AI/ML, AI benefits/risks

Unprotected MCP servers on the rise, report finds

Nearly 1,000 internet-exposed Model Context Protocol servers lacked any authorization controls, with the absence of required OAuth 2.1 implementation driving the proliferation of unprotected MCP deployments, reports SiliconANGLE.

Multiple online MCP instances were associated with sensitive back-end systems and could enable the direct retrieval of tools, prompts, and resources from servers, according to a Bitsight analysis. Other MCP servers were found to facilitate direct Kubernetes cluster management, permitting command execution within live container pods, customer relationship management platform access, and far-reaching WhatsApp message delivery.

Arbitrary command-executing tools have also been exposed by certain MCP servers, threatening total system compromise. With vulnerable MCPs potentially abused to compromise other databases and file systems, organizations have been urged to not only require authorization but also restrict internal network connections, leverage local transport methods, and adopt robust authentication measures.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds