Fetching from the wire…
Public story · 2026-03-03 · source-backed
Trend Micro found 492 with zero authentication and zero encryption. BlueRock analyzed 7,000+ servers with 36.7% vulnerable to SSRF — in a PoC, researchers retrieved AWS IAM access keys from EC2 metadata via Microsoft's MarkItDown MCP server. Over 90% of organizations maintain dangerous default configs. This is the "MongoDB 2017 moment" for AI infrastructure. Medium/BlueRock
Each link below shares sources, entities, or timing with this story.
BlueRock scanned over 7,000 MCP servers against 22-plus security rules. 36.7% carry potential server-side request forgery exposure from unrestricted outbound fetch, and 42% handle credentials insecurely. Their worked example is Microsoft's 85K-star Markitdown MCP server and it...
Security researchers scanned 8,000+ MCP servers on the public internet. 36.7% share SSRF vulnerabilities enabling access to cloud credentials and internal metadata. Default configurations bind admin panels to 0.0.0.0:8080, publicly accessible from first deployment. Exposed dat...
Independent researchers at Bitsight and Knostic discovered 8,000+ MCP servers visible on the public internet with admin panels, debug endpoints, and API routes completely unauthenticated. Default configurations binding to 0.0.0.0:8080. Exposed data includes full agent conversa...
The Model Context Protocol has a security problem, and now we have numbers to prove it. An independent scan of 5,618 public MCP servers found that only 143 — that's 2.5% — scored green on a basic security assessment. The remaining 5,067 servers (90%) flagged yellow for stale d...
The agent skills threat isn't isolated. The infrastructure layer is equally compromised. The Cloud Security Alliance's March 13 State of Cloud and AI Security report analyzed over 7,000 MCP servers and found 36.7% potentially vulnerable to server-side request forgery (SSRF). I...
Token Security researcher Ariel Simon will present at RSAC 2026 a vulnerability chain starting from SSRF in Microsoft's Azure MCP server (CVE-2026-26118, CVSS 8.8). The managed identity token included in outbound MCP requests is capturable without admin access, then escalatabl...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.