· via dev.to (home feed)
ZoomEye scan counts 256,996 MinIO and 198,176 Prometheus instances exposed online
A ZoomEye survey indexed 256,996 MinIO and 198,176 Prometheus instances reachable from the internet, where open storage and metrics endpoints can leak data, credentials and infrastructure details.

Internet-wide scanning has surfaced more than 450,000 publicly reachable MinIO and Prometheus installations, two classes of infrastructure service that can hand an attacker stored data and a detailed map of an internal environment without any exploitation. The figures come from an analysis published on dev.to on 6 October 2026, which queried the ZoomEye search engine through its SDK on 25 September 2026 and frames both storage and telemetry systems as services that hold credentials.
What the scan measured
Product fingerprints returned 256,996 assets identifying as MinIO and 198,176 identifying as Prometheus in ZoomEye's index at query time. Two supporting queries from the same session filled in the surrounding picture: 7,836,873 assets listening on port 9000 over HTTP, and 88,070 assets on port 8080 serving a page titled Dashboard. All four figures are single-day snapshots of the index and will shift as deployments change.
What exposed endpoints give away
The two services leak different things. According to the dev.to post, an object storage endpoint left without authentication discloses bucket names and, depending on the attached policy, the listings and contents inside those buckets. Buckets are commonly used for backups, logs and application uploads, and the post observes that bucket policies often receive less scrutiny than a database holding the same data would.
Prometheus is attractive for a different reason. A reachable metrics endpoint effectively documents the environment: target lists name hosts and services, labels routinely carry environment and version details, and the metrics themselves can indicate which patches were recently applied because version strings surface in the labels. That is reconnaissance requiring no attack at all, and the exposed population is large enough that automated harvesting would be worthwhile from an attacker's perspective.
The author links both exposure types to the MITRE ATT&CK techniques T1213, Data from Information Repositories, and T1190, Exploit Public-Facing Application.
Why the port count is far larger
The 7.8 million result for port 9000 is roughly thirty times the MinIO fingerprint count, which could be read as a far bigger problem. It is not. Port 9000 is used by many applications besides MinIO, and the fingerprint only matches hosts that actually present themselves as the product. The post stresses that port-level and product-level measurements answer different questions, and that swapping one for the other leads to misleading conclusions in either direction.
Checks the post recommends
- Confirm that object storage buckets cannot be listed anonymously, starting with backup buckets, since those hold recovery material in addition to the data itself.
- Treat metrics endpoints as internal documentation and confine them to the monitoring network instead of exposing them for convenience.
- Audit what labels and target lists disclose about software versions, because that information lets an attacker select an exploit without scanning anything themselves.
Caveats on the numbers
The post is explicit about its limitations. Fingerprint counts depend on how a product presents itself and undercount deployments hidden behind proxies, while the port- and title-based counts include many unrelated services. Every figure is a one-time observation from a single date, and the analysis is a single-author effort based on ZoomEye's index rather than vendor research with independent verification.
Why it matters
This is a misconfiguration problem, not a vulnerability disclosure, which cuts two ways. There is no patch to wait for, so the fix is available to every operator today, but there is also nothing that will remediate the exposure automatically, and the populations involved are large enough that unmanaged instances will stay online indefinitely. The combination is particularly potent: open object storage can surrender the data itself, including backups and anything credential-bearing inside them, while an exposed Prometheus hands over the metadata — host inventories, environments, version levels — needed to plan a follow-on attack with precision. The practical response is cheap: verify bucket listings are closed, put metrics behind network boundaries, and strip version-bearing labels from anything internet-facing. For teams running either stack, the scan is a useful prompt to check whether their own instances appear in that count.
- #security
- #minio
- #prometheus
- #observability
- #cloud