Our daily snapshots recorded 29,503 findings marked Open or Verified on August 12, 2026, and 28,569 on September 9, 2026. That is a net decrease of 934 indexed records across the observation window.

These are counts from the Misconfigured.app index. They do not measure the prevalence of misconfiguration across the internet, the number of affected companies, or the number of breaches.

The observations

Snapshot date Records marked Open or Verified
August 12, 2026 29,503
August 28, 2026 28,675
September 4, 2026 28,562
September 9, 2026 28,569

Download all 29 daily observations as CSV. The export was made on September 10, 2026. It contains dates and aggregate counts only.

How the counts were produced

The service's existing daily snapshot job groups index records by finding type and stored status. It excludes credential/private-key types and records hidden from the index when the snapshot runs. This report sums the remaining rows with stored status Open or Verified for each date from August 12 through September 9.

The unit is an indexed finding record. One cloud resource may be associated with more than one application and therefore appear in more than one record. Counts should not be read as unique assets or organizations.

The stored status is the service's recorded observation. A daily count does not mean that every included resource was checked that day. Our snapshot job can overwrite a date when rerun; the CSV preserves the values exported for this report.

What the change means for an application team

The net decline describes a smaller recorded index at the end of the window. It does not establish why those records changed. Discovery, hiding or removal of findings, changes in access, and index maintenance can all affect the total. These aggregates do not separate those causes.

For your team, the useful question is whether a relevant finding belongs to you and whether its recorded access matches your intended configuration. Review the application association, check permissions in your own cloud account, record any remediation, and save the search to follow new matches.

Limitations

  • This is a convenience index, not a random or representative sample of cloud deployments.
  • Provider discovery and application coverage vary. Provider totals are not comparative security scores.
  • Stored status is not proof of current accessibility or sensitive content.
  • Net changes do not count fixes, incidents, or customers protected.
  • Hidden records and excluded credential types are outside this report's population.

See Trust and methodology for the service's scope and the synthetic assessment for an example review. Teams can start an exposure review using an asset they manage.