New Insights on MCP Servers Linking AI Agents with Global Networks

New Insights on MCP Servers Linking AI Agents with Global Networks



Recent analysis conducted by OX Security has revealed critical vulnerabilities in the way AI agents utilize the Model Context Protocol (MCP). This research highlights how these agents are connecting to ungoverned infrastructures, particularly in regions like China and Russia, as well as in personal home networks and abandoned domains, raising alarm over cloud security governance that has taken years to establish.

Understanding MCP and Its Implications



Introduced by Anthropic in November 2024, the MCP serves as an open standard designed to facilitate connections between AI agents and a wide variety of external tools and data sources. However, a significant shortfall of MCP is its vague protocol-related guidelines regarding server operation, data handling, and code verification. These deficiencies mean that organizations—and the developers that interact with these servers—often leave essential security decisions unmanaged.

A thorough examination of 15,465 published MCP servers showed that 15.6% of unique hostnames connected to infrastructures beyond the United States. Notably, this includes 19 servers identified in China and 18 in Russia. There are also connections to home networks and consumer tunneling services, alongside six abandoned domains that can be registered for as little as $4, offering attackers low-cost routes to impersonating trusted endpoints.

The Data Residency Challenge



According to the findings, the problem of 'Data Residency Blind Spots' is significant. Researchers noted that 15.6% of the 5,095 analyzed hostnames resolved to infrastructures based outside the U.S., with no enforcement mechanisms in place through the MCP for geographic boundaries or compliance requirements. This could create potential vulnerabilities for organizations relying on cloud infrastructures that are not fully under their control.

Exposing Enterprises via Home Networks



OX Security found that alarming connections extend to home networks as well. About 0.45% of analyzed hostnames were traced back to consumer ISP networks or personal tunneling services, which undercuts centralized access controls and audit logging capabilities. The consequence is simple: enterprise AI workflows may inadvertently operate outside conventional security protocols, resulting in major exposure points.

Risks of Domain Takeover



The analysis further indicated that 2.3% of hostnames were no longer operational, which included six unregistered domains available for acquisition at minimal costs. This presents a dangerous avenue for cybercriminals who could seize these domains to masquerade as legitimate services, potentially tricking users or organizations into trusting malicious endpoints.

Trust and Permissions



In security testing scenarios involving simulated attacks using tools like Claude Code with Haiku 3.5, researchers noted that a malicious MCP server could exploit a single benign permission meant for a file request. This resulted in unauthorized access to sensitive data files without any necessary subsequent user confirmations. While the Opus 4.6 and 4.7 versions successfully prevented this attack, it still highlights the precarious nature of trust in the MCP ecosystem.

Conclusion



The report presents a worrying reality where AI agents, facilitated by MCP, venture into areas that disregard existing security frameworks. As enterprises continue to evolve their cloud infrastructures, it is crucial they account for the unregulated environments that AI agents may access. For a deeper dive into the full report titled "15,465 MCP Servers, 0 Governance," including its technical methodologies and potential threat scenarios, visit OX Security's website.

By confronting these challenges head-on and enhancing governance strategies, organizations can better protect themselves against the emerging threats posed by unrestricted AI use.

Topics Consumer Technology)

【About Using Articles】

You can freely use the title and article content by linking to the page where the article is posted.
※ Images cannot be used.

【About Links】

Links are free to use.