Issue 2 · June 2026
The internet has a background radiation
In astronomy, background radiation is not the dramatic explosion or the visible fireball. It is the faint, persistent signal that tells us something fundamental about the universe we live in: always there, whether we are looking at it or not. The internet has its own version of this phenomenon, and most organisations are not measuring it.
It is the continuous scanning, probing, fingerprinting, indexing and opportunistic reconnaissance of anything that appears in public view. It does not wait for a company to finish its audit. It does not respect a board reporting cycle. It does not care whether a CISO has deployed a SIEM, renewed cyber insurance, closed a vulnerability report, or presented a green dashboard to the leadership team. It is simply always present.
Most organisations see the internet as something they use. Attackers, scanners, bots, research engines and increasingly automated systems see it as something else entirely: an exposed field of signals. Every open service is a signal. Every banner, every misconfiguration, every forgotten API, test portal, development box, remote-access point, database port, storage endpoint, cloud workload and abandoned subdomain is a signal. And every signal invites a touch.
Every open service is a signal. Every misconfiguration is a signal. Every forgotten API is a signal.
Venus is our telescope
Venus was built to observe this reality. It is our Cyber Background Radiation Telescope: not a honeypot in the narrow sense, not just a dashboard, not merely another threat feed. It is an instrument designed to listen to the ambient hostility of the internet and make visible what most organisations never see clearly: the constant hostile radiation around any exposed digital surface. So I placed one on the open internet, a controlled deception environment holding nothing of value, and watched.
Venus, the first 24 hours · 2026-06-10 16:03 UTC
By the time this issue went to press, the same counter read 62,600, nearly five thousand new events in the few hours it took to write.
| Surface | What it watches |
|---|---|
| Web | HTTP surface |
| Database | DB ports |
| Shell | Remote exec |
| Portal | Logins |
| API | Endpoints |
This was not a production banking platform, a consumer application or a famous brand. It held no customer records, no payment data, no trade secrets. It was a controlled surface that merely existed. And because it existed, it was found.
Found within hours
There was no ramp-up, no grace period, no quiet window in which to finish configuring. The activity began almost immediately and never stopped. Of the sources Venus observed in its first 24 hours, 713 were brand new and only 376 were returning, roughly two in three had never touched it before. The radiation is not a fixed set of known bad actors circling a target. It is a constantly refreshing crowd, most of it arriving for the first time.

None of this required Venus to be important. It only required Venus to be reachable. That distinction is the whole point, and it is the one most boards have not yet internalised.
What the radiation is made of
When people imagine an attack, they picture the dramatic moment: the zero-day, the clever exploit, the breach in progress. The reading shows something far more mundane and far more revealing. Sorted by category, the overwhelming majority of what Venus saw was reconnaissance and credential-guessing. The exotic, high-severity techniques barely register by volume.
Attack categories · Venus, first 24 hours
This is what the background radiation actually looks like. Tens of thousands of scans and credential attempts; a few thousand attempts to plant a foothold; a tiny handful of the loud, named techniques that make headlines. The danger is not in any single event. It is in the volume, the patience and the certainty: the knowledge that something, somewhere, is always knocking, and only needs to be right once.
Most organisations are being observed far more often than they realise.
They are hunting your secrets
Look past the volume to what is actually being requested, and the intent becomes obvious. After the reflexive probes for the home page and /favicon.ico, the most-requested paths are a shopping list for leaked credentials and configuration: environment files, Git config, backend secrets. These are not random. They are the fastest route from “reachable” to “compromised.”
| Method | Path | Hits |
|---|---|---|
| GET | / | 1,033 |
| GET | /favicon.ico | 187 |
| GET | /.env | 105 |
| GET | /.git/config | 68 |
| GET | /.env.local | 46 |
| GET | /config.json | 39 |
| GET | /.env.production | 36 |
| GET | /backend/.env | 35 |

And some of it comes back
Most of the radiation is opportunistic: a scan passes through, fingerprints what it finds and moves on. But not all of it. Venus singled out one address that behaved very differently. It returned again and again, in correlated bursts, working steadily through a list of secret files. On the capability index it scored only a middling 52 out of 100. On persistence it scored a perfect 100.
195.178.110.199 · BG · Techoff Srv Limited
1,585 exposed_file_probe · 386 webshell_probe · 207 admin_console_probe
Its requests read like a burglar trying every window: /web/.env, /v3/.env, /wp-config.php.old, even /webhooks/incoming/stripe.json. This is the part that should unsettle a board. It is not the sophistication that makes an actor dangerous. It is the refusal to leave.
It merely existed, and that was enough to be found, fingerprinted, and revisited.
Origin is not attribution
It is tempting to read the geography and reach for a story. The largest volumes came from Bulgaria, Taiwan, the Netherlands and the United States; the busiest networks were hosting and VPS providers: Techoff, Feo Prest, Unmanaged Ltd, DigitalOcean, M247. But that map shows where the infrastructure was cheap and disposable, not who was sitting behind it. Origin is not attribution, and treating a flag on a map as an adversary is exactly the kind of comfortable shortcut that leads a board to the wrong conclusion.

What matters is not the pin on the map. It is the narrowing distance between the reconnaissance on display here and the exploitation that follows it. In the past, “we are only being scanned, not attacked” offered comfort. Today it should not.
Now add AI
Everything so far is the internet as it already is, without a single new technology. Now add AI. Frontier models and security-specific systems are becoming genuinely capable of reasoning over code, vulnerabilities, configurations, logs and exploit paths. For defenders that is promising: AI can help stretched teams analyse large environments, cut alert fatigue, accelerate remediation and strengthen code review. But capability is capability. The same advances that help defenders help adversaries.
A motivated attacker no longer needs to master every technique in depth. Increasingly they can assemble public tools, scanners, reconnaissance frameworks, exploit logic, wordlists, agentic workflows and AI-assisted reasoning into repeatable pipelines. The question is no longer whether such tooling exists. It does, abundantly.
The public tooling ecosystem
It is a vast, reusable, searchable, forkable body of code, scanners, exploit logic, reconnaissance tooling and automation, sitting in the open, one search away.
The danger is composability
The danger is not that every public repository is malicious. The danger is that the pieces fit together. Reconnaissance tools, scanners, exploit frameworks, payload generators, OSINT collectors, cloud-enumeration scripts, wordlists, automation logic, AI agents and security-specific models can now be assembled into working pipelines far faster than most organisations can validate their own exposure. The cost of experimentation has fallen. The cost of reconnaissance has fallen. The cost of chaining tools together has fallen.
AI does not need to invent reconnaissance. Reconnaissance already exists at scale.
None of this means every attacker becomes elite overnight, which would be an exaggeration. Skill still matters, context still matters, and many automated tools and AI suggestions simply fail. But the floor is rising. The average attacker becomes more capable, the capable attacker faster, the organised attacker more scalable, the opportunistic attacker more automated. And the defender still relying on slow, fragmented, manual, compliance-heavy assurance begins to fall behind. The future attacker may be AI-assisted; the present internet, as Venus shows, is already continuously adversarial. AI does not create the hostile environment. It only accelerates what already exists.
Activity is not assurance
Many companies still speak the language of control presence. Do we have a SIEM? An EDR? A SOC? Vulnerability scanning? An incident-response plan? Did we pass the audit? Is the dashboard green? These are valid questions, and a serious programme needs all of it. But they are no longer sufficient questions. A tool being deployed is not the same as a control being effective. A green dashboard is not the same as being safe. A SOC ticket is not intelligence. A scan is not exploitability. A policy is not resilience.
| Activity asks: what are we doing? | Assurance asks: what can we prove? |
|---|---|
| Do we have a SIEM, EDR, a SOC? | Which assets matter most to survival? |
| Did we pass the audit? | Which of those are exposed? |
| Did we close the finding? | Which vulnerabilities are exploitable today? |
| Is the dashboard green? | Which controls would fail under pressure? |
The uncomfortable truth is that many companies are not under-secured because they lack tools. They are under-secured because they have fragments: fragments of visibility, detection, evidence and accountability. The attacker does not operate in fragments. The attacker follows the path that works.
The comfort of what can be shown
Regulated organisations face a sharper version of this risk. Regulation creates structure, discipline and minimum expectations; it forces evidence, accountability and governance, and no serious person should dismiss it. But it can also create a dangerous comfort when an organisation begins to optimise for what can be shown rather than what is true. A company can hold policies, risk registers, board reports, SOC metrics, vendor attestations, audit evidence and dashboards, and still be fragile in front of a real adversary. So the language has to change.
| From | To |
|---|---|
| Control ownership | Control proof |
| Tool deployment | Signal intelligence |
| Annual testing | Continuous validation |
| Alert volume | Decision quality |
| Compliance evidence | Operational assurance |
If an AI-accelerated attacker targeted our most critical assets tonight, what evidence do we have that we would detect, contain and recover? Not belief. Not confidence by job title. Evidence.
Five questions, asked continuously
This is not an argument against CISOs, auditors, security teams or regulators. Quite the opposite. Their job has only become harder: a larger attack surface, a deeper dependency chain, an overwhelming volume of signals, and a board that wants simplicity while the underlying risk grows more dynamic by the month. What they need is a clearer baseline: five questions a serious organisation should be able to answer at any moment.
The new assurance baseline
- What do we own?
- What is exposed?
- What is exploitable?
- What is being targeted?
- What can we prove?
This does not replace compliance. It strengthens it. It does not replace tools. It makes them accountable. It does not replace the CISO. It gives the CISO a clearer way to speak to the board, defend investment, challenge false comfort and build evidence-led resilience.
The closing signal
The organisations that understand this shift will modernise before an incident forces them to. They will stop treating cybersecurity as a collection of activities and start treating it as a system of evidence. They will recognise that the internet is not waiting for their next audit cycle, and that AI does not merely add a new class of tools, it changes the tempo of risk. The organisations that do not will keep feeling safe inside a cocoon of controls, reports and dashboards. Until reality breaks through.
A single surface that held nothing of value was found within hours and visited thousands of times before its first day was out. The only question left is whether your organisation is prepared to look at what is already pointed at it.
The closing signal
The cyber background radiation is already there. Venus simply gives us a telescope.
