<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>NuClide Research, Surveys &amp; Synthesis</title><description>Cross-cloud surveys and synthesis papers covering AI/LLM infrastructure exposures.</description><link>https://nuclide-research.com/</link><language>en-us</language><item><title>LangGraph Studio Population Survey — Local Dev Tool Misdeployed to Public AWS at 90.9%</title><link>https://nuclide-research.com/research/case-studies--commercial--langgraph-studio-population-survey-2026-06-07/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--langgraph-studio-population-survey-2026-06-07/</guid><description>LangGraph Studio (github.com/langchain-ai/langgraph) is LangChain&apos;s local-development debugger / visualizer for LangGraph applications. It is designed to run on localhost:2024 during development, with desktop auth-type meaning no authentication is required because access is assumed to be from the same machine as the developer. LangChain ships separate produc…</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--langgraph-studio-population-survey-2026-06-07.png&quot; alt=&quot;LangGraph Studio Population Survey — Local Dev Tool Misdeployed to Public AWS at 90.9%&quot; /&gt;&lt;/p&gt;
&lt;p&gt;LangGraph Studio (github.com/langchain-ai/langgraph) is LangChain&amp;#39;s local-development debugger / visualizer for LangGraph applications. It is designed to run on localhost:2024 during development, with desktop auth-type meaning no authentication is required because access is assumed to be from the same machine as the developer. LangChain ships separate produc…&lt;/p&gt;
&lt;p&gt;LangGraph Studio (github.com/langchain-ai/langgraph) is LangChain&amp;#39;s local-development debugger / visualizer for LangGraph applications. It is designed to run on localhost:2024 during development, with desktop auth-type meaning no authentication is required because access is assumed to be from the same machine as the developer. LangChain ships separate production tooling — LangGraph Cloud (paid SaaS) and LangGraph Platform (self-hosted enterprise) — which use proper auth.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--langgraph-studio-population-survey-2026-06-07/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--langgraph-studio-population-survey-2026-06-07.png" length="0" type="image/png"/></item><item><title>OpenHands Population Survey — Autonomous Agent Task History + LLM Config Exposed at Scale</title><link>https://nuclide-research.com/research/case-studies--commercial--openhands-population-survey-2026-06-07/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--openhands-population-survey-2026-06-07/</guid><description>OpenHands (github.com/All-Hands-AI/OpenHands, formerly OpenDevin) is an autonomous coding agent platform with multiple agent types (CodeActAgent, BrowsingAgent, VisualBrowsingAgent, ReadOnlyAgent, LocAgent, DummyAgent) that can interact with code repositories, browse the web, execute shell commands, and modify files. The platform represents one of the highes…</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--openhands-population-survey-2026-06-07.png&quot; alt=&quot;OpenHands Population Survey — Autonomous Agent Task History + LLM Config Exposed at Scale&quot; /&gt;&lt;/p&gt;
&lt;p&gt;OpenHands (github.com/All-Hands-AI/OpenHands, formerly OpenDevin) is an autonomous coding agent platform with multiple agent types (CodeActAgent, BrowsingAgent, VisualBrowsingAgent, ReadOnlyAgent, LocAgent, DummyAgent) that can interact with code repositories, browse the web, execute shell commands, and modify files. The platform represents one of the highes…&lt;/p&gt;
&lt;p&gt;OpenHands (github.com/All-Hands-AI/OpenHands, formerly OpenDevin) is an autonomous coding agent platform with multiple agent types (CodeActAgent, BrowsingAgent, VisualBrowsingAgent, ReadOnlyAgent, LocAgent, DummyAgent) that can interact with code repositories, browse the web, execute shell commands, and modify files. The platform represents one of the highest-LLM06 (Excessive Agency) attack surfaces in the current AI/LLM infrastructure population.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--openhands-population-survey-2026-06-07/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--openhands-population-survey-2026-06-07.png" length="0" type="image/png"/></item><item><title>The Auth-on-Default Landscape of OSS AI/LLM Infrastructure</title><link>https://nuclide-research.com/research/case-studies--commercial--synthesis-2026-06-07-auth-on-default-cohort/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--synthesis-2026-06-07-auth-on-default-cohort/</guid><description>Two-day population survey across 13 OSS AI/LLM infrastructure platforms reveals a maintainer-culture-axis split between demo-first defaults (auth-permissive, 70-91% open) and enterprise-customer-first defaults (auth-required, 0-1%). The cohort is not jurisdiction-defined. Insight #76 scope-bounded to platform class; LLM02 Sensitive Information Disclosure is the dominant finding class; the Capitol.ai escalation demonstrates the maintainer-default failing at enterprise-SaaS scale; in-flight attacker /proc/self/environ activity directly observable on OpenHands instances.</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--synthesis-2026-06-07-auth-on-default-cohort.png&quot; alt=&quot;The Auth-on-Default Landscape of OSS AI/LLM Infrastructure&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Two-day population survey across 13 OSS AI/LLM infrastructure platforms reveals a maintainer-culture-axis split between demo-first defaults (auth-permissive, 70-91% open) and enterprise-customer-first defaults (auth-required, 0-1%). The cohort is not jurisdiction-defined. Insight #76 scope-bounded to platform class; LLM02 Sensitive Information Disclosure is the dominant finding class; the Capitol.ai escalation demonstrates the maintainer-default failing at enterprise-SaaS scale; in-flight attacker /proc/self/environ activity directly observable on OpenHands instances.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--synthesis-2026-06-07-auth-on-default-cohort/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--synthesis-2026-06-07-auth-on-default-cohort.png" length="0" type="image/png"/></item><item><title>Bisheng Population Survey — Negative Result (Auth-Required Default)</title><link>https://nuclide-research.com/research/case-studies--commercial--bisheng-population-survey-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--bisheng-population-survey-2026-06-06/</guid><description>Bisheng (github.com/dataelement/bisheng) is an open-source LLM application development platform from DataElem (Beijing), focused on enterprise-oriented document AI, RAG, agent orchestration, and workflow building. Direct functional parallel to RAGFlow (also Shanghai-based) and Flowise.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--bisheng-population-survey-2026-06-06.png&quot; alt=&quot;Bisheng Population Survey — Negative Result (Auth-Required Default)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Bisheng (github.com/dataelement/bisheng) is an open-source LLM application development platform from DataElem (Beijing), focused on enterprise-oriented document AI, RAG, agent orchestration, and workflow building. Direct functional parallel to RAGFlow (also Shanghai-based) and Flowise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--bisheng-population-survey-2026-06-06/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--bisheng-population-survey-2026-06-06.png" length="0" type="image/png"/></item><item><title>Dify Population Survey — 939 Config-Disclosure, 9 Open Auth Findings</title><link>https://nuclide-research.com/research/case-studies--commercial--dify-population-survey-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--dify-population-survey-2026-06-06/</guid><description>Dify is an open-source LLM application development platform (drag-and-drop workflow builder, RAG pipelines, agent orchestration). 2,289 Shodan-indexed instances on http.title:&quot;Dify&quot;.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--dify-population-survey-2026-06-06.png&quot; alt=&quot;Dify Population Survey — 939 Config-Disclosure, 9 Open Auth Findings&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Dify is an open-source LLM application development platform (drag-and-drop workflow builder, RAG pipelines, agent orchestration). 2,289 Shodan-indexed instances on http.title:&amp;quot;Dify&amp;quot;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--dify-population-survey-2026-06-06/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--dify-population-survey-2026-06-06.png" length="0" type="image/png"/></item><item><title>Flowise Population Survey — 578/841 Open, CVE-2024-36420 PoC Lab Exposed</title><link>https://nuclide-research.com/research/case-studies--commercial--flowise-population-survey-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--flowise-population-survey-2026-06-06/</guid><description>Flowise is a drag-and-drop LLM workflow builder. Default deployment: no authentication on /api/v1/chatflows — the endpoint returns the full list of all configured chatflows, their nodes, deployment status, and embedded credentials in flow configurations.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--flowise-population-survey-2026-06-06.png&quot; alt=&quot;Flowise Population Survey — 578/841 Open, CVE-2024-36420 PoC Lab Exposed&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Flowise is a drag-and-drop LLM workflow builder. Default deployment: no authentication on /api/v1/chatflows — the endpoint returns the full list of all configured chatflows, their nodes, deployment status, and embedded credentials in flow configurations.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--flowise-population-survey-2026-06-06/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--flowise-population-survey-2026-06-06.png" length="0" type="image/png"/></item><item><title>Langfuse Population Survey — 816/918 Open Registration (88.9%)</title><link>https://nuclide-research.com/research/case-studies--commercial--langfuse-population-survey-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--langfuse-population-survey-2026-06-06/</guid><description>Langfuse is an open-source LLM observability platform (trace ingestion, prompt analytics, evaluation tooling for production AI applications). 1,141 Shodan-indexed instances on &quot;Langfuse&quot; port:3000. 918 responded to live probing. 816 (88.9% of live, 71.5% of indexed) expose signUpDisabled: false to the public internet.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--langfuse-population-survey-2026-06-06.png&quot; alt=&quot;Langfuse Population Survey — 816/918 Open Registration (88.9%)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Langfuse is an open-source LLM observability platform (trace ingestion, prompt analytics, evaluation tooling for production AI applications). 1,141 Shodan-indexed instances on &amp;quot;Langfuse&amp;quot; port:3000. 918 responded to live probing. 816 (88.9% of live, 71.5% of indexed) expose signUpDisabled: false to the public internet.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--langfuse-population-survey-2026-06-06/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--langfuse-population-survey-2026-06-06.png" length="0" type="image/png"/></item><item><title>LibreChat Population Survey — 412/1,565 Open Registration (26.3%)</title><link>https://nuclide-research.com/research/case-studies--commercial--librechat-population-survey-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--librechat-population-survey-2026-06-06/</guid><description>LibreChat (github.com/danny-avila/LibreChat) is an open-source ChatGPT-alternative chat interface — supports multiple LLM providers, plugins, multimodal, multi-tenant via shared deployments. 3,153 Shodan-indexed instances on http.title:&quot;LibreChat&quot;. 2,000 downloaded; 1,565 responded.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--librechat-population-survey-2026-06-06.png&quot; alt=&quot;LibreChat Population Survey — 412/1,565 Open Registration (26.3%)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;LibreChat (github.com/danny-avila/LibreChat) is an open-source ChatGPT-alternative chat interface — supports multiple LLM providers, plugins, multimodal, multi-tenant via shared deployments. 3,153 Shodan-indexed instances on http.title:&amp;quot;LibreChat&amp;quot;. 2,000 downloaded; 1,565 responded.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--librechat-population-survey-2026-06-06/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--librechat-population-survey-2026-06-06.png" length="0" type="image/png"/></item><item><title>Cat-05: LiteLLM Gateway Survey — Open Proxies Exposing Commercial LLM API Keys</title><link>https://nuclide-research.com/research/case-studies--commercial--litellm-gateway-survey-cat05-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--litellm-gateway-survey-cat05-2026-06-06/</guid><description>The hunt started with a single Shodan dork: http.title:&quot;LiteLLM&quot; port:4000. It returned 2,219 results in under a second.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--litellm-gateway-survey-cat05-2026-06-06.png&quot; alt=&quot;Cat-05: LiteLLM Gateway Survey — Open Proxies Exposing Commercial LLM API Keys&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The hunt started with a single Shodan dork: http.title:&amp;quot;LiteLLM&amp;quot; port:4000. It returned 2,219 results in under a second.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--litellm-gateway-survey-cat05-2026-06-06/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--litellm-gateway-survey-cat05-2026-06-06.png" length="0" type="image/png"/></item><item><title>LobeChat Population Survey — 10/12 Fully Open (83.3%, small population)</title><link>https://nuclide-research.com/research/case-studies--commercial--lobechat-population-survey-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--lobechat-population-survey-2026-06-06/</guid><description>LobeChat (github.com/lobehub/lobe-chat) is an open-source ChatGPT-alternative chat interface from Lobehub, a China-origin OSS community. Direct functional parallel to LibreChat. 641 Shodan-indexed; 636 downloaded; only 12 of 636 (1.9%) responded to live HTTP probing. Of the 12 reachable: 10 are in fully-open mode (enabledAccessCode: false AND enabledOAuthSSO…</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--lobechat-population-survey-2026-06-06.png&quot; alt=&quot;LobeChat Population Survey — 10/12 Fully Open (83.3%, small population)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;LobeChat (github.com/lobehub/lobe-chat) is an open-source ChatGPT-alternative chat interface from Lobehub, a China-origin OSS community. Direct functional parallel to LibreChat. 641 Shodan-indexed; 636 downloaded; only 12 of 636 (1.9%) responded to live HTTP probing. Of the 12 reachable: 10 are in fully-open mode (enabledAccessCode: false AND enabledOAuthSSO…&lt;/p&gt;
&lt;p&gt;LobeChat (github.com/lobehub/lobe-chat) is an open-source ChatGPT-alternative chat interface from Lobehub, a China-origin OSS community. Direct functional parallel to LibreChat. 641 Shodan-indexed; 636 downloaded; only 12 of 636 (1.9%) responded to live HTTP probing. Of the 12 reachable: 10 are in fully-open mode (enabledAccessCode: false AND enabledOAuthSSO: false), 2 are ACCESSCODEGATED, 1 of the open instances also has OAuth SSO available alongside no-access-code.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--lobechat-population-survey-2026-06-06/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--lobechat-population-survey-2026-06-06.png" length="0" type="image/png"/></item><item><title>Open WebUI Population Survey — 39 Auth-Off, 564 Open Signup</title><link>https://nuclide-research.com/research/case-studies--commercial--openwebui-population-survey-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--openwebui-population-survey-2026-06-06/</guid><description>18,389 Shodan-indexed instances of Open WebUI. One GET to /api/config returns a JSON object that tells you everything: whether auth is enforced, whether public registration is open, the operator&apos;s branding name, and the exact version. No scanning required.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--openwebui-population-survey-2026-06-06.png&quot; alt=&quot;Open WebUI Population Survey — 39 Auth-Off, 564 Open Signup&quot; /&gt;&lt;/p&gt;
&lt;p&gt;18,389 Shodan-indexed instances of Open WebUI. One GET to /api/config returns a JSON object that tells you everything: whether auth is enforced, whether public registration is open, the operator&amp;#39;s branding name, and the exact version. No scanning required.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--openwebui-population-survey-2026-06-06/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--openwebui-population-survey-2026-06-06.png" length="0" type="image/png"/></item><item><title>Cat-OW Calibration Deltas — 5 Named Findings Re-Verified</title><link>https://nuclide-research.com/research/case-studies--commercial--openwebui-population-survey-2026-06-06-calibration-deltas/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--openwebui-population-survey-2026-06-06-calibration-deltas/</guid><description>A spot-check verification pass on five named-institution findings in the
Open WebUI population survey, applying the attribution hierarchy from
Insight #79.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--openwebui-population-survey-2026-06-06-calibration-deltas.png&quot; alt=&quot;Cat-OW Calibration Deltas — 5 Named Findings Re-Verified&quot; /&gt;&lt;/p&gt;
&lt;p&gt;A spot-check verification pass on five named-institution findings in the
Open WebUI population survey, applying the attribution hierarchy from
Insight #79.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--openwebui-population-survey-2026-06-06-calibration-deltas/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--openwebui-population-survey-2026-06-06-calibration-deltas.png" length="0" type="image/png"/></item><item><title>Arize Phoenix Population Survey — 41/55 Unauthenticated Project Disclosure</title><link>https://nuclide-research.com/research/case-studies--commercial--phoenix-population-survey-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--phoenix-population-survey-2026-06-06/</guid><description>Arize Phoenix (github.com/Arize-ai/phoenix) is an open-source LLM observability and tracing platform — span ingestion, project organization, dataset versioning, prompt management for production AI applications. 94 Shodan-indexed instances on &quot;Phoenix&quot; port:6006. 89 unique endpoints downloaded; 55 responded.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--phoenix-population-survey-2026-06-06.png&quot; alt=&quot;Arize Phoenix Population Survey — 41/55 Unauthenticated Project Disclosure&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Arize Phoenix (github.com/Arize-ai/phoenix) is an open-source LLM observability and tracing platform — span ingestion, project organization, dataset versioning, prompt management for production AI applications. 94 Shodan-indexed instances on &amp;quot;Phoenix&amp;quot; port:6006. 89 unique endpoints downloaded; 55 responded.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--phoenix-population-survey-2026-06-06/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--phoenix-population-survey-2026-06-06.png" length="0" type="image/png"/></item><item><title>RAGFlow Population Survey — 618/709 Open Registration (87.2%)</title><link>https://nuclide-research.com/research/case-studies--commercial--ragflow-population-survey-2026-06-06/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--ragflow-population-survey-2026-06-06/</guid><description>RAGFlow (github.com/infiniflow/ragflow) is an open-source RAG knowledge-base engine — document ingestion, vector retrieval, LLM-backed Q&amp;A over enterprise knowledge bases. 1,915 Shodan-indexed instances on http.title:&quot;RAGFlow&quot;. 709 responded to live probing. 618 (87.2% of live, 32.3% of indexed) expose registerEnabled: 1 to the public internet.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--ragflow-population-survey-2026-06-06.png&quot; alt=&quot;RAGFlow Population Survey — 618/709 Open Registration (87.2%)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;RAGFlow (github.com/infiniflow/ragflow) is an open-source RAG knowledge-base engine — document ingestion, vector retrieval, LLM-backed Q&amp;amp;A over enterprise knowledge bases. 1,915 Shodan-indexed instances on http.title:&amp;quot;RAGFlow&amp;quot;. 709 responded to live probing. 618 (87.2% of live, 32.3% of indexed) expose registerEnabled: 1 to the public internet.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--ragflow-population-survey-2026-06-06/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--ragflow-population-survey-2026-06-06.png" length="0" type="image/png"/></item><item><title>Cat-03 Model Serving &amp; Inference — Survey 2026-06-05</title><link>https://nuclide-research.com/research/case-studies--commercial--cat03-model-serving-survey-2026-06-05/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--cat03-model-serving-survey-2026-06-05/</guid><description>Survey of 5,018 IPs across 17 Shodan and 9 Censys queries targeting Cat-03 (model serving and inference: llama.cpp, KoboldCpp, LM Studio, vLLM, SillyTavern, faster-whisper, One API, New API, Open WebUI, SGLang, GPT4All, HuggingFace TGI). 158 hosts responded live; aimap fingerprinted 72 services and flagged 20 CRITICAL / 19 HIGH. Verification of the flagged c…</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--cat03-model-serving-survey-2026-06-05.png&quot; alt=&quot;Cat-03 Model Serving &amp;amp; Inference — Survey 2026-06-05&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Survey of 5,018 IPs across 17 Shodan and 9 Censys queries targeting Cat-03 (model serving and inference: llama.cpp, KoboldCpp, LM Studio, vLLM, SillyTavern, faster-whisper, One API, New API, Open WebUI, SGLang, GPT4All, HuggingFace TGI). 158 hosts responded live; aimap fingerprinted 72 services and flagged 20 CRITICAL / 19 HIGH. Verification of the flagged c…&lt;/p&gt;
&lt;p&gt;Survey of 5,018 IPs across 17 Shodan and 9 Censys queries targeting Cat-03 (model serving and inference: llama.cpp, KoboldCpp, LM Studio, vLLM, SillyTavern, faster-whisper, One API, New API, Open WebUI, SGLang, GPT4All, HuggingFace TGI). 158 hosts responded live; aimap fingerprinted 72 services and flagged 20 CRITICAL / 19 HIGH. Verification of the flagged candidates refuted the majority: the One API/New API default-credential thesis did not hold at population scale (0/9), and four &amp;quot;GPT Researcher&amp;quot;, one &amp;quot;Lunary&amp;quot;, one &amp;quot;h2oGPT&amp;quot;, and two TTS fingerprints were misattributions. Six hosts confirmed genuinely unauthenticated with a 200-with-data read. The most material finding is an unauthenticated Ollama instance proxying a paid Ollama Connect cloud subscription (deepseek-v4-pro:cloud), callable by any internet host.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--cat03-model-serving-survey-2026-06-05/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--cat03-model-serving-survey-2026-06-05.png" length="0" type="image/png"/></item><item><title>AI Gateways Population Survey: Cat-32 (2026-06-01)</title><link>https://nuclide-research.com/research/case-studies--commercial--ai-gateways-survey-cat32-2026-06-01/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--ai-gateways-survey-cat32-2026-06-01/</guid><description>An AI gateway sits in front of every upstream LLM provider an operator uses. It holds the OpenAI key, the Anthropic key, the Gemini key, the DeepSeek key. All in one process. That is the point of the product. It is also the problem.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--ai-gateways-survey-cat32-2026-06-01.png&quot; alt=&quot;AI Gateways Population Survey: Cat-32 (2026-06-01)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;An AI gateway sits in front of every upstream LLM provider an operator uses. It holds the OpenAI key, the Anthropic key, the Gemini key, the DeepSeek key. All in one process. That is the point of the product. It is also the problem.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--ai-gateways-survey-cat32-2026-06-01/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--ai-gateways-survey-cat32-2026-06-01.png" length="0" type="image/png"/></item><item><title>Argo Workflows Population Survey — Cat-29 (2026-05-31)</title><link>https://nuclide-research.com/research/case-studies--commercial--argo-workflows-survey-cat29-2026-05-31/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--argo-workflows-survey-cat29-2026-05-31/</guid><description>&lt;!-- ksat-tag:auto-generated:start --&gt;
## DCWF KSAT coverage</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--argo-workflows-survey-cat29-2026-05-31.png&quot; alt=&quot;Argo Workflows Population Survey — Cat-29 (2026-05-31)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- ksat-tag:auto-generated:start --&amp;gt;
## DCWF KSAT coverage&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--argo-workflows-survey-cat29-2026-05-31/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--argo-workflows-survey-cat29-2026-05-31.png" length="0" type="image/png"/></item><item><title>Data Labeling &amp; Annotation: the registration knob that re-opens the door</title><link>https://nuclide-research.com/research/case-studies--commercial--data-labeling-survey-2026-05-31/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--data-labeling-survey-2026-05-31/</guid><description>Data-labeling platforms sit at the input boundary of every supervised-learning and
RLHF pipeline. They hold the raw data being labeled: PII-dense text, scanned
documents, medical and facial imagery, and the human-preference pairs that fine-tune
LLMs. A 2026-05-04 cheap-VPS pass had already shown the category is auth-on by
default (doccano 348/348, 98.9% auth…</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--data-labeling-survey-2026-05-31.png&quot; alt=&quot;Data Labeling &amp;amp; Annotation: the registration knob that re-opens the door&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Data-labeling platforms sit at the input boundary of every supervised-learning and
RLHF pipeline. They hold the raw data being labeled: PII-dense text, scanned
documents, medical and facial imagery, and the human-preference pairs that fine-tune
LLMs. A 2026-05-04 cheap-VPS pass had already shown the category is auth-on by
default (doccano 348/348, 98.9% auth…&lt;/p&gt;
&lt;p&gt;Data-labeling platforms sit at the input boundary of every supervised-learning and
RLHF pipeline. They hold the raw data being labeled: PII-dense text, scanned
documents, medical and facial imagery, and the human-preference pairs that fine-tune
LLMs. A 2026-05-04 cheap-VPS pass had already shown the category is auth-on by
default (doccano 348/348, 98.9% auth-on). So this survey was not a literal-no-auth
hunt. It asked a sharper question: when a platform ships auth-on, does its own
default-open knob (open self-registration, a documented default API key, no-auth
commercial mode) re-create effective-unauth at population scale? And it targeted the
managed-cloud tier the cheap-VPS pass had missed.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--data-labeling-survey-2026-05-31/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--data-labeling-survey-2026-05-31.png" length="0" type="image/png"/></item><item><title>RAG Framework Servers Population Survey — Cat-07 (2026-05-31)</title><link>https://nuclide-research.com/research/case-studies--commercial--rag-frameworks-survey-cat07-2026-05-31/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--rag-frameworks-survey-cat07-2026-05-31/</guid><description>First population survey of the RAG-framework-server category. 16 platforms in the 2026-05-27 pre-assessment intel (data/platform-intel/rag-frameworks-osint-2026-05-27.md); 15 dorks run this session. The category spans private document-QA workspaces, RAG pipelines, agentic-RAG, and self-hosted AI search — platforms whose value is the document corpus and conne…</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--rag-frameworks-survey-cat07-2026-05-31.png&quot; alt=&quot;RAG Framework Servers Population Survey — Cat-07 (2026-05-31)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;First population survey of the RAG-framework-server category. 16 platforms in the 2026-05-27 pre-assessment intel (data/platform-intel/rag-frameworks-osint-2026-05-27.md); 15 dorks run this session. The category spans private document-QA workspaces, RAG pipelines, agentic-RAG, and self-hosted AI search — platforms whose value is the document corpus and conne…&lt;/p&gt;
&lt;p&gt;First population survey of the RAG-framework-server category. 16 platforms in the 2026-05-27 pre-assessment intel (data/platform-intel/rag-frameworks-osint-2026-05-27.md); 15 dorks run this session. The category spans private document-QA workspaces, RAG pipelines, agentic-RAG, and self-hosted AI search — platforms whose value is the document corpus and connected LLM API keys, not just compute.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--rag-frameworks-survey-cat07-2026-05-31/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--rag-frameworks-survey-cat07-2026-05-31.png" length="0" type="image/png"/></item><item><title>Service Mesh Control Planes: when exposure is the authentication failure</title><link>https://nuclide-research.com/research/case-studies--commercial--service-mesh-survey-2026-05-31/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--service-mesh-survey-2026-05-31/</guid><description>Every survey so far measured platforms that have an authentication layer and
ship it on or off. Service-mesh introspection planes are a harder test for the
auth-on-default thesis: most of them have no auth layer at all. Kiali&apos;s
anonymous strategy, Linkerd&apos;s viz dashboard, Cilium&apos;s Hubble UI and relay, Istio&apos;s
Envoy-admin and istiod-debug all rely on network…</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--service-mesh-survey-2026-05-31.png&quot; alt=&quot;Service Mesh Control Planes: when exposure is the authentication failure&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Every survey so far measured platforms that have an authentication layer and
ship it on or off. Service-mesh introspection planes are a harder test for the
auth-on-default thesis: most of them have no auth layer at all. Kiali&amp;#39;s
anonymous strategy, Linkerd&amp;#39;s viz dashboard, Cilium&amp;#39;s Hubble UI and relay, Istio&amp;#39;s
Envoy-admin and istiod-debug all rely on network…&lt;/p&gt;
&lt;p&gt;Every survey so far measured platforms that have an authentication layer and
ship it on or off. Service-mesh introspection planes are a harder test for the
auth-on-default thesis: most of them have no auth layer at all. Kiali&amp;#39;s
anonymous strategy, Linkerd&amp;#39;s viz dashboard, Cilium&amp;#39;s Hubble UI and relay, Istio&amp;#39;s
Envoy-admin and istiod-debug all rely on network placement (loopback,
ClusterIP, NetworkPolicy, &amp;quot;do not expose&amp;quot;) as the entire control. The question
this survey asks: when the only control is network position, what does the exposed
population look like? The prediction (Insight #71, codified here): exposure and
unauthenticated are the same fact, so the rate approaches 100% by construction.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--service-mesh-survey-2026-05-31/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--service-mesh-survey-2026-05-31.png" length="0" type="image/png"/></item><item><title>Specialty Data Layers survey, 2026-05-30</title><link>https://nuclide-research.com/research/case-studies--commercial--specialty-data-layers-survey-2026-05-29/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--specialty-data-layers-survey-2026-05-29/</guid><description>Three of five sampled Spark History Servers exposed their job inventories with no
authentication, and two of them are machine-learning pipelines. The job names are
the finding. They map the feature-engineering, training, and prediction stages of
an ML workflow on Google Cloud. ClickHouse returned 5,208 hosts on the empty-
password port, but confirming the un…</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--specialty-data-layers-survey-2026-05-29.png&quot; alt=&quot;Specialty Data Layers survey, 2026-05-30&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Three of five sampled Spark History Servers exposed their job inventories with no
authentication, and two of them are machine-learning pipelines. The job names are
the finding. They map the feature-engineering, training, and prediction stages of
an ML workflow on Google Cloud. ClickHouse returned 5,208 hosts on the empty-
password port, but confirming the un…&lt;/p&gt;
&lt;p&gt;Three of five sampled Spark History Servers exposed their job inventories with no
authentication, and two of them are machine-learning pipelines. The job names are
the finding. They map the feature-engineering, training, and prediction stages of
an ML workflow on Google Cloud. ClickHouse returned 5,208 hosts on the empty-
password port, but confirming the unauthenticated-query finding requires executing
SQL against production databases, which the scope discipline did not permit. The
population is real; the unauth claim is unverified, and this writeup says so.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--specialty-data-layers-survey-2026-05-29/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--specialty-data-layers-survey-2026-05-29.png" length="0" type="image/png"/></item><item><title>Auth / Identity / Gateway survey, 2026-05-29</title><link>https://nuclide-research.com/research/case-studies--commercial--auth-gateway-survey-2026-05-29/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--auth-gateway-survey-2026-05-29/</guid><description>Open Policy Agent ships with no authentication, and five of six sampled hosts
returned their full Rego policy list with no credentials. The policy names are the
finding. They map the operator&apos;s authorization model and the topology of whatever
AI stack sits behind them. The admin APIs of Kong and OPA are Shodan-dark because
they serve JSON, so the harvest fou…</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--auth-gateway-survey-2026-05-29.png&quot; alt=&quot;Auth / Identity / Gateway survey, 2026-05-29&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Open Policy Agent ships with no authentication, and five of six sampled hosts
returned their full Rego policy list with no credentials. The policy names are the
finding. They map the operator&amp;#39;s authorization model and the topology of whatever
AI stack sits behind them. The admin APIs of Kong and OPA are Shodan-dark because
they serve JSON, so the harvest fou…&lt;/p&gt;
&lt;p&gt;Open Policy Agent ships with no authentication, and five of six sampled hosts
returned their full Rego policy list with no credentials. The policy names are the
finding. They map the operator&amp;#39;s authorization model and the topology of whatever
AI stack sits behind them. The admin APIs of Kong and OPA are Shodan-dark because
they serve JSON, so the harvest found OPA only through the diagnostic page string.
Casdoor returned 1,375 identity-platform hosts that ship with the admin/123
default, a different exposure class the restraint ethic left untested.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--auth-gateway-survey-2026-05-29/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--auth-gateway-survey-2026-05-29.png" length="0" type="image/png"/></item><item><title>Experiment Tracking, registry and RCE half, 2026-05-29</title><link>https://nuclide-research.com/research/case-studies--commercial--experiment-tracking-registry-survey-2026-05-29/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--experiment-tracking-registry-survey-2026-05-29/</guid><description>MLflow ships with no authentication, and the population shows it: eight of eight
sampled servers returned the full experiment list with no credentials. One held
379 experiments and leaked a Google Cloud Storage bucket name. The other
high-severity targets did not deliver. Determined.ai was authenticated on every
reachable host, including two on AWS GovCloud,…</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--experiment-tracking-registry-survey-2026-05-29.png&quot; alt=&quot;Experiment Tracking, registry and RCE half, 2026-05-29&quot; /&gt;&lt;/p&gt;
&lt;p&gt;MLflow ships with no authentication, and the population shows it: eight of eight
sampled servers returned the full experiment list with no credentials. One held
379 experiments and leaked a Google Cloud Storage bucket name. The other
high-severity targets did not deliver. Determined.ai was authenticated on every
reachable host, including two on AWS GovCloud,…&lt;/p&gt;
&lt;p&gt;MLflow ships with no authentication, and the population shows it: eight of eight
sampled servers returned the full experiment list with no credentials. One held
379 experiments and leaked a Google Cloud Storage bucket name. The other
high-severity targets did not deliver. Determined.ai was authenticated on every
reachable host, including two on AWS GovCloud, so the admin:blank default did not
appear. Ray and Aim are Shodan-dark behind React single-page apps.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--experiment-tracking-registry-survey-2026-05-29/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--experiment-tracking-registry-survey-2026-05-29.png" length="0" type="image/png"/></item><item><title>ML Governance / Data Catalog survey, 2026-05-29</title><link>https://nuclide-research.com/research/case-studies--commercial--ml-governance-survey-2026-05-29/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--ml-governance-survey-2026-05-29/</guid><description>Nine dorks. Six platforms. The category is well-secured at population scale, and
that is the finding. The auth-on platforms run patched versions. The auth-off
platforms are either Shodan-dark or empty demos. One unauthenticated Marquez
server confirmed, and it held no production data.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--ml-governance-survey-2026-05-29.png&quot; alt=&quot;ML Governance / Data Catalog survey, 2026-05-29&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Nine dorks. Six platforms. The category is well-secured at population scale, and
that is the finding. The auth-on platforms run patched versions. The auth-off
platforms are either Shodan-dark or empty demos. One unauthenticated Marquez
server confirmed, and it held no production data.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--ml-governance-survey-2026-05-29/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--ml-governance-survey-2026-05-29.png" length="0" type="image/png"/></item><item><title>Model Serving, management-plane and registry, 2026-05-29</title><link>https://nuclide-research.com/research/case-studies--commercial--model-serving-management-survey-2026-05-29/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--model-serving-management-survey-2026-05-29/</guid><description>The model-serving category is Shodan-dark. vLLM, Triton, TGI, and TorchServe all
serve JSON APIs, and their identifying strings live in JSON bodies, not in the
HTML Shodan crawls. The dominant self-hosted LLM inference server returned one hit
on its own banner. That one host was a real unauthenticated vLLM serving a 20B
model. The management-bypass surfaces…</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--model-serving-management-survey-2026-05-29.png&quot; alt=&quot;Model Serving, management-plane and registry, 2026-05-29&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The model-serving category is Shodan-dark. vLLM, Triton, TGI, and TorchServe all
serve JSON APIs, and their identifying strings live in JSON bodies, not in the
HTML Shodan crawls. The dominant self-hosted LLM inference server returned one hit
on its own banner. That one host was a real unauthenticated vLLM serving a 20B
model. The management-bypass surfaces…&lt;/p&gt;
&lt;p&gt;The model-serving category is Shodan-dark. vLLM, Triton, TGI, and TorchServe all
serve JSON APIs, and their identifying strings live in JSON bodies, not in the
HTML Shodan crawls. The dominant self-hosted LLM inference server returned one hit
on its own banner. That one host was a real unauthenticated vLLM serving a 20B
model. The management-bypass surfaces that make this category dangerous are
invisible to passive discovery.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--model-serving-management-survey-2026-05-29/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--model-serving-management-survey-2026-05-29.png" length="0" type="image/png"/></item><item><title>RAG framework stragglers, 2026-05-29</title><link>https://nuclide-research.com/research/case-studies--commercial--rag-stragglers-survey-2026-05-29/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--rag-stragglers-survey-2026-05-29/</guid><description>AnythingLLM ships single-user mode with no password, and two of five sampled
hosts had the web UI open to any browser visitor. The verification narrowed the
finding: the open UI is browser-reachable, but the developer REST API still
demands a key even in no-auth mode. RAGFlow returned 1,705 hosts, a large
pre-auth-RCE-class population, but the RCE lives on a…</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--rag-stragglers-survey-2026-05-29.png&quot; alt=&quot;RAG framework stragglers, 2026-05-29&quot; /&gt;&lt;/p&gt;
&lt;p&gt;AnythingLLM ships single-user mode with no password, and two of five sampled
hosts had the web UI open to any browser visitor. The verification narrowed the
finding: the open UI is browser-reachable, but the developer REST API still
demands a key even in no-auth mode. RAGFlow returned 1,705 hosts, a large
pre-auth-RCE-class population, but the RCE lives on a…&lt;/p&gt;
&lt;p&gt;AnythingLLM ships single-user mode with no password, and two of five sampled
hosts had the web UI open to any browser visitor. The verification narrowed the
finding: the open UI is browser-reachable, but the developer REST API still
demands a key even in no-auth mode. RAGFlow returned 1,705 hosts, a large
pre-auth-RCE-class population, but the RCE lives on an internal RPC port and the
vulnerable version cannot be confirmed from outside, so the survey confirms
identity and stops there. LightRAG is Shodan-dark behind its JSON API.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--rag-stragglers-survey-2026-05-29/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--rag-stragglers-survey-2026-05-29.png" length="0" type="image/png"/></item><item><title>LLM Safety / Guardrail survey, 2026-05-29</title><link>https://nuclide-research.com/research/case-studies--commercial--safety-guardrail-survey-2026-05-29/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--safety-guardrail-survey-2026-05-29/</guid><description>Five dorks. One confirmed unauthenticated guardrail server, and the guardrail was
the least exposed thing on the box. The same host left MongoDB, Redis, MySQL,
PostgreSQL, and a Docker registry open with no authentication. The safety tool
meant to inspect untrusted input was sitting on an unlocked data tier.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--safety-guardrail-survey-2026-05-29.png&quot; alt=&quot;LLM Safety / Guardrail survey, 2026-05-29&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Five dorks. One confirmed unauthenticated guardrail server, and the guardrail was
the least exposed thing on the box. The same host left MongoDB, Redis, MySQL,
PostgreSQL, and a Docker registry open with no authentication. The safety tool
meant to inspect untrusted input was sitting on an unlocked data tier.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--safety-guardrail-survey-2026-05-29/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--safety-guardrail-survey-2026-05-29.png" length="0" type="image/png"/></item><item><title>AI Evaluation and Red-Team Platform Survey — Promptfoo Population Pass</title><link>https://nuclide-research.com/research/case-studies--commercial--ai-eval-redteam-survey-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--ai-eval-redteam-survey-2026-05-28/</guid><description>Promptfoo is the only AI eval/red-team platform in the 13-platform scope that produced confirmed unauthenticated exposure at scale. Four instances returned {&quot;email&quot;:null} on GET /api/user/email with eval datasets and provider configurations readable without credentials. The best-characterized instance (evals.dev.generalwisdom.com, AWS Ashburn) exposed 60 LLM…</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--ai-eval-redteam-survey-2026-05-28.png&quot; alt=&quot;AI Evaluation and Red-Team Platform Survey — Promptfoo Population Pass&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Promptfoo is the only AI eval/red-team platform in the 13-platform scope that produced confirmed unauthenticated exposure at scale. Four instances returned {&amp;quot;email&amp;quot;:null} on GET /api/user/email with eval datasets and provider configurations readable without credentials. The best-characterized instance (evals.dev.generalwisdom.com, AWS Ashburn) exposed 60 LLM…&lt;/p&gt;
&lt;p&gt;Promptfoo is the only AI eval/red-team platform in the 13-platform scope that produced confirmed unauthenticated exposure at scale. Four instances returned {&amp;quot;email&amp;quot;:null} on GET /api/user/email with eval datasets and provider configurations readable without credentials. The best-characterized instance (evals.dev.generalwisdom.com, AWS Ashburn) exposed 60 LLM provider configurations including the Anthropic Claude 4.x model family and Azure GPT-4o, along with active eval datasets including test case corpora, prompt templates, and token usage statistics from runs as recent as 2026-05-01. LangSmith self-hosted instances were auth-enforced across all 30+ sampled hosts; v0.10+ default auth tightening has held. The six remaining platforms with HTTP server modes (TruLens, Inspect AI, HELM, DeepEval, Arthur Shield, Patronus AI) produced zero confirmed instances on Shodan. Six platforms are CLI-only with no HTTP server; Shodan surface is zero by design.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--ai-eval-redteam-survey-2026-05-28/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--ai-eval-redteam-survey-2026-05-28.png" length="0" type="image/png"/></item><item><title>Auth and API Gateway Platforms: Population Survey</title><link>https://nuclide-research.com/research/case-studies--commercial--auth-gateway-survey-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--auth-gateway-survey-2026-05-28/</guid><description>Shodan harvest of 13 auth and API gateway platforms returned confirmed populations across six categories. SuperTokens (port 3567) is the largest exposed surface at 455 confirmed internet-facing instances with no API key configured by default. Authentik reaches or exceeds Shodan&apos;s 1,000-result display cap. Authelia shows 33 instances. Kong admin port (8001) r…</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--auth-gateway-survey-2026-05-28.png&quot; alt=&quot;Auth and API Gateway Platforms: Population Survey&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Shodan harvest of 13 auth and API gateway platforms returned confirmed populations across six categories. SuperTokens (port 3567) is the largest exposed surface at 455 confirmed internet-facing instances with no API key configured by default. Authentik reaches or exceeds Shodan&amp;#39;s 1,000-result display cap. Authelia shows 33 instances. Kong admin port (8001) r…&lt;/p&gt;
&lt;p&gt;Shodan harvest of 13 auth and API gateway platforms returned confirmed populations across six categories. SuperTokens (port 3567) is the largest exposed surface at 455 confirmed internet-facing instances with no API key configured by default. Authentik reaches or exceeds Shodan&amp;#39;s 1,000-result display cap. Authelia shows 33 instances. Kong admin port (8001) returns four direct admin API exposures. Casdoor, Keycloak, and ZITADEL have smaller footprints with IP populations harvested and queued for identity verification. Ory Kratos (port 4434), Ory Hydra (port 4445), OPA (port 8181), Tyk, and OPAL returned no hits on precision dorks, with broad port-only dorks requiring per-host verification before any finding can be claimed.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--auth-gateway-survey-2026-05-28/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--auth-gateway-survey-2026-05-28.png" length="0" type="image/png"/></item><item><title>Unauthenticated FinOps Cost APIs Hand Attackers a Free Cluster Recon Map</title><link>https://nuclide-research.com/research/case-studies--commercial--kubecost-opencost-finops-cost-api-survey-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--kubecost-opencost-finops-cost-api-survey-2026-05-28/</guid><description>Sixty-seven Kubernetes cost-tooling endpoints (Kubecost 50, OpenCost 14, vendor-undetermined 3) answer their cost-model API with no authentication. Fifty-nine return full per-namespace cluster topology and summed daily spend on a single unauthenticated GET. That is the finding: a FinOps cost sidecar, deployed to watch the wallet, indexes the entire cluster a…</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--kubecost-opencost-finops-cost-api-survey-2026-05-28.png&quot; alt=&quot;Unauthenticated FinOps Cost APIs Hand Attackers a Free Cluster Recon Map&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Sixty-seven Kubernetes cost-tooling endpoints (Kubecost 50, OpenCost 14, vendor-undetermined 3) answer their cost-model API with no authentication. Fifty-nine return full per-namespace cluster topology and summed daily spend on a single unauthenticated GET. That is the finding: a FinOps cost sidecar, deployed to watch the wallet, indexes the entire cluster a…&lt;/p&gt;
&lt;p&gt;Sixty-seven Kubernetes cost-tooling endpoints (Kubecost 50, OpenCost 14, vendor-undetermined 3) answer their cost-model API with no authentication. Fifty-nine return full per-namespace cluster topology and summed daily spend on a single unauthenticated GET. That is the finding: a FinOps cost sidecar, deployed to watch the wallet, indexes the entire cluster and then serves that index to anyone who asks. An unauthenticated caller gets a labeled map of every workload namespace, the cluster&amp;#39;s security control plane (secret stores, admission controllers, EDR/SIEM), a dollar-denominated ranking of which clusters are the high-value production estates, and on 10 host-rows a co-located AI/LLM workload inventory. No credential needs to leak for any of this. The cost API is the map; the namespaces it reveals are the marked destinations.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--kubecost-opencost-finops-cost-api-survey-2026-05-28/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--kubecost-opencost-finops-cost-api-survey-2026-05-28.png" length="0" type="image/png"/></item><item><title>Model Serving and Registry Infrastructure Survey</title><link>https://nuclide-research.com/research/case-studies--commercial--model-serving-registry-survey-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--model-serving-registry-survey-2026-05-28/</guid><description>Shodan sweep across 11 model-serving and registry platforms. MLflow is the only platform with a live, indexable population -- 10 confirmed unauthenticated instances spanning 6 cloud providers and 6 countries. Every other platform surveyed (vLLM, TorchServe, TensorFlow Serving, Ray Serve, BentoML, Seldon Core, KServe, ONNX Runtime Server, TGI, Triton) returne…</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--model-serving-registry-survey-2026-05-28.png&quot; alt=&quot;Model Serving and Registry Infrastructure Survey&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Shodan sweep across 11 model-serving and registry platforms. MLflow is the only platform with a live, indexable population -- 10 confirmed unauthenticated instances spanning 6 cloud providers and 6 countries. Every other platform surveyed (vLLM, TorchServe, TensorFlow Serving, Ray Serve, BentoML, Seldon Core, KServe, ONNX Runtime Server, TGI, Triton) returne…&lt;/p&gt;
&lt;p&gt;Shodan sweep across 11 model-serving and registry platforms. MLflow is the only platform with a live, indexable population -- 10 confirmed unauthenticated instances spanning 6 cloud providers and 6 countries. Every other platform surveyed (vLLM, TorchServe, TensorFlow Serving, Ray Serve, BentoML, Seldon Core, KServe, ONNX Runtime Server, TGI, Triton) returned zero live hosts.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--model-serving-registry-survey-2026-05-28/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--model-serving-registry-survey-2026-05-28.png" length="0" type="image/png"/></item><item><title>RAG Stragglers: LightRAG, RAGFlow, DocsGPT, Ragapp Population Survey</title><link>https://nuclide-research.com/research/case-studies--commercial--rag-stragglers-survey-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--rag-stragglers-survey-2026-05-28/</guid><description>Four RAG platforms were left unfinished from prior survey runs: LightRAG, RAGFlow, DocsGPT, and Ragapp. This pass closes them out with a full Shodan harvest, verification, and arsenal run.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--rag-stragglers-survey-2026-05-28.png&quot; alt=&quot;RAG Stragglers: LightRAG, RAGFlow, DocsGPT, Ragapp Population Survey&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Four RAG platforms were left unfinished from prior survey runs: LightRAG, RAGFlow, DocsGPT, and Ragapp. This pass closes them out with a full Shodan harvest, verification, and arsenal run.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--rag-stragglers-survey-2026-05-28/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--rag-stragglers-survey-2026-05-28.png" length="0" type="image/png"/></item><item><title>LLM Guard survey: guardrail platforms Shodan-dark except /metrics side-channel</title><link>https://nuclide-research.com/research/case-studies--commercial--safety-guardrail-survey-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--safety-guardrail-survey-2026-05-28/</guid><description>Two LLM Guard v0.0.10 instances confirmed from an 11-platform Shodan sweep. Both have auth configured on scan endpoints (/analyze/prompt, /analyze/output, /scan/output). Both expose /metrics without auth. The metrics endpoints leak operator domain names, internal docker network topology, container IPs, and production request volumes. F2 (57.128.58.103) has a…</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--safety-guardrail-survey-2026-05-28.png&quot; alt=&quot;LLM Guard survey: guardrail platforms Shodan-dark except /metrics side-channel&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Two LLM Guard v0.0.10 instances confirmed from an 11-platform Shodan sweep. Both have auth configured on scan endpoints (/analyze/prompt, /analyze/output, /scan/output). Both expose /metrics without auth. The metrics endpoints leak operator domain names, internal docker network topology, container IPs, and production request volumes. F2 (57.128.58.103) has a…&lt;/p&gt;
&lt;p&gt;Two LLM Guard v0.0.10 instances confirmed from an 11-platform Shodan sweep. Both have auth configured on scan endpoints (/analyze/prompt, /analyze/output, /scan/output). Both expose /metrics without auth. The metrics endpoints leak operator domain names, internal docker network topology, container IPs, and production request volumes. F2 (57.128.58.103) has a second open Prometheus instance on port 9090 with scrape topology naming litellm:4000/metrics as the upstream target. All other guardrail platforms surveyed (Vigil, Rebuff, NeMo Guardrails, Guardrails AI, LlamaGuard, ShieldLM, PromptGuard, LlamaFirewall, OpenShield) returned zero confirmed instances across all dorks.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--safety-guardrail-survey-2026-05-28/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--safety-guardrail-survey-2026-05-28.png" length="0" type="image/png"/></item><item><title>Cat-30: Specialty Data Layers — Population Survey</title><link>https://nuclide-research.com/research/case-studies--commercial--specialty-data-layers-survey-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--specialty-data-layers-survey-2026-05-28/</guid><description>&lt;!-- ksat-tag:auto-generated:start --&gt;
## DCWF KSAT coverage</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--specialty-data-layers-survey-2026-05-28.png&quot; alt=&quot;Cat-30: Specialty Data Layers — Population Survey&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- ksat-tag:auto-generated:start --&amp;gt;
## DCWF KSAT coverage&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--specialty-data-layers-survey-2026-05-28/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--specialty-data-layers-survey-2026-05-28.png" length="0" type="image/png"/></item><item><title>Voice/Audio AI Infrastructure Survey</title><link>https://nuclide-research.com/research/case-studies--commercial--voice-audio-ai-survey-2026-05-28/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--voice-audio-ai-survey-2026-05-28/</guid><description>&lt;!-- ksat-tag:auto-generated:start --&gt;
## DCWF KSAT coverage</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--voice-audio-ai-survey-2026-05-28.png&quot; alt=&quot;Voice/Audio AI Infrastructure Survey&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- ksat-tag:auto-generated:start --&amp;gt;
## DCWF KSAT coverage&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--voice-audio-ai-survey-2026-05-28/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--voice-audio-ai-survey-2026-05-28.png" length="0" type="image/png"/></item><item><title>Argo Workflows: K8s-Native Workflow Orchestration Survey</title><link>https://nuclide-research.com/research/case-studies--commercial--argo-workflows-survey-2026-05-27/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--argo-workflows-survey-2026-05-27/</guid><description>Shodan survey of the global Argo Workflows population via TLS certificate fingerprint. 67 confirmed instances (initial survey, ssl:&quot;ArgoProj&quot; dork) plus 17 Argo-confirmed instances from a second non-overlapping population of 200 IPs (ssl:&quot;Argo Workflows&quot; dork). All tested instances across both populations: auth-enforced. Combined passive-discoverable populat…</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--argo-workflows-survey-2026-05-27.png&quot; alt=&quot;Argo Workflows: K8s-Native Workflow Orchestration Survey&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Shodan survey of the global Argo Workflows population via TLS certificate fingerprint. 67 confirmed instances (initial survey, ssl:&amp;quot;ArgoProj&amp;quot; dork) plus 17 Argo-confirmed instances from a second non-overlapping population of 200 IPs (ssl:&amp;quot;Argo Workflows&amp;quot; dork). All tested instances across both populations: auth-enforced. Combined passive-discoverable populat…&lt;/p&gt;
&lt;p&gt;Shodan survey of the global Argo Workflows population via TLS certificate fingerprint. 67 confirmed instances (initial survey, ssl:&amp;quot;ArgoProj&amp;quot; dork) plus 17 Argo-confirmed instances from a second non-overlapping population of 200 IPs (ssl:&amp;quot;Argo Workflows&amp;quot; dork). All tested instances across both populations: auth-enforced. Combined passive-discoverable population: 267 hosts. Notable operators include Home Depot, Apex Clearing, ForgeRock/Ping Identity, Salling Group, GREE Inc, Waabi AI, freed.ai, CAFIS (NTT Data). Zero unauthenticated instances across the entire combined population.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--argo-workflows-survey-2026-05-27/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--argo-workflows-survey-2026-05-27.png" length="0" type="image/png"/></item><item><title>ML Governance / Data Catalog Survey — OpenMetadata + DataHub</title><link>https://nuclide-research.com/research/case-studies--commercial--ml-governance-data-catalog-survey-2026-05-27/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--ml-governance-data-catalog-survey-2026-05-27/</guid><description>56 confirmed governance platforms, 56 auth-enforced. Zero auth-off. All OpenMetadata instances run v1.3.1+, past the CVE-2024-28255 patch boundary. Version disclosure MEDIUM on 31 OpenMetadata hosts.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--ml-governance-data-catalog-survey-2026-05-27.png&quot; alt=&quot;ML Governance / Data Catalog Survey — OpenMetadata + DataHub&quot; /&gt;&lt;/p&gt;
&lt;p&gt;56 confirmed governance platforms, 56 auth-enforced. Zero auth-off. All OpenMetadata instances run v1.3.1+, past the CVE-2024-28255 patch boundary. Version disclosure MEDIUM on 31 OpenMetadata hosts.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--ml-governance-data-catalog-survey-2026-05-27/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--ml-governance-data-catalog-survey-2026-05-27.png" length="0" type="image/png"/></item><item><title>OpenHands Autonomous Agent: 52 Unauth Deployments, WhatsApp Bot Builder Pattern</title><link>https://nuclide-research.com/research/case-studies--commercial--openhands-code-assistant-survey-cat09-2026-05-26/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--openhands-code-assistant-survey-cat09-2026-05-26/</guid><description>191 OpenHands instances in Shodan. We scanned 56. 52 returned /api/v1/settings without authentication. On 26 of those 52 hosts, Evolution API (WhatsApp automation gateway) runs on port 3000 alongside OpenHands on port 3001. The same deployment template, the same no-auth posture, repeated across 26 cloud servers.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--openhands-code-assistant-survey-cat09-2026-05-26.png&quot; alt=&quot;OpenHands Autonomous Agent: 52 Unauth Deployments, WhatsApp Bot Builder Pattern&quot; /&gt;&lt;/p&gt;
&lt;p&gt;191 OpenHands instances in Shodan. We scanned 56. 52 returned /api/v1/settings without authentication. On 26 of those 52 hosts, Evolution API (WhatsApp automation gateway) runs on port 3000 alongside OpenHands on port 3001. The same deployment template, the same no-auth posture, repeated across 26 cloud servers.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--openhands-code-assistant-survey-cat09-2026-05-26/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--openhands-code-assistant-survey-cat09-2026-05-26.png" length="0" type="image/png"/></item><item><title>LangGraph&apos;s Deployment Gap: Exposed AI Agent Infrastructure at Scale</title><link>https://nuclide-research.com/research/case-studies--commercial--langgraph-deployment-gap-survey-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--langgraph-deployment-gap-survey-2026-05-25/</guid><description>LangGraph&apos;s self-hosted deployment path ships with no authentication. We found sixteen internet-facing deployments. All sixteen were open. A financial AI system processing credit reports in Shanghai. A two-node PII scraper running in Paris with no auth by design.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--langgraph-deployment-gap-survey-2026-05-25.png&quot; alt=&quot;LangGraph&amp;#39;s Deployment Gap: Exposed AI Agent Infrastructure at Scale&quot; /&gt;&lt;/p&gt;
&lt;p&gt;LangGraph&amp;#39;s self-hosted deployment path ships with no authentication. We found sixteen internet-facing deployments. All sixteen were open. A financial AI system processing credit reports in Shanghai. A two-node PII scraper running in Paris with no auth by design.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--langgraph-deployment-gap-survey-2026-05-25/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--langgraph-deployment-gap-survey-2026-05-25.png" length="0" type="image/png"/></item><item><title>LangGraph Server Population Survey (2026-05-25)</title><link>https://nuclide-research.com/research/case-studies--commercial--langgraph-server-survey-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--langgraph-server-survey-2026-05-25/</guid><description>Population-scale survey of LangGraph Server deployments. LangGraph is LangChain&apos;s stateful multi-agent execution runtime. The canonical server ships on FastAPI/uvicorn (port 8000) with no authentication by default. Community wrappers (Node.js, custom Python) follow the same pattern.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--langgraph-server-survey-2026-05-25.png&quot; alt=&quot;LangGraph Server Population Survey (2026-05-25)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population-scale survey of LangGraph Server deployments. LangGraph is LangChain&amp;#39;s stateful multi-agent execution runtime. The canonical server ships on FastAPI/uvicorn (port 8000) with no authentication by default. Community wrappers (Node.js, custom Python) follow the same pattern.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--langgraph-server-survey-2026-05-25/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--langgraph-server-survey-2026-05-25.png" length="0" type="image/png"/></item><item><title>Redis Stack / RedisInsight Population Survey (2026-05-25)</title><link>https://nuclide-research.com/research/case-studies--commercial--redis-stack-redisinsight-population-survey-2026-05-25/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--redis-stack-redisinsight-population-survey-2026-05-25/</guid><description>Population-scale survey of Redis Stack (Redis with RediSearch vector search module) and RedisInsight (browser-based Redis management GUI) deployments.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--redis-stack-redisinsight-population-survey-2026-05-25.png&quot; alt=&quot;Redis Stack / RedisInsight Population Survey (2026-05-25)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population-scale survey of Redis Stack (Redis with RediSearch vector search module) and RedisInsight (browser-based Redis management GUI) deployments.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--redis-stack-redisinsight-population-survey-2026-05-25/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--redis-stack-redisinsight-population-survey-2026-05-25.png" length="0" type="image/png"/></item><item><title>Agenta LLMOps — Population Survey</title><link>https://nuclide-research.com/research/case-studies--commercial--agenta-llmops-observability-survey-2026-05-22/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--agenta-llmops-observability-survey-2026-05-22/</guid><description>&lt;!-- ksat-tag:auto-generated:start --&gt;
## DCWF KSAT coverage</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--agenta-llmops-observability-survey-2026-05-22.png&quot; alt=&quot;Agenta LLMOps — Population Survey&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- ksat-tag:auto-generated:start --&amp;gt;
## DCWF KSAT coverage&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--agenta-llmops-observability-survey-2026-05-22/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--agenta-llmops-observability-survey-2026-05-22.png" length="0" type="image/png"/></item><item><title>University AI Infrastructure Exposure: Global Overview</title><link>https://nuclide-research.com/research/case-studies--universities--overview/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--universities--overview/</guid><description>Full sweep of all 10,224 recognized universities worldwide (Hipo dataset, 202 countries). Two lanes ran:</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--universities--overview.png&quot; alt=&quot;University AI Infrastructure Exposure: Global Overview&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Full sweep of all 10,224 recognized universities worldwide (Hipo dataset, 202 countries). Two lanes ran:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--universities--overview/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--universities--overview.png" length="0" type="image/png"/></item><item><title>AI Cost / Billing / Usage Analytics population survey: Langfuse secret-key exposures + Dokploy frontend-secret leak class</title><link>https://nuclide-research.com/research/case-studies--commercial--cost-billing-analytics-survey-2026-05-19/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--cost-billing-analytics-survey-2026-05-19/</guid><description>The AI cost / billing / usage analytics tier sits at the intersection of LLM operations and finance: it tracks per-tenant token usage, attaches dollar amounts to model calls, and surfaces usage to operators and customers. The auth posture matters because the data is financial-grade (CFO + auditor attention) and the API keys exposed in this tier are upstream…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--cost-billing-analytics-survey-2026-05-19.png&quot; alt=&quot;AI Cost / Billing / Usage Analytics population survey: Langfuse secret-key exposures + Dokploy frontend-secret leak class&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The AI cost / billing / usage analytics tier sits at the intersection of LLM operations and finance: it tracks per-tenant token usage, attaches dollar amounts to model calls, and surfaces usage to operators and customers. The auth posture matters because the data is financial-grade (CFO + auditor attention) and the API keys exposed in this tier are upstream…&lt;/p&gt;
&lt;p&gt;The AI cost / billing / usage analytics tier sits at the intersection of LLM operations and finance: it tracks per-tenant token usage, attaches dollar amounts to model calls, and surfaces usage to operators and customers. The auth posture matters because the data is financial-grade (CFO + auditor attention) and the API keys exposed in this tier are upstream LLM provider keys with real billing power.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--cost-billing-analytics-survey-2026-05-19/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--cost-billing-analytics-survey-2026-05-19.png" length="0" type="image/png"/></item><item><title>Service mesh + workflow-orchestration population surveys: Envoy admin config-dump + Prefect admin/settings + ML pipeline-engine exposures</title><link>https://nuclide-research.com/research/case-studies--commercial--mesh-and-orchestration-surveys-2026-05-19/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--mesh-and-orchestration-surveys-2026-05-19/</guid><description>Two surveys ran in parallel against unsurveyed FUTURE-SURVEYS roadmap categories:</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--mesh-and-orchestration-surveys-2026-05-19.png&quot; alt=&quot;Service mesh + workflow-orchestration population surveys: Envoy admin config-dump + Prefect admin/settings + ML pipeline-engine exposures&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Two surveys ran in parallel against unsurveyed FUTURE-SURVEYS roadmap categories:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--mesh-and-orchestration-surveys-2026-05-19/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--mesh-and-orchestration-surveys-2026-05-19.png" length="0" type="image/png"/></item><item><title>LLM Safety / Guardrail / Policy Engine population survey</title><link>https://nuclide-research.com/research/case-studies--commercial--safety-guardrail-population-survey-2026-05-19/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--safety-guardrail-population-survey-2026-05-19/</guid><description>The auth-on-default thesis predicts that products which ship without authentication will appear at population scale with the unauth posture intact. The LLM safety / guardrail / policy layer is the inversion test: does the layer that filters LLM input/output run itself unauthenticated? The first-pass verified-real result is yes, for a small but substantive su…</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--safety-guardrail-population-survey-2026-05-19.png&quot; alt=&quot;LLM Safety / Guardrail / Policy Engine population survey&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The auth-on-default thesis predicts that products which ship without authentication will appear at population scale with the unauth posture intact. The LLM safety / guardrail / policy layer is the inversion test: does the layer that filters LLM input/output run itself unauthenticated? The first-pass verified-real result is yes, for a small but substantive su…&lt;/p&gt;
&lt;p&gt;The auth-on-default thesis predicts that products which ship without authentication will appear at population scale with the unauth posture intact. The LLM safety / guardrail / policy layer is the inversion test: does the layer that filters LLM input/output run itself unauthenticated? The first-pass verified-real result is yes, for a small but substantive subset.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--safety-guardrail-population-survey-2026-05-19/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--safety-guardrail-population-survey-2026-05-19.png" length="0" type="image/png"/></item><item><title>Code assistants — category 09 population follow-up survey 2026-05-18</title><link>https://nuclide-research.com/research/case-studies--commercial--code-assistants-population-survey-2026-05-18/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--code-assistants-population-survey-2026-05-18/</guid><description>This is the second pass on the AI code-assistant tier. The first pass on
2026-05-14 ran the full chain on 233 hosts and found 54 unauth across 8
platforms. Four days later we re-harvested and ran the chain again. Late in
the session, a Stage-2 verification pass at the data-layer corrected the
headline numbers down by 66 percent and produced two new insights.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--code-assistants-population-survey-2026-05-18.png&quot; alt=&quot;Code assistants — category 09 population follow-up survey 2026-05-18&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This is the second pass on the AI code-assistant tier. The first pass on
2026-05-14 ran the full chain on 233 hosts and found 54 unauth across 8
platforms. Four days later we re-harvested and ran the chain again. Late in
the session, a Stage-2 verification pass at the data-layer corrected the
headline numbers down by 66 percent and produced two new insights.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--code-assistants-population-survey-2026-05-18/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--code-assistants-population-survey-2026-05-18.png" length="0" type="image/png"/></item><item><title>Jetson, TensorRT, and edge-AI: a population survey of NVR and inference exposure</title><link>https://nuclide-research.com/research/case-studies--commercial--jetson-tensorrt-edge-survey-2026-05-18/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--jetson-tensorrt-edge-survey-2026-05-18/</guid><description>The survey scoped as &quot;Jetson / TensorRT edge&quot; found that the dominant exposed
population on the public internet is not the Jetson hardware itself. It is the
edge-AI applications that ship with Jetson and run on similar hardware
elsewhere. The four largest classes are Frigate (205 unauthenticated of 447
reachable), CodeProject.AI (39 of 40), DeepStack (24 of…</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--jetson-tensorrt-edge-survey-2026-05-18.png&quot; alt=&quot;Jetson, TensorRT, and edge-AI: a population survey of NVR and inference exposure&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The survey scoped as &amp;quot;Jetson / TensorRT edge&amp;quot; found that the dominant exposed
population on the public internet is not the Jetson hardware itself. It is the
edge-AI applications that ship with Jetson and run on similar hardware
elsewhere. The four largest classes are Frigate (205 unauthenticated of 447
reachable), CodeProject.AI (39 of 40), DeepStack (24 of…&lt;/p&gt;
&lt;p&gt;The survey scoped as &amp;quot;Jetson / TensorRT edge&amp;quot; found that the dominant exposed
population on the public internet is not the Jetson hardware itself. It is the
edge-AI applications that ship with Jetson and run on similar hardware
elsewhere. The four largest classes are Frigate (205 unauthenticated of 447
reachable), CodeProject.AI (39 of 40), DeepStack (24 of 25), and motionEye (18
of 64). Frigate alone produced 15 hosts where /api/config returns YAML
containing back-end RTSP camera URLs with plaintext credentials.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--jetson-tensorrt-edge-survey-2026-05-18/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--jetson-tensorrt-edge-survey-2026-05-18.png" length="0" type="image/png"/></item><item><title>22 unauthenticated AI-stack Elasticsearch operators (2026-05-17)</title><link>https://nuclide-research.com/research/case-studies--commercial--22-ai-stack-attribution-2026-05-17/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--22-ai-stack-attribution-2026-05-17/</guid><description>The morning&apos;s mapping probe surfaced 22 Elasticsearch hosts with densevector or knnvector fields. Those are unambiguous AI / RAG workloads. We ran cert-pivot, Shodan, and aimap-profile on each one.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--22-ai-stack-attribution-2026-05-17.png&quot; alt=&quot;22 unauthenticated AI-stack Elasticsearch operators (2026-05-17)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The morning&amp;#39;s mapping probe surfaced 22 Elasticsearch hosts with densevector or knnvector fields. Those are unambiguous AI / RAG workloads. We ran cert-pivot, Shodan, and aimap-profile on each one.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--22-ai-stack-attribution-2026-05-17/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--22-ai-stack-attribution-2026-05-17.png" length="0" type="image/png"/></item><item><title>AI agent framework population survey, 2026-05-17</title><link>https://nuclide-research.com/research/case-studies--commercial--ai-agents-survey-2026-05-17/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--ai-agents-survey-2026-05-17/</guid><description>We surveyed the public-facing agent-framework population: AutoGen Studio, CrewAI, LangGraph Studio, Langflow, AgentOps. The corpus harvested from Shodan dorks totaled 351 unique IPs. After running aimap with existing fingerprints and applying Insight #30 multi-port consistency checking, the result is striking: the population is dominated by honeypot baits.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--ai-agents-survey-2026-05-17.png&quot; alt=&quot;AI agent framework population survey, 2026-05-17&quot; /&gt;&lt;/p&gt;
&lt;p&gt;We surveyed the public-facing agent-framework population: AutoGen Studio, CrewAI, LangGraph Studio, Langflow, AgentOps. The corpus harvested from Shodan dorks totaled 351 unique IPs. After running aimap with existing fingerprints and applying Insight #30 multi-port consistency checking, the result is striking: the population is dominated by honeypot baits.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--ai-agents-survey-2026-05-17/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--ai-agents-survey-2026-05-17.png" length="0" type="image/png"/></item><item><title>Cross-stack 24-hour follow-up on Elasticsearch and ClickHouse (2026-05-17)</title><link>https://nuclide-research.com/research/case-studies--commercial--es-clickhouse-cross-stack-2026-05-17/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--es-clickhouse-cross-stack-2026-05-17/</guid><description>Yesterday&apos;s surveys produced raw counts of 5,037 unauthenticated Elasticsearch hosts and 1,832 unauthenticated ClickHouse hosts. The verification ran through bespoke Python scripts. This survey ships aimap v1.9.8 (enumElasticsearch and enumClickHouse) and re-runs both host lists.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--es-clickhouse-cross-stack-2026-05-17.png&quot; alt=&quot;Cross-stack 24-hour follow-up on Elasticsearch and ClickHouse (2026-05-17)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Yesterday&amp;#39;s surveys produced raw counts of 5,037 unauthenticated Elasticsearch hosts and 1,832 unauthenticated ClickHouse hosts. The verification ran through bespoke Python scripts. This survey ships aimap v1.9.8 (enumElasticsearch and enumClickHouse) and re-runs both host lists.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--es-clickhouse-cross-stack-2026-05-17/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--es-clickhouse-cross-stack-2026-05-17.png" length="0" type="image/png"/></item><item><title>LLM gateway / proxy population survey, 2026-05-17</title><link>https://nuclide-research.com/research/case-studies--commercial--llm-gateway-survey-2026-05-17/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--llm-gateway-survey-2026-05-17/</guid><description>We surveyed the public-facing LLM gateway / API-proxy population: LiteLLM, Helicone, Portkey, OneAPI, NewAPI, OpenRouter self-host. A LLM gateway sits between an application and one or more upstream LLM providers. It brokers requests, holds the operator&apos;s OpenAI / Anthropic / DeepSeek API keys, logs every prompt and response, and meters usage.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--llm-gateway-survey-2026-05-17.png&quot; alt=&quot;LLM gateway / proxy population survey, 2026-05-17&quot; /&gt;&lt;/p&gt;
&lt;p&gt;We surveyed the public-facing LLM gateway / API-proxy population: LiteLLM, Helicone, Portkey, OneAPI, NewAPI, OpenRouter self-host. A LLM gateway sits between an application and one or more upstream LLM providers. It brokers requests, holds the operator&amp;#39;s OpenAI / Anthropic / DeepSeek API keys, logs every prompt and response, and meters usage.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--llm-gateway-survey-2026-05-17/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--llm-gateway-survey-2026-05-17.png" length="0" type="image/png"/></item><item><title>MCP server population survey, 2026-05-17</title><link>https://nuclide-research.com/research/case-studies--commercial--mcp-server-survey-2026-05-17/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--mcp-server-survey-2026-05-17/</guid><description>We surveyed the public Model Context Protocol (MCP) server population. MCP is Anthropic&apos;s wire format for letting LLMs call into external tools, prompts, and resources. It has become the standard control plane for agentic LLM deployments. We harvested candidates with protocol-strict Shodan dorks and cross-referenced against the 51 accidental MCP hits in yest…</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--mcp-server-survey-2026-05-17.png&quot; alt=&quot;MCP server population survey, 2026-05-17&quot; /&gt;&lt;/p&gt;
&lt;p&gt;We surveyed the public Model Context Protocol (MCP) server population. MCP is Anthropic&amp;#39;s wire format for letting LLMs call into external tools, prompts, and resources. It has become the standard control plane for agentic LLM deployments. We harvested candidates with protocol-strict Shodan dorks and cross-referenced against the 51 accidental MCP hits in yest…&lt;/p&gt;
&lt;p&gt;We surveyed the public Model Context Protocol (MCP) server population. MCP is Anthropic&amp;#39;s wire format for letting LLMs call into external tools, prompts, and resources. It has become the standard control plane for agentic LLM deployments. We harvested candidates with protocol-strict Shodan dorks and cross-referenced against the 51 accidental MCP hits in yesterday&amp;#39;s training-observability survey.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--mcp-server-survey-2026-05-17/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--mcp-server-survey-2026-05-17.png" length="0" type="image/png"/></item><item><title>Meow / Indexrm Elasticsearch extortion. Three actors. (2026-05-17)</title><link>https://nuclide-research.com/research/case-studies--commercial--meow-multi-actor-campaign-scope-2026-05-17/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--meow-multi-actor-campaign-scope-2026-05-17/</guid><description>We sampled 150 of the 3,604 fully-wiped Elasticsearch hosts from this morning&apos;s re-probe. We read the readme index on each one. Three different actors are running the campaign in parallel.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--meow-multi-actor-campaign-scope-2026-05-17.png&quot; alt=&quot;Meow / Indexrm Elasticsearch extortion. Three actors. (2026-05-17)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;We sampled 150 of the 3,604 fully-wiped Elasticsearch hosts from this morning&amp;#39;s re-probe. We read the readme index on each one. Three different actors are running the campaign in parallel.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--meow-multi-actor-campaign-scope-2026-05-17/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--meow-multi-actor-campaign-scope-2026-05-17.png" length="0" type="image/png"/></item><item><title>Meow / Indexrm campaign: per-actor census across 4,776 ES hosts</title><link>https://nuclide-research.com/research/case-studies--commercial--meow-population-census-2026-05-17/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--meow-population-census-2026-05-17/</guid><description>We re-ran the full 4,776-host Elasticsearch population through aimap v1.9.10. The new release reads one document from the attacker-planted marker index and parses it for actor identifiers. The morning&apos;s 150-host probe found three actors; the population-scale pass confirms three primary actors plus a long tail.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--meow-population-census-2026-05-17.png&quot; alt=&quot;Meow / Indexrm campaign: per-actor census across 4,776 ES hosts&quot; /&gt;&lt;/p&gt;
&lt;p&gt;We re-ran the full 4,776-host Elasticsearch population through aimap v1.9.10. The new release reads one document from the attacker-planted marker index and parses it for actor identifiers. The morning&amp;#39;s 150-host probe found three actors; the population-scale pass confirms three primary actors plus a long tail.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--meow-population-census-2026-05-17/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--meow-population-census-2026-05-17.png" length="0" type="image/png"/></item><item><title>Training observability survey, 2026-05-17</title><link>https://nuclide-research.com/research/case-studies--commercial--training-observability-survey-2026-05-17/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--training-observability-survey-2026-05-17/</guid><description>We surveyed self-hosted training-observability platforms: Weights &amp; Biases (self-hosted), ClearML, Aim, Ray Dashboard, MLflow. The aim was to map the population of public-facing experiment trackers and characterize the auth posture per platform class.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--training-observability-survey-2026-05-17.png&quot; alt=&quot;Training observability survey, 2026-05-17&quot; /&gt;&lt;/p&gt;
&lt;p&gt;We surveyed self-hosted training-observability platforms: Weights &amp;amp; Biases (self-hosted), ClearML, Aim, Ray Dashboard, MLflow. The aim was to map the population of public-facing experiment trackers and characterize the auth posture per platform class.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--training-observability-survey-2026-05-17/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--training-observability-survey-2026-05-17.png" length="0" type="image/png"/></item><item><title>Vector database population survey, 2026-05-17</title><link>https://nuclide-research.com/research/case-studies--commercial--vectordb-survey-2026-05-17/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--vectordb-survey-2026-05-17/</guid><description>We surveyed the public vector-database population: Qdrant, Weaviate, Milvus, ChromaDB. Vector DBs hold the embeddings for an operator&apos;s RAG pipeline. Every document, customer transcript, support ticket, legal record, or PII row the operator has chunked and indexed for retrieval. The Meow / Indexrm extortion campaign hits Elasticsearch only, so unlike yesterd…</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--vectordb-survey-2026-05-17.png&quot; alt=&quot;Vector database population survey, 2026-05-17&quot; /&gt;&lt;/p&gt;
&lt;p&gt;We surveyed the public vector-database population: Qdrant, Weaviate, Milvus, ChromaDB. Vector DBs hold the embeddings for an operator&amp;#39;s RAG pipeline. Every document, customer transcript, support ticket, legal record, or PII row the operator has chunked and indexed for retrieval. The Meow / Indexrm extortion campaign hits Elasticsearch only, so unlike yesterd…&lt;/p&gt;
&lt;p&gt;We surveyed the public vector-database population: Qdrant, Weaviate, Milvus, ChromaDB. Vector DBs hold the embeddings for an operator&amp;#39;s RAG pipeline. Every document, customer transcript, support ticket, legal record, or PII row the operator has chunked and indexed for retrieval. The Meow / Indexrm extortion campaign hits Elasticsearch only, so unlike yesterday&amp;#39;s ES population the vector-DB population is not wipe-contaminated. Operator data is alive.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--vectordb-survey-2026-05-17/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--vectordb-survey-2026-05-17.png" length="0" type="image/png"/></item><item><title>Agent-Framework Stragglers Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--agent-framework-stragglers-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--agent-framework-stragglers-population-survey-2026-05-16/</guid><description>Population survey of the agent-framework stragglers. Platforms that emerged in 2024-2025 alongside the AutoGen / Open WebUI / Flowise generation. Closes the gap left by the AutoGen Studio survey (2026-05-14) which only covered one platform in category 06.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--agent-framework-stragglers-population-survey-2026-05-16.png&quot; alt=&quot;Agent-Framework Stragglers Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population survey of the agent-framework stragglers. Platforms that emerged in 2024-2025 alongside the AutoGen / Open WebUI / Flowise generation. Closes the gap left by the AutoGen Studio survey (2026-05-14) which only covered one platform in category 06.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--agent-framework-stragglers-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--agent-framework-stragglers-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>Agent-Memory Population Survey: Falsification-Confirmation Result (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--agent-memory-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--agent-memory-population-survey-2026-05-16/</guid><description>Population-scale survey of agent-memory backends. The platform class that stores LLM conversation history, user profiles, and per-session context. A null-result-as-finding survey in the METHODOLOGY sense: the agent-memory tier is Tier-C (auth-on-default) at population scale.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--agent-memory-population-survey-2026-05-16.png&quot; alt=&quot;Agent-Memory Population Survey: Falsification-Confirmation Result (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population-scale survey of agent-memory backends. The platform class that stores LLM conversation history, user profiles, and per-session context. A null-result-as-finding survey in the METHODOLOGY sense: the agent-memory tier is Tier-C (auth-on-default) at population scale.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--agent-memory-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--agent-memory-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>Argo CD Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--argocd-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--argocd-population-survey-2026-05-16/</guid><description>Population-scale survey of Argo CD. The Kubernetes continuous-deployment pipeline. Argo CD operators configure git-source repositories, deploy targets (k8s clusters), and credentials; the platform watches git and reconciles cluster state. Unauth access to an Argo CD instance = arbitrary code deployment to the operator&apos;s k8s clusters.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--argocd-population-survey-2026-05-16.png&quot; alt=&quot;Argo CD Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population-scale survey of Argo CD. The Kubernetes continuous-deployment pipeline. Argo CD operators configure git-source repositories, deploy targets (k8s clusters), and credentials; the platform watches git and reconciles cluster state. Unauth access to an Argo CD instance = arbitrary code deployment to the operator&amp;#39;s k8s clusters.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--argocd-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--argocd-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>ClickHouse Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--clickhouse-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--clickhouse-population-survey-2026-05-16/</guid><description>Largest single-platform population survey of the day. ClickHouse is the OLAP database that powers most modern observability stacks (SigNoz, Plausible, PostHog, Helicone, Phoenix-on-OTLP). Wherever an AI/LLM service emits traces or analytics, there&apos;s often a ClickHouse behind it.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--clickhouse-population-survey-2026-05-16.png&quot; alt=&quot;ClickHouse Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Largest single-platform population survey of the day. ClickHouse is the OLAP database that powers most modern observability stacks (SigNoz, Plausible, PostHog, Helicone, Phoenix-on-OTLP). Wherever an AI/LLM service emits traces or analytics, there&amp;#39;s often a ClickHouse behind it.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--clickhouse-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--clickhouse-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>Consul (HashiCorp) Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--consul-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--consul-population-survey-2026-05-16/</guid><description>Population-scale survey of HashiCorp Consul deployments. Service registry + KV store + service-mesh control plane. Consul&apos;s default ACL policy is allow, so out-of-the-box deployments expose the agent, catalog, and KV state to anyone on the network. This survey is the third in the HashiCorp infrastructure trinity (etcd survey + Vault survey on 2026-05-15, Con…</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--consul-population-survey-2026-05-16.png&quot; alt=&quot;Consul (HashiCorp) Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population-scale survey of HashiCorp Consul deployments. Service registry + KV store + service-mesh control plane. Consul&amp;#39;s default ACL policy is allow, so out-of-the-box deployments expose the agent, catalog, and KV state to anyone on the network. This survey is the third in the HashiCorp infrastructure trinity (etcd survey + Vault survey on 2026-05-15, Con…&lt;/p&gt;
&lt;p&gt;Population-scale survey of HashiCorp Consul deployments. Service registry + KV store + service-mesh control plane. Consul&amp;#39;s default ACL policy is allow, so out-of-the-box deployments expose the agent, catalog, and KV state to anyone on the network. This survey is the third in the HashiCorp infrastructure trinity (etcd survey + Vault survey on 2026-05-15, Consul completes today).&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--consul-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--consul-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>Data-Labeling Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--data-labeling-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--data-labeling-population-survey-2026-05-16/</guid><description>Survey of the data-labeling platform population. The systems that store training-data annotation tasks, often containing PII or sensitive labels. Smaller surface than other categories surveyed today; the mixed result is informative.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--data-labeling-population-survey-2026-05-16.png&quot; alt=&quot;Data-Labeling Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Survey of the data-labeling platform population. The systems that store training-data annotation tasks, often containing PII or sensitive labels. Smaller surface than other categories surveyed today; the mixed result is informative.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--data-labeling-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--data-labeling-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>Elasticsearch AI-Stack Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--elasticsearch-ai-stack-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--elasticsearch-ai-stack-population-survey-2026-05-16/</guid><description>Population survey of Elasticsearch clusters with focus on AI-stack adjacency. RAG vector stores, langchain/llama-index indices, embedding caches, prompt history. Elasticsearch has been a major exposure surface for 8 years (the original &quot;exposed Elasticsearch&quot; panic was 2015); the novel angle here is the AI-stack-specific index-naming as an operator-attributi…</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--elasticsearch-ai-stack-population-survey-2026-05-16.png&quot; alt=&quot;Elasticsearch AI-Stack Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population survey of Elasticsearch clusters with focus on AI-stack adjacency. RAG vector stores, langchain/llama-index indices, embedding caches, prompt history. Elasticsearch has been a major exposure surface for 8 years (the original &amp;quot;exposed Elasticsearch&amp;quot; panic was 2015); the novel angle here is the AI-stack-specific index-naming as an operator-attributi…&lt;/p&gt;
&lt;p&gt;Population survey of Elasticsearch clusters with focus on AI-stack adjacency. RAG vector stores, langchain/llama-index indices, embedding caches, prompt history. Elasticsearch has been a major exposure surface for 8 years (the original &amp;quot;exposed Elasticsearch&amp;quot; panic was 2015); the novel angle here is the AI-stack-specific index-naming as an operator-attribution channel.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--elasticsearch-ai-stack-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--elasticsearch-ai-stack-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>Experiment-Tracking Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--experiment-tracking-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--experiment-tracking-population-survey-2026-05-16/</guid><description>Closes the experiment-tracking half of category 04 (the compute-orchestration half was surveyed 2026-05-06 with Spark / Airflow / Ray). MLflow was surveyed earlier in the series (Insight #18 buckets-locked finding). This survey covers the MLflow siblings: Weights &amp; Biases self-hosted, ClearML, Aim Stack, Comet ML.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--experiment-tracking-population-survey-2026-05-16.png&quot; alt=&quot;Experiment-Tracking Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Closes the experiment-tracking half of category 04 (the compute-orchestration half was surveyed 2026-05-06 with Spark / Airflow / Ray). MLflow was surveyed earlier in the series (Insight #18 buckets-locked finding). This survey covers the MLflow siblings: Weights &amp;amp; Biases self-hosted, ClearML, Aim Stack, Comet ML.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--experiment-tracking-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--experiment-tracking-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>GPU-Compute Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--gpu-compute-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--gpu-compute-population-survey-2026-05-16/</guid><description>Survey of the GPU-compute orchestration tier: Run:ai (Nvidia&apos;s enterprise GPU scheduler), DCGM-exporter (Prometheus exporter for NVIDIA GPU metrics), NVIDIA Bright Cluster Manager, Slurm REST API. Smaller surface than image-gen / vector-DB but operator-rich. These are dashboards and exporters that disclose the operator&apos;s full GPU topology.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--gpu-compute-population-survey-2026-05-16.png&quot; alt=&quot;GPU-Compute Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Survey of the GPU-compute orchestration tier: Run:ai (Nvidia&amp;#39;s enterprise GPU scheduler), DCGM-exporter (Prometheus exporter for NVIDIA GPU metrics), NVIDIA Bright Cluster Manager, Slurm REST API. Smaller surface than image-gen / vector-DB but operator-rich. These are dashboards and exporters that disclose the operator&amp;#39;s full GPU topology.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--gpu-compute-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--gpu-compute-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>Image-Generation Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--image-generation-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--image-generation-population-survey-2026-05-16/</guid><description>First population-scale survey of the image-generation modality. ComfyUI, AUTOMATIC1111 / SD WebUI, InvokeAI, Fooocus, SwarmUI, SD.Next, Forge. The category had no aimap fingerprints prior to this survey; the manual→productize→re-run loop applied. Fingerprint built mid-survey, shipped as aimap v1.9.6, then re-run across the corpus.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--image-generation-population-survey-2026-05-16.png&quot; alt=&quot;Image-Generation Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;First population-scale survey of the image-generation modality. ComfyUI, AUTOMATIC1111 / SD WebUI, InvokeAI, Fooocus, SwarmUI, SD.Next, Forge. The category had no aimap fingerprints prior to this survey; the manual→productize→re-run loop applied. Fingerprint built mid-survey, shipped as aimap v1.9.6, then re-run across the corpus.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--image-generation-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--image-generation-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>ROS Robotics Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--ros-robotics-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--ros-robotics-population-survey-2026-05-16/</guid><description>Population survey of ROS (Robot Operating System) deployments. The canonical robotics middleware stack. ROS master :11311 speaks XMLRPC, rosbridge :9090 speaks WebSocket+HTTP. Both leak topic/node names when reachable unauth, and ROS is physical-impact tier, topics like /cmdvel, /jointstates, /movebase map to physical actuators on robots.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--ros-robotics-population-survey-2026-05-16.png&quot; alt=&quot;ROS Robotics Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population survey of ROS (Robot Operating System) deployments. The canonical robotics middleware stack. ROS master :11311 speaks XMLRPC, rosbridge :9090 speaks WebSocket+HTTP. Both leak topic/node names when reachable unauth, and ROS is physical-impact tier, topics like /cmdvel, /jointstates, /movebase map to physical actuators on robots.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--ros-robotics-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--ros-robotics-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>Vector-DB Stragglers Population Survey (2026-05-16)</title><link>https://nuclide-research.com/research/case-studies--commercial--vectordb-stragglers-population-survey-2026-05-16/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--vectordb-stragglers-population-survey-2026-05-16/</guid><description>Closes the four platform-class stragglers left after the 2026-05 Qdrant / ChromaDB / Milvus / Weaviate sweep: Apache Solr, Meilisearch, Typesense, Vespa, plus pgvector body-marker recheck. Each candidate corpus was harvested individually and probed via fastenumvectordb.py.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--vectordb-stragglers-population-survey-2026-05-16.png&quot; alt=&quot;Vector-DB Stragglers Population Survey (2026-05-16)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Closes the four platform-class stragglers left after the 2026-05 Qdrant / ChromaDB / Milvus / Weaviate sweep: Apache Solr, Meilisearch, Typesense, Vespa, plus pgvector body-marker recheck. Each candidate corpus was harvested individually and probed via fastenumvectordb.py.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--vectordb-stragglers-population-survey-2026-05-16/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--vectordb-stragglers-population-survey-2026-05-16.png" length="0" type="image/png"/></item><item><title>Unauth Docker Daemon Population Survey (2026-05-15)</title><link>https://nuclide-research.com/research/case-studies--commercial--docker-daemon-population-survey-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--docker-daemon-population-survey-2026-05-15/</guid><description>Survey of the Shodan-indexed Docker daemon population on port 2375. The canonical unauth port for the Docker HTTP API. Port 2376 is the TLS-auth variant; port 2375 is unauth by framework spec, and operators who expose it on the public internet are running with root-equivalent RCE-on-the-host as a default.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--docker-daemon-population-survey-2026-05-15.png&quot; alt=&quot;Unauth Docker Daemon Population Survey (2026-05-15)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Survey of the Shodan-indexed Docker daemon population on port 2375. The canonical unauth port for the Docker HTTP API. Port 2376 is the TLS-auth variant; port 2375 is unauth by framework spec, and operators who expose it on the public internet are running with root-equivalent RCE-on-the-host as a default.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--docker-daemon-population-survey-2026-05-15/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--docker-daemon-population-survey-2026-05-15.png" length="0" type="image/png"/></item><item><title>etcd Population Survey (2026-05-15)</title><link>https://nuclide-research.com/research/case-studies--commercial--etcd-population-survey-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--etcd-population-survey-2026-05-15/</guid><description>Population-scale survey of etcd. The distributed key-value store that backs Kubernetes&apos; entire cluster state. Each unauthenticated etcd is a secrets-store leak class: anyone can list (and read) the cluster&apos;s stored data including Kubernetes secrets, service-discovery records, and operator-stored configuration.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--etcd-population-survey-2026-05-15.png&quot; alt=&quot;etcd Population Survey (2026-05-15)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population-scale survey of etcd. The distributed key-value store that backs Kubernetes&amp;#39; entire cluster state. Each unauthenticated etcd is a secrets-store leak class: anyone can list (and read) the cluster&amp;#39;s stored data including Kubernetes secrets, service-discovery records, and operator-stored configuration.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--etcd-population-survey-2026-05-15/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--etcd-population-survey-2026-05-15.png" length="0" type="image/png"/></item><item><title>llama.cpp HTTP Server Population Survey (2026-05-15)</title><link>https://nuclide-research.com/research/case-studies--commercial--llamacpp-population-survey-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--llamacpp-population-survey-2026-05-15/</guid><description>Direct follow-on survey to the day&apos;s Ollama work and the aimap v1.9.4 release. aimap v1.9.4 added a llama.cpp server fingerprint after the 194.233.71.223 single-host case revealed that PHASE-2 fingerprinting was missing llama.cpp on port 11434 despite an explicit Server: llama.cpp HTTP header. This survey is the first population-scale exercise of that finger…</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--llamacpp-population-survey-2026-05-15.png&quot; alt=&quot;llama.cpp HTTP Server Population Survey (2026-05-15)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Direct follow-on survey to the day&amp;#39;s Ollama work and the aimap v1.9.4 release. aimap v1.9.4 added a llama.cpp server fingerprint after the 194.233.71.223 single-host case revealed that PHASE-2 fingerprinting was missing llama.cpp on port 11434 despite an explicit Server: llama.cpp HTTP header. This survey is the first population-scale exercise of that finger…&lt;/p&gt;
&lt;p&gt;Direct follow-on survey to the day&amp;#39;s Ollama work and the aimap v1.9.4 release. aimap v1.9.4 added a llama.cpp server fingerprint after the 194.233.71.223 single-host case revealed that PHASE-2 fingerprinting was missing llama.cpp on port 11434 despite an explicit Server: llama.cpp HTTP header. This survey is the first population-scale exercise of that fingerprint.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--llamacpp-population-survey-2026-05-15/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--llamacpp-population-survey-2026-05-15.png" length="0" type="image/png"/></item><item><title>Medical / Edge AI Survey: DICOM Protocol Exposure at Population Scale</title><link>https://nuclide-research.com/research/case-studies--commercial--medical-edge-ai-survey-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--medical-edge-ai-survey-2026-05-15/</guid><description>Surveyed the 1,017-CIDR tier-2 cloud range list (DigitalOcean / Hetzner / Vultr / OVH / Linode ≈ 3.55M IPs) for medical-imaging AI infrastructure: Orthanc DICOM servers, MONAI Label / MONAI Deploy, NVIDIA Clara, NVIDIA NIM, and dcm4che-class archives. Shodan was unavailable for this survey (API key rotated stale), so discovery used the port-first methodology…</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--medical-edge-ai-survey-2026-05-15.png&quot; alt=&quot;Medical / Edge AI Survey: DICOM Protocol Exposure at Population Scale&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Surveyed the 1,017-CIDR tier-2 cloud range list (DigitalOcean / Hetzner / Vultr / OVH / Linode ≈ 3.55M IPs) for medical-imaging AI infrastructure: Orthanc DICOM servers, MONAI Label / MONAI Deploy, NVIDIA Clara, NVIDIA NIM, and dcm4che-class archives. Shodan was unavailable for this survey (API key rotated stale), so discovery used the port-first methodology…&lt;/p&gt;
&lt;p&gt;Surveyed the 1,017-CIDR tier-2 cloud range list (DigitalOcean / Hetzner / Vultr / OVH / Linode ≈ 3.55M IPs) for medical-imaging AI infrastructure: Orthanc DICOM servers, MONAI Label / MONAI Deploy, NVIDIA Clara, NVIDIA NIM, and dcm4che-class archives. Shodan was unavailable for this survey (API key rotated stale), so discovery used the port-first methodology from Insight #21: masscan against the medical/edge port set (4242 / 8042 / 8043 / 11112 / 8000) followed by protocol-strict verification per Insight #1.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--medical-edge-ai-survey-2026-05-15/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--medical-edge-ai-survey-2026-05-15.png" length="0" type="image/png"/></item><item><title>Ollama Population Survey: Shodan-Walk (2026-05-15)</title><link>https://nuclide-research.com/research/case-studies--commercial--ollama-population-survey-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--ollama-population-survey-2026-05-15/</guid><description>Re-survey of the Ollama exposure surface, walked on Shodan rather than via masscan-on-cloud-prefixes. The prior two surveys (5.38M IPs across six tier-1+2 clouds) found 1,192 confirmed unauth Ollama. This re-survey walks the Shodan-indexed Ollama population directly:</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--ollama-population-survey-2026-05-15.png&quot; alt=&quot;Ollama Population Survey: Shodan-Walk (2026-05-15)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Re-survey of the Ollama exposure surface, walked on Shodan rather than via masscan-on-cloud-prefixes. The prior two surveys (5.38M IPs across six tier-1+2 clouds) found 1,192 confirmed unauth Ollama. This re-survey walks the Shodan-indexed Ollama population directly:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--ollama-population-survey-2026-05-15/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--ollama-population-survey-2026-05-15.png" length="0" type="image/png"/></item><item><title>RAG Framework Servers: Population-Scale Survey (2026-05-15)</title><link>https://nuclide-research.com/research/case-studies--commercial--rag-frameworks-population-survey-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--rag-frameworks-population-survey-2026-05-15/</guid><description>&lt;!-- ksat-tag:auto-generated:start --&gt;
## DCWF KSAT coverage</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--rag-frameworks-population-survey-2026-05-15.png&quot; alt=&quot;RAG Framework Servers: Population-Scale Survey (2026-05-15)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;!-- ksat-tag:auto-generated:start --&amp;gt;
## DCWF KSAT coverage&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--rag-frameworks-population-survey-2026-05-15/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--rag-frameworks-population-survey-2026-05-15.png" length="0" type="image/png"/></item><item><title>Vault (HashiCorp) Population Survey (2026-05-15)</title><link>https://nuclide-research.com/research/case-studies--commercial--vault-population-survey-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--vault-population-survey-2026-05-15/</guid><description>Population-scale survey of HashiCorp Vault deployments. Vault is the canonical secrets-management platform. The operator&apos;s database credentials, API keys, signing keys, and other application secrets live inside. Unauth exposure isn&apos;t itself an instant-compromise (Vault auth-gates the secret-read API), but it IS a major intel-disclosure surface and, in three…</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--vault-population-survey-2026-05-15.png&quot; alt=&quot;Vault (HashiCorp) Population Survey (2026-05-15)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population-scale survey of HashiCorp Vault deployments. Vault is the canonical secrets-management platform. The operator&amp;#39;s database credentials, API keys, signing keys, and other application secrets live inside. Unauth exposure isn&amp;#39;t itself an instant-compromise (Vault auth-gates the secret-read API), but it IS a major intel-disclosure surface and, in three…&lt;/p&gt;
&lt;p&gt;Population-scale survey of HashiCorp Vault deployments. Vault is the canonical secrets-management platform. The operator&amp;#39;s database credentials, API keys, signing keys, and other application secrets live inside. Unauth exposure isn&amp;#39;t itself an instant-compromise (Vault auth-gates the secret-read API), but it IS a major intel-disclosure surface and, in three rare cases, a full-takeover candidate.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--vault-population-survey-2026-05-15/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--vault-population-survey-2026-05-15.png" length="0" type="image/png"/></item><item><title>Voice-Agent Population Survey: LiveKit-dominant (2026-05-15)</title><link>https://nuclide-research.com/research/case-studies--commercial--voice-agents-population-survey-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--voice-agents-population-survey-2026-05-15/</guid><description>Survey of the voice-agent platform population: LiveKit (server + agents framework), Pipecat, Vocode, with Deepgram / Twilio as secondary integration signals.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--voice-agents-population-survey-2026-05-15.png&quot; alt=&quot;Voice-Agent Population Survey: LiveKit-dominant (2026-05-15)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Survey of the voice-agent platform population: LiveKit (server + agents framework), Pipecat, Vocode, with Deepgram / Twilio as secondary integration signals.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--voice-agents-population-survey-2026-05-15/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--voice-agents-population-survey-2026-05-15.png" length="0" type="image/png"/></item><item><title>Voice-Cloning Population Survey: Shodan-Reachable Slice (2026-05-15)</title><link>https://nuclide-research.com/research/case-studies--commercial--voice-cloning-population-survey-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--voice-cloning-population-survey-2026-05-15/</guid><description>Survey of the Shodan-reachable voice-cloning surface (RVC / GPT-SoVITS / Applio / OpenVoice / ChatTTS / F5-TTS) and adjacent voice-TTS platforms. The aimap fingerprints for these platforms were shipped 2026-05-08 (shodan/queries/17-voice-audio-ai.md); this is the population-survey leg that closes Survey 17 batch 2.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--voice-cloning-population-survey-2026-05-15.png&quot; alt=&quot;Voice-Cloning Population Survey: Shodan-Reachable Slice (2026-05-15)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Survey of the Shodan-reachable voice-cloning surface (RVC / GPT-SoVITS / Applio / OpenVoice / ChatTTS / F5-TTS) and adjacent voice-TTS platforms. The aimap fingerprints for these platforms were shipped 2026-05-08 (shodan/queries/17-voice-audio-ai.md); this is the population-survey leg that closes Survey 17 batch 2.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--voice-cloning-population-survey-2026-05-15/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--voice-cloning-population-survey-2026-05-15.png" length="0" type="image/png"/></item><item><title>Whisper ASR Population Survey (2026-05-15)</title><link>https://nuclide-research.com/research/case-studies--commercial--whisper-asr-population-survey-2026-05-15/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--whisper-asr-population-survey-2026-05-15/</guid><description>Population-scale survey of Whisper ASR (speech-to-text) deployments. The canonical OpenAI Whisper plus the popular forks (whisper.cpp, faster-whisper, WhisperX). aimap fingerprints shipped 2026-05-08; this survey closes the remaining open piece of Survey 17.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--whisper-asr-population-survey-2026-05-15.png&quot; alt=&quot;Whisper ASR Population Survey (2026-05-15)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Population-scale survey of Whisper ASR (speech-to-text) deployments. The canonical OpenAI Whisper plus the popular forks (whisper.cpp, faster-whisper, WhisperX). aimap fingerprints shipped 2026-05-08; this survey closes the remaining open piece of Survey 17.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--whisper-asr-population-survey-2026-05-15/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--whisper-asr-population-survey-2026-05-15.png" length="0" type="image/png"/></item><item><title>AutoGen Studio, agent-platform tier cloud survey 2026-05-14</title><link>https://nuclide-research.com/research/case-studies--commercial--autogen-studio-survey-2026-05-14/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--autogen-studio-survey-2026-05-14/</guid><description>NuClide Research</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--autogen-studio-survey-2026-05-14.png&quot; alt=&quot;AutoGen Studio, agent-platform tier cloud survey 2026-05-14&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--autogen-studio-survey-2026-05-14/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--autogen-studio-survey-2026-05-14.png" length="0" type="image/png"/></item><item><title>Browser-automation backend tier cloud survey 2026-05-14</title><link>https://nuclide-research.com/research/case-studies--commercial--browser-automation-backend-survey-2026-05-14/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--browser-automation-backend-survey-2026-05-14/</guid><description>NuClide Research</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--browser-automation-backend-survey-2026-05-14.png&quot; alt=&quot;Browser-automation backend tier cloud survey 2026-05-14&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--browser-automation-backend-survey-2026-05-14/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--browser-automation-backend-survey-2026-05-14.png" length="0" type="image/png"/></item><item><title>Chrome DevTools Protocol, browser-automation backend cloud survey 2026-05-14</title><link>https://nuclide-research.com/research/case-studies--commercial--cdp-browser-control-survey-2026-05-14/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--cdp-browser-control-survey-2026-05-14/</guid><description>NuClide Research</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--cdp-browser-control-survey-2026-05-14.png&quot; alt=&quot;Chrome DevTools Protocol, browser-automation backend cloud survey 2026-05-14&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--cdp-browser-control-survey-2026-05-14/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--cdp-browser-control-survey-2026-05-14.png" length="0" type="image/png"/></item><item><title>VisorBishop Phase 5b: Bucket-accessibility pass against 49 MLflow artifact stores</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase5b-bucket-accessibility-2026-05-13/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase5b-bucket-accessibility-2026-05-13/</guid><description>NuClide Research · 2026-05-13</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-phase5b-bucket-accessibility-2026-05-13.png&quot; alt=&quot;VisorBishop Phase 5b: Bucket-accessibility pass against 49 MLflow artifact stores&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-13&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase5b-bucket-accessibility-2026-05-13/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-phase5b-bucket-accessibility-2026-05-13.png" length="0" type="image/png"/></item><item><title>VisorBishop Phase 5b: bucket-accessibility pass against 49 MLflow artifact stores (public)</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase5b-public-survey-2026-05-13/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase5b-public-survey-2026-05-13/</guid><description>NuClide Research · 2026-05-13</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-phase5b-public-survey-2026-05-13.png&quot; alt=&quot;VisorBishop Phase 5b: bucket-accessibility pass against 49 MLflow artifact stores (public)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-13&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase5b-public-survey-2026-05-13/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-phase5b-public-survey-2026-05-13.png" length="0" type="image/png"/></item><item><title>AI observability tier, Phase 2 synthesis (cross-cuts + version-deltas)</title><link>https://nuclide-research.com/research/case-studies--commercial--synthesis-ai-observability-phase2-2026-05-12/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--synthesis-ai-observability-phase2-2026-05-12/</guid><description>NuClide Research · 2026-05-12</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--synthesis-ai-observability-phase2-2026-05-12.png&quot; alt=&quot;AI observability tier, Phase 2 synthesis (cross-cuts + version-deltas)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-12&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--synthesis-ai-observability-phase2-2026-05-12/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--synthesis-ai-observability-phase2-2026-05-12.png" length="0" type="image/png"/></item><item><title>VisorBishop loop-iteration #1: Re-sweep all Phase 1 corpora, surface gaps</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter1-survey-2026-05-11/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter1-survey-2026-05-11/</guid><description>NuClide Research · 2026-05-11</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter1-survey-2026-05-11.png&quot; alt=&quot;VisorBishop loop-iteration #1: Re-sweep all Phase 1 corpora, surface gaps&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-11&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter1-survey-2026-05-11/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter1-survey-2026-05-11.png" length="0" type="image/png"/></item><item><title>VisorBishop loop-iteration #2: Extended port set, exposure-inventory pivot</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter2-survey-2026-05-11/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter2-survey-2026-05-11/</guid><description>NuClide Research · 2026-05-11</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter2-survey-2026-05-11.png&quot; alt=&quot;VisorBishop loop-iteration #2: Extended port set, exposure-inventory pivot&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-11&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter2-survey-2026-05-11/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter2-survey-2026-05-11.png" length="0" type="image/png"/></item><item><title>VisorBishop loop-iteration #3: AI-stack ML pipeline ports, Rogers NetOps disclosure</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter3-survey-2026-05-11/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter3-survey-2026-05-11/</guid><description>NuClide Research · 2026-05-11</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter3-survey-2026-05-11.png&quot; alt=&quot;VisorBishop loop-iteration #3: AI-stack ML pipeline ports, Rogers NetOps disclosure&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-11&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter3-survey-2026-05-11/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter3-survey-2026-05-11.png" length="0" type="image/png"/></item><item><title>VisorBishop iter-4: Adjacent platforms (Opik, AgentOps, Phospho)</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter4-survey-2026-05-11/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter4-survey-2026-05-11/</guid><description>NuClide Research · 2026-05-11</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter4-survey-2026-05-11.png&quot; alt=&quot;VisorBishop iter-4: Adjacent platforms (Opik, AgentOps, Phospho)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-11&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter4-survey-2026-05-11/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter4-survey-2026-05-11.png" length="0" type="image/png"/></item><item><title>VisorBishop iter-5: LiteLLM Proxy + Argilla + Promptfoo (gateway + annotation + eval tiers)</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter5-survey-2026-05-11/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter5-survey-2026-05-11/</guid><description>NuClide Research · 2026-05-11</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter5-survey-2026-05-11.png&quot; alt=&quot;VisorBishop iter-5: LiteLLM Proxy + Argilla + Promptfoo (gateway + annotation + eval tiers)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-11&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter5-survey-2026-05-11/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter5-survey-2026-05-11.png" length="0" type="image/png"/></item><item><title>VisorBishop iter-6: Full LiteLLM 5,391-host population sweep (283 unauth LLMjacking primitives)</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter6-survey-2026-05-11/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter6-survey-2026-05-11/</guid><description>NuClide Research · 2026-05-11</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter6-survey-2026-05-11.png&quot; alt=&quot;VisorBishop iter-6: Full LiteLLM 5,391-host population sweep (283 unauth LLMjacking primitives)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-11&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter6-survey-2026-05-11/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter6-survey-2026-05-11.png" length="0" type="image/png"/></item><item><title>VisorBishop iter-7: MLflow Tracking + Weights &amp; Biases self-host (experiment-tracking tier)</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter7-survey-2026-05-11/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter7-survey-2026-05-11/</guid><description>NuClide Research · 2026-05-11</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter7-survey-2026-05-11.png&quot; alt=&quot;VisorBishop iter-7: MLflow Tracking + Weights &amp;amp; Biases self-host (experiment-tracking tier)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-11&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter7-survey-2026-05-11/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter7-survey-2026-05-11.png" length="0" type="image/png"/></item><item><title>VisorBishop iter-8: Six platforms swept, near-zero critical (LLM pipeline + ML orchestration + product analytics)</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter8-survey-2026-05-11/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter8-survey-2026-05-11/</guid><description>NuClide Research · 2026-05-11</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter8-survey-2026-05-11.png&quot; alt=&quot;VisorBishop iter-8: Six platforms swept, near-zero critical (LLM pipeline + ML orchestration + product analytics)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-11&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-iter8-survey-2026-05-11/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-iter8-survey-2026-05-11.png" length="0" type="image/png"/></item><item><title>VisorBishop: Phase 3 meta-fingerprinter for the AI observability tier</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase3-survey-2026-05-11/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase3-survey-2026-05-11/</guid><description>NuClide Research · 2026-05-11</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-phase3-survey-2026-05-11.png&quot; alt=&quot;VisorBishop: Phase 3 meta-fingerprinter for the AI observability tier&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-11&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase3-survey-2026-05-11/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-phase3-survey-2026-05-11.png" length="0" type="image/png"/></item><item><title>VisorBishop Phase 5: Three primitives that turn 492 critical hosts into an impact narrative</title><link>https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase5-primitives-2026-05-11/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase5-primitives-2026-05-11/</guid><description>NuClide Research · 2026-05-11</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-phase5-primitives-2026-05-11.png&quot; alt=&quot;VisorBishop Phase 5: Three primitives that turn 492 critical hosts into an impact narrative&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-11&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--visorbishop-phase5-primitives-2026-05-11/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--visorbishop-phase5-primitives-2026-05-11.png" length="0" type="image/png"/></item><item><title>Helicone deep-dive: Phase 2 (default ClickHouse exposure on benchmarkit.solutions)</title><link>https://nuclide-research.com/research/case-studies--commercial--helicone-deep-dive-survey-2026-05-10/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--helicone-deep-dive-survey-2026-05-10/</guid><description>NuClide Research · 2026-05-10</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--helicone-deep-dive-survey-2026-05-10.png&quot; alt=&quot;Helicone deep-dive: Phase 2 (default ClickHouse exposure on benchmarkit.solutions)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-10&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--helicone-deep-dive-survey-2026-05-10/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--helicone-deep-dive-survey-2026-05-10.png" length="0" type="image/png"/></item><item><title>Helicone LLM-observability population survey (21-host self-hosted population)</title><link>https://nuclide-research.com/research/case-studies--commercial--helicone-llm-observability-survey-2026-05-10/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--helicone-llm-observability-survey-2026-05-10/</guid><description>NuClide Research · 2026-05-10</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--helicone-llm-observability-survey-2026-05-10.png&quot; alt=&quot;Helicone LLM-observability population survey (21-host self-hosted population)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-10&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--helicone-llm-observability-survey-2026-05-10/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--helicone-llm-observability-survey-2026-05-10.png" length="0" type="image/png"/></item><item><title>Langfuse deep-dive: Phase 2 (source audit + latent primitives + extended IP-shadow)</title><link>https://nuclide-research.com/research/case-studies--commercial--langfuse-deep-dive-survey-2026-05-10/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--langfuse-deep-dive-survey-2026-05-10/</guid><description>NuClide Research · 2026-05-10</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--langfuse-deep-dive-survey-2026-05-10.png&quot; alt=&quot;Langfuse deep-dive: Phase 2 (source audit + latent primitives + extended IP-shadow)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-10&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--langfuse-deep-dive-survey-2026-05-10/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--langfuse-deep-dive-survey-2026-05-10.png" length="0" type="image/png"/></item><item><title>Langfuse LLM-observability population survey (1,333-host population, 0% unauth)</title><link>https://nuclide-research.com/research/case-studies--commercial--langfuse-llm-observability-survey-2026-05-10/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--langfuse-llm-observability-survey-2026-05-10/</guid><description>NuClide Research · 2026-05-10</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--langfuse-llm-observability-survey-2026-05-10.png&quot; alt=&quot;Langfuse LLM-observability population survey (1,333-host population, 0% unauth)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-10&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--langfuse-llm-observability-survey-2026-05-10/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--langfuse-llm-observability-survey-2026-05-10.png" length="0" type="image/png"/></item><item><title>LangSmith deep-dive: Phase 2 (customer identity disclosure on 19 enterprise operators)</title><link>https://nuclide-research.com/research/case-studies--commercial--langsmith-deep-dive-survey-2026-05-10/</link><guid isPermaLink="true">https://nuclide-research.com/research/case-studies--commercial--langsmith-deep-dive-survey-2026-05-10/</guid><description>NuClide Research · 2026-05-10</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img src=&quot;https://nuclide-research.com/og/research/case-studies--commercial--langsmith-deep-dive-survey-2026-05-10.png&quot; alt=&quot;LangSmith deep-dive: Phase 2 (customer identity disclosure on 19 enterprise operators)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;NuClide Research · 2026-05-10&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nuclide-research.com/research/case-studies--commercial--langsmith-deep-dive-survey-2026-05-10/&quot;&gt;Read the survey →&lt;/a&gt;&lt;/p&gt;</content:encoded><enclosure url="https://nuclide-research.com/og/research/case-studies--commercial--langsmith-deep-dive-survey-2026-05-10.png" length="0" type="image/png"/></item></channel></rss>