Published open by the CogniWatch autonomous red team · GET /api/intel/articles
● Live observatory feed
The internet is running — autonomous AI agents.
Most are wide open.
CogniWatch continuously sweeps the public internet for exposed agent infrastructure — n8n, Dify, Flowise, OpenClaw and more — and scores how dangerous each one is to reach.
Frameworks —
Countries —
CVEs across fleet —
Last sweep —
Agent Network Map · Live Globe SSE
DRAG TO ROTATE · SCROLL TO ZOOM
—
Agents detected worldwide
—
High / critical risk
—
CVEs across fleet
—
Critical / high-risk hosts
Detection trend · 14 days GET /api/analytics/trends
Global Sentinel Score LIVE
—
/100
—
—High
—Medium
—Low
—Total
Top affected hosts LIVE
| Host | Framework | Risk |
|---|
Recent detections LIVE FEED
—
Connecting to live detection stream…
Live per-host detection feed · GET /api/events/stream
Framework breakdown GET /api/frameworks/detected
Geographic distribution GET /api/archive/overview/public
—
Threat score · lower is better
—
Coverage · % known ranges scanned
—
Agents monitored
—
Total detections recorded
Validated findings GET /api/probe/validated · login required
| Finding | Severity | Hosts | First seen |
|---|
Probe batches GET /api/probe/batches · login required
| Batch | Type | Status | Probes |
|---|
Enriched agent registry GET /api/agents/enriched · GET /api/search?q=
| Host | Framework | Region | Sentinel Score | CVEs | Last seen |
|---|
Score distribution GET /api/agents/confidence
Detection confidence
| Method | Confidence | Agents |
|---|
Recent discoveries GET /api/agents/enriched
| Host | Framework | Confidence | Risk | Last seen |
|---|
—
MCP servers discovered
—
High poisoning risk
—
Critical-capability tools
Red-team posture GET /api/mcp/redteam/public
—
Deputy-risk servers
—
Poisoning-risk servers
—
PyRIT attacks
Discovered MCP servers GET /api/mcp/discovered
| Server | Port | Tools | Risk |
|---|
Capability exposure GET /api/mcp/capabilities
● The CogniWatch Newsroom
Original reporting on AI supply-chain attacks.
Field reports from our own autonomous red team. Every article is based on real probes, real exposures and real exploit chains observed by the observatory — published open, forever.
Wire · live advisories GET /api/intel/rss
—
Registered users
—
Scanner nodes online
—
IPs swept today
Users GET /api/admin/users · PUT role · DELETE user
| User | Role | Joined |
|---|
Scanner control GET /api/scan/status
Scanner —. Next scheduled sweep in —.
Raw detections stream GET /api/admin/detections/raw
| Timestamp | IP | Signature | Action |
|---|