2026 State of the Underground Report
Get the full picture on AI exposure, exploit pressure, and the underground trends security teams need to watch.
According to Bitsight TRACE’s 2025 State of the Underground report, the most exposed devices tied to critical vulnerabilities were found in the United States, and the most affected sectors included Information (telecom, IT) and Professional, Scientific, and Technical Services (including security and software vendors).
Even the most security-conscious industries are struggling to maintain visibility over exposed assets, especially those introduced by third parties. As of this blog’s publication, Bitsight threat research has identified over 230 million exposures in the U.S. alone, representing more than 40% of all exposures worldwide. That’s a staggering number, one that should stop any security leader in their tracks. How many of those 230 million exposures are you at risk for? Are your vendors at risk for? Are their vendors at risk?
In a recent study, Bitsight’s Dr. Ben Edwards predicted up to 59,000 new CVEs would be published in 2025. But with the NVD (NIST’s vulnerability database) still struggling to keep up, many of these vulnerabilities aren’t being fully analyzed thus creating a growing intelligence gap. As the volume of CVEs rises, the odds increase that a truly dangerous vulnerability slips through the cracks, especially on untracked, unmanaged, or vendor-owned assets. In other words, Shadow IT.
Without visibility into your full digital footprint, including assets you didn’t know existed, high-risk vulnerabilities can sit unpatched and exploited. You can only patch what you are aware of.
Imagine your parents know every toy in your room. But one day, your friend brings a toy and hides it under your bed. That toy might be fun, it could also be sharp or dangerous and no one knows it’s there to check.
That’s what Shadow IT is like: unauthorized tech that’s introduced without oversight. And when it’s your vendors—or even their vendors—bringing it in, the risk becomes harder to control and nearly impossible to see.
Shadow IT refers to devices, apps, cloud services, or infrastructure spun up without IT’s knowledge or approval. This includes:
While third-party Shadow IT involves assets introduced by your immediate vendors, fourth-party Shadow IT refers to assets introduced by your vendors’ vendors—integrators, cloud hosts, subcontractors—often outside your direct line of sight. Those assets can still carry your domain, your logo, or your data.
These assets might not appear in any inventory, but they’re visible to attackers, indexable by search engines, and exploitable like any other exposed infrastructure.
Shadow IT, (first, third, or fourth party), is usually not malicious. It’s driven by:
But lack of visibility is lack of control. And when it comes to fourth-party risk, you may not even know the vendor exists, let alone what they’ve exposed on your behalf.
A fintech firm hired a digital marketing vendor for a three-month campaign. That vendor outsourced hosting to another provider (a 4th party), spinning up a microsite under securepromo.finbrand.com. The campaign ended. The 4th-party host kept the site live (intentionally or unintentionally). Months later, it was quietly compromised and redirected users to a phishing site mimicking the fintech's login portal.
IT never knew the asset, or the 4th party, existed. But the brand and customer damage was real.
This is why it is important to monitor your company, your vendors, and your vendors’ vendors. The attack surface is vast, ensure you are protected.
Manual inventories and static assessments can’t catch vendor- or 4th-party Shadow IT. You need continuous, outside-in visibility that spans your entire digital supply chain.
That’s where Bitsight Exposure Management delivers. Combining the strengths of External Attack Surface Management (EASM) and Third-Party Risk Management (TPRM), Bitsight provides the only solution that helps you:
Shadow IT isn’t just an internal challenge anymore. It’s an ecosystem-wide risk that includes your third and fourth parties, and it’s being actively exploited.
With Bitsight Exposure Management, you get the visibility and control needed to detect, assess, and mitigate risk across the entire digital footprint, not just what you own, but what’s tied to your brand.
Don’t let hidden infrastructure become your next breach. Shine a light on Shadow IT, wherever it lives.
Shadow IT can refer to a number of different IT applications, cloud software, outside technologies, and devices (laptop, smartphone, etc.) that are connected to an organization’s network without the knowledge of the IT department. These non-approved technologies aren’t vetted through the usual IT vendor onboarding process, which means they might have security standards that are below your organization’s normal risk-thresholds.
It can be hard to believe that your IT department would miss critical vendors being given access to your network, but research shows that the average organization houses over 900 unknown cloud services, and 80% of workers surveyed admit to using SaaS applications at work without getting approval from IT.
It might be hard to believe in the danger of shadow IT if security managers aren’t constantly talking about it. In reality, when the sources of data breaches are not always made public, it can be because security teams are embarrassed to admit to having shadow IT. Major data breaches, like SolarWinds, are impacting large numbers of companies because IT departments weren’t aware that SolarWinds software was present because it had been downloaded by an employee for free.
Shadow IT is there, and it’s worth your worrying about. With today’s remote office environment, employees around the world are accessing their organization's network from home internet points. This means that anyone else using that same internet is also connected to the company’s network, which dramatically expands the attack surface for bad actors to infiltrate.
Your employees most likely are not trying to welcome bad actors onto your network by choosing to bypass IT protocols. In reality, the most common reason for shadow IT on your network is because your employees are trying to work more efficiently, and are trying out a new service or cloud provider. Sometimes the team leaders don’t realize even the seemingly smaller integrations still need to be run through IT, and other times the need is urgent and employees don’t want to wait for the IT audit to be completed.
In other instances, employees might be very conscious of their cybersecurity decisions on the company network, but don’t know how using a remote internet connection or using personal devices for work could impact the company. Including shadow IT in your employee cybersecurity training is the best way to educate your workforce about the potential danger of their decisions.
Protecting your organization from bad actors requires a monitoring technique that scans for shadow IT. Manual processes or tools requiring oversight from a member of the IT department can be time consuming, and can fail to monitor every corner of your network.
With Bitsight for Security Performance Management, customers are given access to Attack Surface Analytics. Attack Surface Analytics specifically helps program managers discover hidden assets and cloud instances on your network. Bitsight then will assess the discovered areas of shadow IT for their inherent risk to your business, and then help bring them into line with your corporate security policies.
If you’re curious about what shadow IT is lurking in your network, you can request an Attack Surface Analytics report with Bitsight today.
Get the full picture on AI exposure, exploit pressure, and the underground trends security teams need to watch.