Close Menu
NCIJ Network NCIJ Network
    What's Hot

    No evidence death of man in Rotherham explosion is linked to an ‘attempted terror attack’ – Full Fact

    October 6, 2026

    White House defends Trump comment to let Iran ‘take out’ LA and San Diego

    October 6, 2026

    Why Tories are talking about winning the next election

    October 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • No evidence death of man in Rotherham explosion is linked to an ‘attempted terror attack’ – Full Fact
    • White House defends Trump comment to let Iran ‘take out’ LA and San Diego
    • Why Tories are talking about winning the next election
    • Our first five impressions of Googlebooks — exciting but underbaked
    • FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
    • Securitize Partners With LG CNS on Tokenized Assets in South Korea
    • Goodbye joint replacements? Stanford scientists found a way to regrow cartilage and stop arthritis
    • Science, Indigenous knowledge team up to restore Canada’s kelp. (Sea otters help, too.)
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, October 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 6, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Hacker NewsOct 06, 2026Supply Chain / Artificial Intelligence

    In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows.

    The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic’s MCP source code, downloaded more than 150 million times. This time, we looked at what people actually install: community-published servers across the most popular MCP marketplaces. We found no guardrails and no review. Security is a recommendation, not a policy.

    A Marketplace With No Bouncer

    In 2012, Google ran Bouncer, an automated scanner that checked Android apps for malware before they reached users. It wasn’t perfect: researchers slipped malware past it. But it existed. MCP marketplaces have no equivalent. Anyone can write a server, push it, and publish it.

    Even a review wouldn’t close the gap. At RSAC and OWASP last year, we presented “In GitHub We Trust: 10 Ways You Can Get Pwned,” on how developers over-trust what they see in a repository. MCP repeats that mistake. Remote MCP servers can run backend code that differs entirely from what their public repository shows. Code review tells you what the developer published, not what the server runs.

    Where Does Your Data Go?

    Over the past decade, enterprises built strict governance to adopt public cloud safely: data residency rules, Zero Trust boundaries, granular IAM, and supply chain audits. MCP connections often sit outside all of it.

    To measure the gap, we analyzed 15,465 publicly indexed MCP servers across 5 MCP registries, deduplicated to 5,095 unique hostnames.

    • Hosted outside the US: 15.6% of hostnames resolve to infrastructure outside the United States, including 19 in China and 18 in Russia. An agent connected to these servers may send data to jurisdictions the security team never approved.
    • Running on personal machines: 0.45% route traffic through consumer tunneling services, mainly ngrok-free. These publicly listed servers run from personal machines and, likely, home networks.
    • Dangling domains: 2.3% no longer resolve. Six sit on expired domains that anyone can register for $4 to $12 a year. A new owner would inherit an established server identity, along with requests from any agent still configured to call it.

    Location can also change. An operator could launch a server on a clean US IP address and later route traffic somewhere else.

    The full report covers our methodology, a prompt-injection proof of concept, and the threat scenarios behind each finding. Download “15,465 MCP Servers, 0 Governance”

    Trust Is the Attack Surface

    The protocol isn’t the problem. The trust we hand it is. Until marketplaces add vetting, code signing, and origin verification, the enterprise has to do that work.

    It’s still a jungle out there. Make sure you’re not the prey.

    Get the full report, “15,465 MCP Servers, 0 Governance”

    Want to go further? Join our live webinar, “The AI Attack Surface Is Already in Your Cloud,” on October 13 at 12:00 PM ET. Latio founder and CEO James Berthoty and OX Field CTO Chris Lindsey will cover how AI is reshaping cloud threats and what security teams should do about it. Register

    Note: This article has been expertly written and contributed Moshe Siman Tov Bustan, Security Research Team Lead, OX Security.

    Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    Jungle MCP public Servers
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

    FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

    How to secure RMM software: 8 controls MSPs should test

    Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

    LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

    Cybersecurity M&A Roundup: 39 Deals Announced in September 2026

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    No evidence death of man in Rotherham explosion is linked to an ‘attempted terror attack’ – Full Fact

    October 6, 2026

    White House defends Trump comment to let Iran ‘take out’ LA and San Diego

    October 6, 2026

    Why Tories are talking about winning the next election

    October 6, 2026

    Our first five impressions of Googlebooks — exciting but underbaked

    October 6, 2026
    Latest Posts

    4 Best Compression Boots: Therabody, Hyperice, and More (2026)

    August 9, 2026

    Former Iraqi provincial governor arrested as graft crackdown continues | Corruption News

    August 9, 2026

    The culture surrounding ‘ideal’ childbirth has to evolve | Childbirth

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    No evidence death of man in Rotherham explosion is linked to an ‘attempted terror attack’ – Full Fact

    October 6, 2026

    White House defends Trump comment to let Iran ‘take out’ LA and San Diego

    October 6, 2026

    Why Tories are talking about winning the next election

    October 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.