Security research on AI agent infrastructure. A continuous honey-agent fleet, monthly internet-wide exposure sweeps, and live indices. Every finding classified by Threat Matrix technique, every count published with its query.
The agents following our injections are mostly not agents.
Behavioral Threat Report Issue 3. Agent-vs-crawler attribution shipped this month: of the AgentPwn payload callbacks we could attribute, 1,985 were browsers and link prefetchers, 9 were LLM content crawlers, and 0 were autonomous LLM agents. It corrects the Issue 2 framing. Inside the honey-agent fleet, MCP drew 99% of events and 99.5% of sessions classified as automated scanners.
Exposure over time
Exposed AI services per monthly internet-wide sweep. Latest: 204.9K.
What's exposed
What attackers target
Honey-agent events, June 22 to July 22, 2026 (30 days).
Where attacks originate
Top 5 of 105 countries observed.
Confirmed findings
Content-verified ARIAscout Shodan probe · June 2026.
Passive Shodan-index probe, dedup’d by host (point-in-time). A floor, not directly comparable to the January 2026 active host probe.