[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fh1oEfzHPhCA_f1JddAYe5dhXLwVGPmu_QVr6eaB-uFg":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"544dee08-a321-454a-bf08-7cff74f13ae5","Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers","welcome-to-the-jungle-what-we-found-inside-15-465-public-mcp-servers-7cefa7","In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP","OX Security researchers analyzed 15,465 publicly indexed MCP servers and found a significant lack of security guardrails. Many servers were hosted outside approved jurisdictions, ran on personal machines, or used dangling domains, posing risks to enterprise data and workflows. The findings highlight a critical gap in the AI ecosystem's supply chain security, as marketplaces lack vetting processes.","OX Security found 15,465 public MCP servers with no security review or governance.","Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers The Hacker NewsOct 06, 2026Supply Chain \u002F Artificial Intelligence In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP source code, downloaded more than 150 million times. This time, we looked at what people actually install: community-published servers across the most popular MCP marketplaces. We found no guardrails and no review. Security is a recommendation, not a policy. A Marketplace With No Bouncer In 2012, Google ran Bouncer, an automated scanner that checked Android apps for malware before they reached users. It wasn't perfect: researchers slipped malware past it. But it existed. MCP marketplaces have no equivalent. Anyone can write a server, push it, and publish it. Even a review wouldn't close the gap. At RSAC and OWASP last year, we presented \"In GitHub We Trust: 10 Ways You Can Get Pwned,\" on how developers over-trust what they see in a repository. MCP repeats that mistake. Remote MCP servers can run backend code that differs entirely from what their public repository shows. Code review tells you what the developer published, not what the server runs. Where Does Your Data Go? Over the past decade, enterprises built strict governance to adopt public cloud safely: data residency rules, Zero Trust boundaries, granular IAM, and supply chain audits. MCP connections often sit outside all of it. To measure the gap, we analyzed 15,465 publicly indexed MCP servers across 5 MCP registries, deduplicated to 5,095 unique hostnames. Hosted outside the US: 15.6% of hostnames resolve to infrastructure outside the United States, including 19 in China and 18 in Russia. An agent connected to these servers may send data to jurisdictions the security team never approved. Running on personal machines: 0.45% route traffic through consumer tunneling services, mainly ngrok-free. These publicly listed servers run from personal machines and, likely, home networks. Dangling domains: 2.3% no longer resolve. Six sit on expired domains that anyone can register for $4 to $12 a year. A new owner would inherit an established server identity, along with requests from any agent still configured to call it. Location can also change. An operator could launch a server on a clean US IP address and later route traffic somewhere else. The full report covers our methodology, a prompt-injection proof of concept, and the threat scenarios behind each finding. Download \"15,465 MCP Servers, 0 Governance\" Trust Is the Attack Surface The protocol isn't the problem. The trust we hand it is. Until marketplaces add vetting, code signing, and origin verification, the enterprise has to do that work. It's still a jungle out there. Make sure you're not the prey. Get the full report, \"15,465 MCP Servers, 0 Governance\" Want to go further? Join our live webinar, \"The AI Attack Surface Is Already in Your Cloud,\" on October 13 at 12:00 PM ET. Latio founder and CEO James Berthoty and OX Field CTO Chris Lindsey will cover how AI is reshaping cloud threats and what security teams should do about it. Register Note: This article has been expertly written and contributed Moshe Siman Tov Bustan, Security Research Team Lead, OX Security. Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Cloud security, Supply Chain ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fwelcome-to-jungle-what-we-found-inside.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhd9ijWk9zlAlr4Ogzkb3OyeREM6GDYe0AZx5DQ-TmdUPN5ogFXFM0Z9Lh-qdG1CAIVdBX7cV7NSfgEk_yBtaTFCPdIjAo23ixCfHqa4j1m8FY2cRfmdcrd4GZNn-5QQScWonyO6GDRx6RA1ZRcuW9tAmCOFG9u7KQbWx3fftJ921w8rUqHx4ya_5CFuJM\u002Fs1600\u002Fox.png.jpg","2026-10-06T11:02:30+00:00","2026-10-06T12:00:14.925646+00:00",8,[18,21,24,26,29],{"name":19,"type":20},"MCP","product",{"name":22,"type":23},"OX Security","vendor",{"name":25,"type":23},"Anthropic",{"name":27,"type":28},"AI","technology",{"name":30,"type":20},"ngrok","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":31,"icon":33,"name":34,"slug":35},null,"Supply Chain","supply-chain",[37,39,44,49],{"category":38},{"id":31,"icon":33,"name":34,"slug":35},{"category":40},{"id":41,"icon":33,"name":42,"slug":43},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"c70f3a41-2f0c-4608-870d-b8cbcd8be076","Cloud Security","cloud-security",{"category":50},{"id":51,"icon":33,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]