class) and enableldap: true (LDAP federation backend enabled). Properly configured closed-enrollment deployment. First community college observed in the NuClide .edu LLM-in…&lt;/p&gt;
&lt;p&gt;Red Rocks Community College runs an Open WebUI instance at datalab02.rrcc.edu (164.47.99.16:8080). /api/config returned Open WebUI v0.9.2 with enablesignup: false (auth-on; no signup-open class) and enableldap: true (LDAP federation backend enabled). Properly configured closed-enrollment deployment. First community college observed in the NuClide .edu LLM-infra ledger.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--co-red-rocks/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--co-red-rocks.png" length="0" type="image/png"/></item><item><title>University of South Florida: Marine Lab JupyterHubs (auth-enforced) + Adjacent Prometheus `/metrics` Public</title><link>https://nuclide-research.com/cases/case-studies--universities--us--fl-usf/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--fl-usf/</guid><description>USF College of Marine Science operates two JupyterHub instances on the marine.usf.edu subdomain: ocgmod1.marine.usf.edu (131.247.139.171:8000) and manglillo.marine.usf.edu (131.247.136.183:8000). Both correctly enforce authentication (/hub/api/info returns 403 &quot;Missing or invalid credentials&quot;). However, the manglillo host has a separate Prometheus instance o…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--fl-usf.png&quot; alt=&quot;University of South Florida: Marine Lab JupyterHubs (auth-enforced) + Adjacent Prometheus `/metrics` Public&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;USF College of Marine Science operates two JupyterHub instances on the marine.usf.edu subdomain: ocgmod1.marine.usf.edu (131.247.139.171:8000) and manglillo.marine.usf.edu (131.247.136.183:8000). Both correctly enforce authentication (/hub/api/info returns 403 &amp;quot;Missing or invalid credentials&amp;quot;). However, the manglillo host has a separate Prometheus instance o…&lt;/p&gt;
&lt;p&gt;USF College of Marine Science operates two JupyterHub instances on the marine.usf.edu subdomain: ocgmod1.marine.usf.edu (131.247.139.171:8000) and manglillo.marine.usf.edu (131.247.136.183:8000). Both correctly enforce authentication (/hub/api/info returns 403 &amp;quot;Missing or invalid credentials&amp;quot;). However, the manglillo host has a separate Prometheus instance on port 9090 with /metrics returning 90 KB of unauthenticated metric data — a co-located observability service exposed without auth alongside the auth-enforced JupyterHub.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--fl-usf/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--fl-usf.png" length="0" type="image/png"/></item><item><title>Georgia State University: Streamlit app on `gluon.gsu.edu:8501` (framework confirmed; app content WebSocket-only)</title><link>https://nuclide-research.com/cases/case-studies--universities--us--ga-georgia-state/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--ga-georgia-state/</guid><description>Georgia State University runs a Streamlit application at gluon.gsu.edu (131.96.55.92:8501). The Streamlit framework is confirmed via /stcore/health returning ok. The application title is the Streamlit default (&lt;title&gt;Streamlit&lt;/title&gt; in the rendered HTML — no customization). Actual application content is served over Streamlit&apos;s WebSocket data channel; stati…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--ga-georgia-state.png&quot; alt=&quot;Georgia State University: Streamlit app on `gluon.gsu.edu:8501` (framework confirmed; app content WebSocket-only)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;Georgia State University runs a Streamlit application at gluon.gsu.edu (131.96.55.92:8501). The Streamlit framework is confirmed via /stcore/health returning ok. The application title is the Streamlit default (&amp;lt;title&amp;gt;Streamlit&amp;lt;/title&amp;gt; in the rendered HTML — no customization). Actual application content is served over Streamlit&amp;#39;s WebSocket data channel; stati…&lt;/p&gt;
&lt;p&gt;Georgia State University runs a Streamlit application at gluon.gsu.edu (131.96.55.92:8501). The Streamlit framework is confirmed via /stcore/health returning ok. The application title is the Streamlit default (&amp;lt;title&amp;gt;Streamlit&amp;lt;/title&amp;gt; in the rendered HTML — no customization). Actual application content is served over Streamlit&amp;#39;s WebSocket data channel; static probes cannot enumerate the app&amp;#39;s purpose without establishing an interactive session.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--ga-georgia-state/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--ga-georgia-state.png" length="0" type="image/png"/></item><item><title>DePaul University: Campus-Wide Port-3000 Population — Live Open WebUI Auth-On, DHCP-Rotated Hosts, Mixed Student Dev Work</title><link>https://nuclide-research.com/cases/case-studies--universities--us--il-depaul/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--il-depaul/</guid><description>DePaul&apos;s institutional network surfaces 20+ hosts with port 3000 open when scoped via Shodan org:&quot;DePaul University&quot;. Only 4 of these have HTTP title &quot;Open WebUI&quot;; the rest are student dev servers (React apps, project portfolios, course assignments). Of the 4 Open WebUI hosts, one was the original signup-open target captured during Stage-0 (lpc-eduroam-187-2…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--il-depaul.png&quot; alt=&quot;DePaul University: Campus-Wide Port-3000 Population — Live Open WebUI Auth-On, DHCP-Rotated Hosts, Mixed Student Dev Work&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;DePaul&amp;#39;s institutional network surfaces 20+ hosts with port 3000 open when scoped via Shodan org:&amp;quot;DePaul University&amp;quot;. Only 4 of these have HTTP title &amp;quot;Open WebUI&amp;quot;; the rest are student dev servers (React apps, project portfolios, course assignments). Of the 4 Open WebUI hosts, one was the original signup-open target captured during Stage-0 (lpc-eduroam-187-2…&lt;/p&gt;
&lt;p&gt;DePaul&amp;#39;s institutional network surfaces 20+ hosts with port 3000 open when scoped via Shodan org:&amp;quot;DePaul University&amp;quot;. Only 4 of these have HTTP title &amp;quot;Open WebUI&amp;quot;; the rest are student dev servers (React apps, project portfolios, course assignments). Of the 4 Open WebUI hosts, one was the original signup-open target captured during Stage-0 (lpc-eduroam-187-239.eduroam-employee.depaul.edu) — that hostname&amp;#39;s DHCP-assigned IP has since rotated and the host is no longer reachable. Three other employee-network Open WebUI hosts are visible in Shodan; one (140.192.183.141) was verified at probe time as Open WebUI v0.4.7 with enablesignup: false (auth-on, NOT exploitable for takeover). Documents the DHCP-rotation operational pattern + the &amp;quot;port 3000 ≠ Open WebUI&amp;quot; false-positive class at the .edu institutional scope.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--il-depaul/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--il-depaul.png" length="0" type="image/png"/></item><item><title>University of Chicago: Two-Host Observation — Streamlit on `helabserver0` (auth-on framework) + JupyterHub on `jupyterhub-dev.grid` (502 Bad Gateway / degraded)</title><link>https://nuclide-research.com/cases/case-studies--universities--us--il-uchicago/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--il-uchicago/</guid><description>The University of Chicago surfaces two distinct hosts in this survey: helabserver0.uchicago.edu running a Streamlit application on port 8501, and jupyterhub-dev.grid.uchicago.edu running JupyterHub on port 8000. The Streamlit host has framework-confirmed deployment with default title; the JupyterHub host returns HTTP 502 Bad Gateway, indicating the service i…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--il-uchicago.png&quot; alt=&quot;University of Chicago: Two-Host Observation — Streamlit on `helabserver0` (auth-on framework) + JupyterHub on `jupyterhub-dev.grid` (502 Bad Gateway / degraded)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;The University of Chicago surfaces two distinct hosts in this survey: helabserver0.uchicago.edu running a Streamlit application on port 8501, and jupyterhub-dev.grid.uchicago.edu running JupyterHub on port 8000. The Streamlit host has framework-confirmed deployment with default title; the JupyterHub host returns HTTP 502 Bad Gateway, indicating the service i…&lt;/p&gt;
&lt;p&gt;The University of Chicago surfaces two distinct hosts in this survey: helabserver0.uchicago.edu running a Streamlit application on port 8501, and jupyterhub-dev.grid.uchicago.edu running JupyterHub on port 8000. The Streamlit host has framework-confirmed deployment with default title; the JupyterHub host returns HTTP 502 Bad Gateway, indicating the service is degraded / not serving requests.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--il-uchicago/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--il-uchicago.png" length="0" type="image/png"/></item><item><title>University of Maryland College Park: Open WebUI v0.3.32 on `amorgos.umd.edu` — `enable_signup:true` OBSERVED on Very-Old Version</title><link>https://nuclide-research.com/cases/case-studies--universities--us--md-umd-college-park/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--md-umd-college-park/</guid><description>University of Maryland College Park runs an Open WebUI instance at amorgos.umd.edu (128.8.235.4, Brookeville MD). /api/config returned enablesignup: true on Open WebUI v0.3.32 — class membership for signup-open OBSERVED. Version 0.3.32 is significantly older than the current Open WebUI release line; multiple disclosed advisories apply per the publicly-known…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--md-umd-college-park.png&quot; alt=&quot;University of Maryland College Park: Open WebUI v0.3.32 on `amorgos.umd.edu` — `enable_signup:true` OBSERVED on Very-Old Version&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;University of Maryland College Park runs an Open WebUI instance at amorgos.umd.edu (128.8.235.4, Brookeville MD). /api/config returned enablesignup: true on Open WebUI v0.3.32 — class membership for signup-open OBSERVED. Version 0.3.32 is significantly older than the current Open WebUI release line; multiple disclosed advisories apply per the publicly-known…&lt;/p&gt;
&lt;p&gt;University of Maryland College Park runs an Open WebUI instance at amorgos.umd.edu (128.8.235.4, Brookeville MD). /api/config returned enablesignup: true on Open WebUI v0.3.32 — class membership for signup-open OBSERVED. Version 0.3.32 is significantly older than the current Open WebUI release line; multiple disclosed advisories apply per the publicly-known version-vulnerability mapping. Apache 2.4.58 serving the Ubuntu default &amp;quot;It works&amp;quot; page is present on port 80 alongside the OW deployment on port 8080.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--md-umd-college-park/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--md-umd-college-park.png" length="0" type="image/png"/></item><item><title>University of Southern Maine: 8-Host JupyterHub Fleet on `cs.usm.maine.edu` — Entomology-Themed Research Cluster, All Auth-Enforced</title><link>https://nuclide-research.com/cases/case-studies--universities--us--me-southern-maine/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--me-southern-maine/</guid><description>University of Southern Maine&apos;s CS department runs an 8-host JupyterHub fleet on the cs.usm.maine.edu subdomain, with hostnames following an entomology theme (wasp, earwig, locust, mosquito, ant, beetle) plus two computing-pioneer-named hosts (turing, pascal). All 8 hosts respond to /hub/api/info with HTTP 403 &quot;Missing or invalid credentials&quot; — JupyterHub aut…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--me-southern-maine.png&quot; alt=&quot;University of Southern Maine: 8-Host JupyterHub Fleet on `cs.usm.maine.edu` — Entomology-Themed Research Cluster, All Auth-Enforced&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;University of Southern Maine&amp;#39;s CS department runs an 8-host JupyterHub fleet on the cs.usm.maine.edu subdomain, with hostnames following an entomology theme (wasp, earwig, locust, mosquito, ant, beetle) plus two computing-pioneer-named hosts (turing, pascal). All 8 hosts respond to /hub/api/info with HTTP 403 &amp;quot;Missing or invalid credentials&amp;quot; — JupyterHub aut…&lt;/p&gt;
&lt;p&gt;University of Southern Maine&amp;#39;s CS department runs an 8-host JupyterHub fleet on the cs.usm.maine.edu subdomain, with hostnames following an entomology theme (wasp, earwig, locust, mosquito, ant, beetle) plus two computing-pioneer-named hosts (turing, pascal). All 8 hosts respond to /hub/api/info with HTTP 403 &amp;quot;Missing or invalid credentials&amp;quot; — JupyterHub authentication is correctly enforced fleet-wide. Documented here as an institutional-fleet entry: same operator, same configuration template, properly secured across the deployment.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--me-southern-maine/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--me-southern-maine.png" length="0" type="image/png"/></item><item><title>Cooper Union for the Advancement of Science and Art: Open WebUI v0.9.2 on `kahan.ee.cooper.edu` — Auth-On + LDAP</title><link>https://nuclide-research.com/cases/case-studies--universities--us--ny-cooper-union/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--ny-cooper-union/</guid><description>Cooper Union runs an Open WebUI instance at kahan.ee.cooper.edu (199.98.27.237). /api/config returned Open WebUI v0.9.2 with enablesignup: false (auth-on; no signup-open class) and enableldap: true (LDAP federation backend enabled). Properly configured closed-enrollment deployment with directory integration. Documented as a wave-2 cohort entry — first privat…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--ny-cooper-union.png&quot; alt=&quot;Cooper Union for the Advancement of Science and Art: Open WebUI v0.9.2 on `kahan.ee.cooper.edu` — Auth-On + LDAP&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;Cooper Union runs an Open WebUI instance at kahan.ee.cooper.edu (199.98.27.237). /api/config returned Open WebUI v0.9.2 with enablesignup: false (auth-on; no signup-open class) and enableldap: true (LDAP federation backend enabled). Properly configured closed-enrollment deployment with directory integration. Documented as a wave-2 cohort entry — first privat…&lt;/p&gt;
&lt;p&gt;Cooper Union runs an Open WebUI instance at kahan.ee.cooper.edu (199.98.27.237). /api/config returned Open WebUI v0.9.2 with enablesignup: false (auth-on; no signup-open class) and enableldap: true (LDAP federation backend enabled). Properly configured closed-enrollment deployment with directory integration. Documented as a wave-2 cohort entry — first private engineering school in the survey.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--ny-cooper-union/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--ny-cooper-union.png" length="0" type="image/png"/></item><item><title>Cornell University: Open WebUI v0.6.14 on `onepl.aap.cornell.edu` — Auth-On + API Keys Enabled</title><link>https://nuclide-research.com/cases/case-studies--universities--us--ny-cornell/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--ny-cornell/</guid><description>Cornell University runs an Open WebUI instance at onepl.aap.cornell.edu (128.253.41.30:3000). /api/config returned Open WebUI v0.6.14 with enablesignup: false (auth-on; no signup-open class) and enableapikey: true (post-authentication API key minting enabled). Properly configured for closed enrollment. Documented here as a wave-2 cohort entry: contrasts with…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--ny-cornell.png&quot; alt=&quot;Cornell University: Open WebUI v0.6.14 on `onepl.aap.cornell.edu` — Auth-On + API Keys Enabled&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;Cornell University runs an Open WebUI instance at onepl.aap.cornell.edu (128.253.41.30:3000). /api/config returned Open WebUI v0.6.14 with enablesignup: false (auth-on; no signup-open class) and enableapikey: true (post-authentication API key minting enabled). Properly configured for closed enrollment. Documented here as a wave-2 cohort entry: contrasts with…&lt;/p&gt;
&lt;p&gt;Cornell University runs an Open WebUI instance at onepl.aap.cornell.edu (128.253.41.30:3000). /api/config returned Open WebUI v0.6.14 with enablesignup: false (auth-on; no signup-open class) and enableapikey: true (post-authentication API key minting enabled). Properly configured for closed enrollment. Documented here as a wave-2 cohort entry: contrasts with wave-1 signup-open hosts.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--ny-cornell/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--ny-cornell.png" length="0" type="image/png"/></item><item><title>University of Washington: Streamlit app on `D4-084.ce.washington.edu:8501` (Civil Engineering dept; framework confirmed)</title><link>https://nuclide-research.com/cases/case-studies--universities--us--wa-uw/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--universities--us--wa-uw/</guid><description>University of Washington&apos;s Civil Engineering department surfaces a Streamlit application at D4-084.ce.washington.edu (128.95.204.84:8501). Streamlit framework confirmed via /stcore/health returning ok. Hostname pattern (D4-084) suggests a numbered lab compute host in the CE department. App-level title is the Streamlit default; per restraint ethic, the WebSoc…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--universities--us--wa-uw.png&quot; alt=&quot;University of Washington: Streamlit app on `D4-084.ce.washington.edu:8501` (Civil Engineering dept; framework confirmed)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Universities&lt;/p&gt;
&lt;p&gt;University of Washington&amp;#39;s Civil Engineering department surfaces a Streamlit application at D4-084.ce.washington.edu (128.95.204.84:8501). Streamlit framework confirmed via /stcore/health returning ok. Hostname pattern (D4-084) suggests a numbered lab compute host in the CE department. App-level title is the Streamlit default; per restraint ethic, the WebSoc…&lt;/p&gt;
&lt;p&gt;University of Washington&amp;#39;s Civil Engineering department surfaces a Streamlit application at D4-084.ce.washington.edu (128.95.204.84:8501). Streamlit framework confirmed via /stcore/health returning ok. Hostname pattern (D4-084) suggests a numbered lab compute host in the CE department. App-level title is the Streamlit default; per restraint ethic, the WebSocket session that would reveal app content was not established.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--universities--us--wa-uw/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--universities--us--wa-uw.png" length="0" type="image/png"/></item><item><title>Tegrity / McGraw-Hill Campus Self-Registration — ASP.NET YSOD + Service Outage</title><link>https://nuclide-research.com/cases/case-studies--commercial--tegrity-mhcampus-selfreg-2026-05-18/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--tegrity-mhcampus-selfreg-2026-05-18/</guid><description>selfreg.tegrity.com, the production self-registration service for McGraw-Hill Campus, is failing at AppDomain initialization. The AWS SDK for .NET&apos;s credential provider chain exhausts because the host has no IAM credentials reachable (no instance profile, no env vars, no IMDS response). Every URL — including /robots.txt and /favicon.ico — returns the same 17…</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--tegrity-mhcampus-selfreg-2026-05-18.png&quot; alt=&quot;Tegrity / McGraw-Hill Campus Self-Registration — ASP.NET YSOD + Service Outage&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;selfreg.tegrity.com, the production self-registration service for McGraw-Hill Campus, is failing at AppDomain initialization. The AWS SDK for .NET&amp;#39;s credential provider chain exhausts because the host has no IAM credentials reachable (no instance profile, no env vars, no IMDS response). Every URL — including /robots.txt and /favicon.ico — returns the same 17…&lt;/p&gt;
&lt;p&gt;selfreg.tegrity.com, the production self-registration service for McGraw-Hill Campus, is failing at AppDomain initialization. The AWS SDK for .NET&amp;#39;s credential provider chain exhausts because the host has no IAM credentials reachable (no instance profile, no env vars, no IMDS response). Every URL — including /robots.txt and /favicon.ico — returns the same 17,539-byte ASP.NET Yellow Screen of Death, byte-identical across all three ELB pool members.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--tegrity-mhcampus-selfreg-2026-05-18/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--tegrity-mhcampus-selfreg-2026-05-18.png" length="0" type="image/png"/></item><item><title>Adya AI: WandB workspace exfil via unauth FastAPI proxy (vanijmcp.adya.ai)</title><link>https://nuclide-research.com/cases/case-studies--commercial--adya-ai-vanijmcp-2026-05-17/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--adya-ai-vanijmcp-2026-05-17/</guid><description>vanijmcp.adya.ai (20.198.18.237) is an Adya AI infrastructure host on Microsoft Azure India. It exposes seven services on different ports. The headline finding is on port 5005: a custom FastAPI service named &quot;WandB Service&quot; with embedded Weights &amp; Biases credentials. Any internet client can query it and receive the operator&apos;s entire WandB workspace, includin…</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--adya-ai-vanijmcp-2026-05-17.png&quot; alt=&quot;Adya AI: WandB workspace exfil via unauth FastAPI proxy (vanijmcp.adya.ai)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;vanijmcp.adya.ai (20.198.18.237) is an Adya AI infrastructure host on Microsoft Azure India. It exposes seven services on different ports. The headline finding is on port 5005: a custom FastAPI service named &amp;quot;WandB Service&amp;quot; with embedded Weights &amp;amp; Biases credentials. Any internet client can query it and receive the operator&amp;#39;s entire WandB workspace, includin…&lt;/p&gt;
&lt;p&gt;vanijmcp.adya.ai (20.198.18.237) is an Adya AI infrastructure host on Microsoft Azure India. It exposes seven services on different ports. The headline finding is on port 5005: a custom FastAPI service named &amp;quot;WandB Service&amp;quot; with embedded Weights &amp;amp; Biases credentials. Any internet client can query it and receive the operator&amp;#39;s entire WandB workspace, including project metadata, training runs, configs, summaries, full training-history time series, and logged-artifact metadata.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--adya-ai-vanijmcp-2026-05-17/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--adya-ai-vanijmcp-2026-05-17.png" length="0" type="image/png"/></item><item><title>Hospital&apos;s AI chatbot exposes 270,000+ patient records</title><link>https://nuclide-research.com/cases/case-studies--commercial--multi-cross-survey-stacked-catastrophe-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--multi-cross-survey-stacked-catastrophe-2026-05-16/</guid><description>A multi-tenant Chinese hospital AI assistant is running on a single Chinese-cloud-hosted IP with every layer of its AI stack reachable from the public internet without authentication. The chatbot&apos;s RAG (retrieval-augmented generation) backend stores patient records in a vector database whose collection names alone disclose what&apos;s inside: prescriptions, surgi…</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--multi-cross-survey-stacked-catastrophe-2026-05-16.png&quot; alt=&quot;Hospital&amp;#39;s AI chatbot exposes 270,000+ patient records&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;A multi-tenant Chinese hospital AI assistant is running on a single Chinese-cloud-hosted IP with every layer of its AI stack reachable from the public internet without authentication. The chatbot&amp;#39;s RAG (retrieval-augmented generation) backend stores patient records in a vector database whose collection names alone disclose what&amp;#39;s inside: prescriptions, surgi…&lt;/p&gt;
&lt;p&gt;A multi-tenant Chinese hospital AI assistant is running on a single Chinese-cloud-hosted IP with every layer of its AI stack reachable from the public internet without authentication. The chatbot&amp;#39;s RAG (retrieval-augmented generation) backend stores patient records in a vector database whose collection names alone disclose what&amp;#39;s inside: prescriptions, surgical history, inpatient and outpatient visits, billing, diagnoses, doctor names, patient names. The Elasticsearch index holding the RAG document chunks contains 214,597 entity-vector documents and 55,807 source-text chunks.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--multi-cross-survey-stacked-catastrophe-2026-05-16/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--multi-cross-survey-stacked-catastrophe-2026-05-16.png" length="0" type="image/png"/></item><item><title>alpha_miner Job Scheduler: 194.233.71.223 (Contabo SG)</title><link>https://nuclide-research.com/cases/case-studies--commercial--alpha-miner-194-233-71-223-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--alpha-miner-194-233-71-223-2026-05-15/</guid><description>- IP: 194.233.71.223
- rDNS: vmi2733226.contaboserver.net
- ASN: AS141995 Contabo Asia Private Limited
- Location: Singapore (Contabo Asia Pte Ltd, 8 Robinson Road / International Plaza)
- WHOIS abuse: abuse@contabo.de
- Passive DNS (HackerTarget) cluster on same IP:
  - aceservice.store
  - ackeliling.store (Bahasa Indonesia: &quot;AC keliling&quot; = mobile AC servi…</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--alpha-miner-194-233-71-223-2026-05-15.png&quot; alt=&quot;alpha_miner Job Scheduler: 194.233.71.223 (Contabo SG)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;- IP: 194.233.71.223
- rDNS: vmi2733226.contaboserver.net
- ASN: AS141995 Contabo Asia Private Limited
- Location: Singapore (Contabo Asia Pte Ltd, 8 Robinson Road / International Plaza)
- WHOIS abuse: abuse@contabo.de
- Passive DNS (HackerTarget) cluster on same IP:
  - aceservice.store
  - ackeliling.store (Bahasa Indonesia: &amp;quot;AC keliling&amp;quot; = mobile AC servi…&lt;/p&gt;
&lt;p&gt;- IP: 194.233.71.223
- rDNS: vmi2733226.contaboserver.net
- ASN: AS141995 Contabo Asia Private Limited
- Location: Singapore (Contabo Asia Pte Ltd, 8 Robinson Road / International Plaza)
- WHOIS abuse: abuse@contabo.de
- Passive DNS (HackerTarget) cluster on same IP:
  - aceservice.store
  - ackeliling.store (Bahasa Indonesia: &amp;quot;AC keliling&amp;quot; = mobile AC service)
  - jasatukangac.store (&amp;quot;jasa tukang AC&amp;quot; = AC repairman service)
  - liangserviceac.store
  - warungngopi.xyz (&amp;quot;warung ngopi&amp;quot; = coffee stall)&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--alpha-miner-194-233-71-223-2026-05-15/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--alpha-miner-194-233-71-223-2026-05-15.png" length="0" type="image/png"/></item><item><title>23.239.19.219: Exposed LlamaIndex Chat with Broken Backend, Multi-Tenant SNI Co-Tenancy</title><link>https://nuclide-research.com/cases/case-studies--commercial--llamaindex-chat-23-239-19-219-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--llamaindex-chat-23-239-19-219-2026-05-15/</guid><description>23.239.19.219. Linode US datacenter (Akamai AS), 23.239.0.0/19, rDNS 23-239-19-219.ip.linodeusercontent.com. Linode shared-allocation, neighbor at .217 is harperdbcloud.com. No AS63949 honeypot salt match. Verdict &quot;no honeypot signals&quot; per aimap-profile.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--llamaindex-chat-23-239-19-219-2026-05-15.png&quot; alt=&quot;23.239.19.219: Exposed LlamaIndex Chat with Broken Backend, Multi-Tenant SNI Co-Tenancy&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;23.239.19.219. Linode US datacenter (Akamai AS), 23.239.0.0/19, rDNS 23-239-19-219.ip.linodeusercontent.com. Linode shared-allocation, neighbor at .217 is harperdbcloud.com. No AS63949 honeypot salt match. Verdict &amp;quot;no honeypot signals&amp;quot; per aimap-profile.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--llamaindex-chat-23-239-19-219-2026-05-15/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--llamaindex-chat-23-239-19-219-2026-05-15.png" length="0" type="image/png"/></item><item><title>SmartShop AI / amazonrec.space: Multi-service ML pipeline exposure on a single PENTECH host</title><link>https://nuclide-research.com/cases/case-studies--commercial--smartshop-ai-pentech-disclosure-2026-05-13/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--smartshop-ai-pentech-disclosure-2026-05-13/</guid><description>NuClide Research · 2026-05-13</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--smartshop-ai-pentech-disclosure-2026-05-13.png&quot; alt=&quot;SmartShop AI / amazonrec.space: Multi-service ML pipeline exposure on a single PENTECH host&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-13&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--smartshop-ai-pentech-disclosure-2026-05-13/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--smartshop-ai-pentech-disclosure-2026-05-13.png" length="0" type="image/png"/></item><item><title>reputacion.digital: Multi-surface chained exposure (Phoenix + NFS + Prometheus + dev SMTP)</title><link>https://nuclide-research.com/cases/case-studies--commercial--ar-reputacion-digital-multi-surface-2026-05-10/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--ar-reputacion-digital-multi-surface-2026-05-10/</guid><description>NuClide Research · 2026-05-10</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--ar-reputacion-digital-multi-surface-2026-05-10.png&quot; alt=&quot;reputacion.digital: Multi-surface chained exposure (Phoenix + NFS + Prometheus + dev SMTP)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-10&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--ar-reputacion-digital-multi-surface-2026-05-10/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--ar-reputacion-digital-multi-surface-2026-05-10.png" length="0" type="image/png"/></item><item><title>CouchDB Telecom Consent Platform: Active RCE + 244M Subscriber Records</title><link>https://nuclide-research.com/cases/case-studies--commercial--couchdb-telecom-consent-rce-2026-05-09/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--couchdb-telecom-consent-rce-2026-05-09/</guid><description>Unauth CouchDB 2.3.1 on Microsoft Azure (Pune, India) hosting Airtel + Tata telecom consent management infrastructure. 7.1M consent records, 244M subscriber preferences with MSISDN phone numbers. Instance has been actively exploited via CVE-2022-24706. 9 attack design documents present including a live reverse shell beacon to 57.131.25.205:4444 (OVH Roubaix,…</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--couchdb-telecom-consent-rce-2026-05-09.png&quot; alt=&quot;CouchDB Telecom Consent Platform: Active RCE + 244M Subscriber Records&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;Unauth CouchDB 2.3.1 on Microsoft Azure (Pune, India) hosting Airtel + Tata telecom consent management infrastructure. 7.1M consent records, 244M subscriber preferences with MSISDN phone numbers. Instance has been actively exploited via CVE-2022-24706. 9 attack design documents present including a live reverse shell beacon to 57.131.25.205:4444 (OVH Roubaix,…&lt;/p&gt;
&lt;p&gt;Unauth CouchDB 2.3.1 on Microsoft Azure (Pune, India) hosting Airtel + Tata telecom consent management infrastructure. 7.1M consent records, 244M subscriber preferences with MSISDN phone numbers. Instance has been actively exploited via CVE-2022-24706. 9 attack design documents present including a live reverse shell beacon to 57.131.25.205:4444 (OVH Roubaix, France).&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--couchdb-telecom-consent-rce-2026-05-09/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--couchdb-telecom-consent-rce-2026-05-09.png" length="0" type="image/png"/></item><item><title>NATS JetStream: ParamWallet Production Ledger + AI Pipeline (Open Pub/Sub)</title><link>https://nuclide-research.com/cases/case-studies--commercial--nats-jetstream-paramwallet-ledger-2026-05-09/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--nats-jetstream-paramwallet-ledger-2026-05-09/</guid><description>141.148.212.34 (Oracle Cloud Mumbai). Production NATS JetStream cluster running an AI document-processing pipeline coupled to a private blockchain ledger. NATS protocol port 4222 advertises no auth requirement; unauthenticated clients can list streams, read all message contents, and publish to any subject. Workspace hil-taloja (likely Hindustan Infrastructur…</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--nats-jetstream-paramwallet-ledger-2026-05-09.png&quot; alt=&quot;NATS JetStream: ParamWallet Production Ledger + AI Pipeline (Open Pub/Sub)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;141.148.212.34 (Oracle Cloud Mumbai). Production NATS JetStream cluster running an AI document-processing pipeline coupled to a private blockchain ledger. NATS protocol port 4222 advertises no auth requirement; unauthenticated clients can list streams, read all message contents, and publish to any subject. Workspace hil-taloja (likely Hindustan Infrastructur…&lt;/p&gt;
&lt;p&gt;141.148.212.34 (Oracle Cloud Mumbai). Production NATS JetStream cluster running an AI document-processing pipeline coupled to a private blockchain ledger. NATS protocol port 4222 advertises no auth requirement; unauthenticated clients can list streams, read all message contents, and publish to any subject. Workspace hil-taloja (likely Hindustan Infrastructure Ltd. Taloja, Mumbai industrial area). TLS cert .paramwallet.com ties the host to ParamWallet, a fintech wallet/payment platform. AI pipeline (AITASKS, DOCUMENTS) feeds a smart-contract gateway (GATEWAY, TRANSACTIONS, LEDGERNODES, OFFCHAIN). An attacker on the open NATS port can inject ledger transactions, poison AI classifications, and alter document state-machine transitions.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--nats-jetstream-paramwallet-ledger-2026-05-09/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--nats-jetstream-paramwallet-ledger-2026-05-09.png" length="0" type="image/png"/></item><item><title>Anduril Industries, Lattice Monitoring Plane (Telefonica ARO Grafana), Disclosure Sent, Awaiting Acknowledgment</title><link>https://nuclide-research.com/cases/case-studies--commercial--anduril-lattice-dev-infrastructure-2026-05-08/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--anduril-lattice-dev-infrastructure-2026-05-08/</guid><description>NuClide Research · 2026-05-08 (sent 2026-05-09)</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--anduril-lattice-dev-infrastructure-2026-05-08.png&quot; alt=&quot;Anduril Industries, Lattice Monitoring Plane (Telefonica ARO Grafana), Disclosure Sent, Awaiting Acknowledgment&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-08 (sent 2026-05-09)&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--anduril-lattice-dev-infrastructure-2026-05-08/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--anduril-lattice-dev-infrastructure-2026-05-08.png" length="0" type="image/png"/></item><item><title>ollama launch claude-desktop: Gateway-mode MITM by default + community-tutorial typosquat surface</title><link>https://nuclide-research.com/cases/case-studies--commercial--vendor-ollama-launch-claude-desktop-2026-05-07/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--vendor-ollama-launch-claude-desktop-2026-05-07/</guid><description>NuClide Research, 2026-05-07</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--vendor-ollama-launch-claude-desktop-2026-05-07.png&quot; alt=&quot;ollama launch claude-desktop: Gateway-mode MITM by default + community-tutorial typosquat surface&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research, 2026-05-07&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--vendor-ollama-launch-claude-desktop-2026-05-07/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--vendor-ollama-launch-claude-desktop-2026-05-07.png" length="0" type="image/png"/></item><item><title>Vendor-template adjacent-vendor sweep, planning doc + Shodan dork catalog (2026-05-07)</title><link>https://nuclide-research.com/cases/case-studies--commercial--vendor-template-adjacent-sweep-2026-05-07/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--vendor-template-adjacent-sweep-2026-05-07/</guid><description>NuClide Research, 2026-05-07</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--vendor-template-adjacent-sweep-2026-05-07.png&quot; alt=&quot;Vendor-template adjacent-vendor sweep, planning doc + Shodan dork catalog (2026-05-07)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research, 2026-05-07&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--vendor-template-adjacent-sweep-2026-05-07/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--vendor-template-adjacent-sweep-2026-05-07.png" length="0" type="image/png"/></item><item><title>Hetzner LiteLLM proxy fronting Ollama-cpu + 4 RunPod GPU pods, fully unauth (65.108.197.157)</title><link>https://nuclide-research.com/cases/case-studies--commercial--hetzner-65-108-litellm-runpod-2026-05-06/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--hetzner-65-108-litellm-runpod-2026-05-06/</guid><description>NuClide Research · 2026-05-06</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--hetzner-65-108-litellm-runpod-2026-05-06.png&quot; alt=&quot;Hetzner LiteLLM proxy fronting Ollama-cpu + 4 RunPod GPU pods, fully unauth (65.108.197.157)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-06&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--hetzner-65-108-litellm-runpod-2026-05-06/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--hetzner-65-108-litellm-runpod-2026-05-06.png" length="0" type="image/png"/></item><item><title>AIPOD orthodontic AI MLflow + Label Studio + S3 stack, CVE-2023-1177 actively-exploited (138.197.152.103)</title><link>https://nuclide-research.com/cases/case-studies--commercial--multi-aipod-mlflow-cve-2026-05-06/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--multi-aipod-mlflow-cve-2026-05-06/</guid><description>NuClide Research · 2026-05-06</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--multi-aipod-mlflow-cve-2026-05-06.png&quot; alt=&quot;AIPOD orthodontic AI MLflow + Label Studio + S3 stack, CVE-2023-1177 actively-exploited (138.197.152.103)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-06&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--multi-aipod-mlflow-cve-2026-05-06/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--multi-aipod-mlflow-cve-2026-05-06.png" length="0" type="image/png"/></item><item><title>Hilix-class botnet campaign, multi-victim Jupyter-targeted operation (Ulm Cortical Labs + Tencent OpenClaw)</title><link>https://nuclide-research.com/cases/case-studies--commercial--multi-hilix-jupyter-campaign-2026-05-06/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--multi-hilix-jupyter-campaign-2026-05-06/</guid><description>NuClide Research · 2026-05-06</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--multi-hilix-jupyter-campaign-2026-05-06.png&quot; alt=&quot;Hilix-class botnet campaign, multi-victim Jupyter-targeted operation (Ulm Cortical Labs + Tencent OpenClaw)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-06&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--multi-hilix-jupyter-campaign-2026-05-06/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--multi-hilix-jupyter-campaign-2026-05-06.png" length="0" type="image/png"/></item><item><title>Pediatric medical ML operator, 224 unauth MLflow experiments + Metabase setup-token unclaimed (65.109.36.121)</title><link>https://nuclide-research.com/cases/case-studies--commercial--multi-pediatric-mlflow-metabase-setup-2026-05-06/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--multi-pediatric-mlflow-metabase-setup-2026-05-06/</guid><description>NuClide Research · 2026-05-06</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--multi-pediatric-mlflow-metabase-setup-2026-05-06.png&quot; alt=&quot;Pediatric medical ML operator, 224 unauth MLflow experiments + Metabase setup-token unclaimed (65.109.36.121)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-06&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--multi-pediatric-mlflow-metabase-setup-2026-05-06/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--multi-pediatric-mlflow-metabase-setup-2026-05-06.png" length="0" type="image/png"/></item><item><title>Squeeze/Helios short-squeeze trading platform, full architecture leaked + MLflow CVE-2023-1177 actively exploited (159.203.110.202)</title><link>https://nuclide-research.com/cases/case-studies--commercial--multi-squeeze-helios-trading-2026-05-06/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--multi-squeeze-helios-trading-2026-05-06/</guid><description>NuClide Research · 2026-05-06</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--multi-squeeze-helios-trading-2026-05-06.png&quot; alt=&quot;Squeeze/Helios short-squeeze trading platform, full architecture leaked + MLflow CVE-2023-1177 actively exploited (159.203.110.202)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-06&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--multi-squeeze-helios-trading-2026-05-06/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--multi-squeeze-helios-trading-2026-05-06.png" length="0" type="image/png"/></item><item><title>Triton chat-safety pipeline, minor-detection classifier still live (159.203.42.211 + 178.62.225.198)</title><link>https://nuclide-research.com/cases/case-studies--commercial--multi-triton-chat-safety-2026-05-06/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--multi-triton-chat-safety-2026-05-06/</guid><description>NuClide Research · 2026-05-06</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--multi-triton-chat-safety-2026-05-06.png&quot; alt=&quot;Triton chat-safety pipeline, minor-detection classifier still live (159.203.42.211 + 178.62.225.198)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-06&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--multi-triton-chat-safety-2026-05-06/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--multi-triton-chat-safety-2026-05-06.png" length="0" type="image/png"/></item><item><title>Vendor-template default-no-auth on research-instrument web stacks, pattern recognition + fleet-audit roadmap</title><link>https://nuclide-research.com/cases/case-studies--commercial--vendor-template-default-no-auth-research-instruments/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial--vendor-template-default-no-auth-research-instruments/</guid><description>NuClide Research · 2026-05-06</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial--vendor-template-default-no-auth-research-instruments.png&quot; alt=&quot;Vendor-template default-no-auth on research-instrument web stacks, pattern recognition + fleet-audit roadmap&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Commercial&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-06&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial--vendor-template-default-no-auth-research-instruments/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial--vendor-template-default-no-auth-research-instruments.png" length="0" type="image/png"/></item><item><title>Commercial AI Infrastructure Exposures</title><link>https://nuclide-research.com/cases/case-studies--commercial/</link><guid isPermaLink="true">https://nuclide-research.com/cases/case-studies--commercial/</guid><description>Commercial / SaaS Ollama and AI infrastructure exposures discovered during OSINT sweeps. These differ from university and research-network exposures in that the operators are commercial entities with paying customers and PII pipelines.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/cases/case-studies--commercial.png&quot; alt=&quot;Commercial AI Infrastructure Exposures&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sector:&lt;/strong&gt; Other&lt;/p&gt;
&lt;p&gt;Commercial / SaaS Ollama and AI infrastructure exposures discovered during OSINT sweeps. These differ from university and research-network exposures in that the operators are commercial entities with paying customers and PII pipelines.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/cases/case-studies--commercial/&quot;&gt;Read the engagement record →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/cases/case-studies--commercial.png" length="0" type="image/png"/></item></channel></rss>