Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT Security NachrichtenAb 1.10: Meldepflicht für IT-Vorfälle in Österreich | heise online(22.09.2026 um 23:31 Uhr)
•
IT Security NachrichtenIT Security News Daily Summary 2026-09-22(22.09.2026 um 23:55 Uhr)
•
IT Security NachrichtenIT Security News Hourly Summary 2026-09-23 00h : 3 posts(23.09.2026 um 00:00 Uhr)
•
IT Security NachrichtenRelays Are Masking Chinese Access to Frontier AI Models in the US(22.09.2026 um 23:12 Uhr)
•
Malware / Trojaner / VirenAttackers Use Wallpaper Engine to Distribute Malware(22.09.2026 um 15:10 Uhr)
•
IT Security NachrichtenSweden fines Miljödata $183,000 over breach affecting 2.2 million(22.09.2026 um 23:40 Uhr)
•
IT Security NachrichtenRogue external MFA providers can steal passwords during logins(22.09.2026 um 23:45 Uhr)
•
IT Security NachrichtenÖsterreich setzt NIS2 um, erhält Bundesamt für Cybersicherheit(22.09.2026 um 23:24 Uhr)
•
IT NachrichtenHere’s a Newer Galaxy Z Fold 8 Update for You(22.09.2026 um 23:19 Uhr)
••
IT Security NachrichtenAb 1.10: Meldepflicht für IT-Vorfälle in Österreich | heise online(22.09.2026 um 23:31 Uhr)
•
IT Security NachrichtenIT Security News Daily Summary 2026-09-22(22.09.2026 um 23:55 Uhr)
•
IT Security NachrichtenIT Security News Hourly Summary 2026-09-23 00h : 3 posts(23.09.2026 um 00:00 Uhr)
•
IT Security NachrichtenRelays Are Masking Chinese Access to Frontier AI Models in the US(22.09.2026 um 23:12 Uhr)
•
Malware / Trojaner / VirenAttackers Use Wallpaper Engine to Distribute Malware(22.09.2026 um 15:10 Uhr)
•
IT Security NachrichtenSweden fines Miljödata $183,000 over breach affecting 2.2 million(22.09.2026 um 23:40 Uhr)
•
IT Security NachrichtenRogue external MFA providers can steal passwords during logins(22.09.2026 um 23:45 Uhr)
•
IT Security NachrichtenÖsterreich setzt NIS2 um, erhält Bundesamt für Cybersicherheit(22.09.2026 um 23:24 Uhr)
•
IT NachrichtenHere’s a Newer Galaxy Z Fold 8 Update for You(22.09.2026 um 23:19 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

I Scanned 492 MCP Servers Exposed to the Internet. Here's What I Found.

Over the past few weeks, I've been spending a lot of time looking at the security of AI agents. Not the models themselves. The infrastructure around them. Specifically, MCP servers. As more companies adopt AI agents, MCP servers are…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Over the past few weeks, I've been spending a lot of time looking at the security of AI agents.



Not the models themselves.



The infrastructure around them.



Specifically, MCP servers.



As more companies adopt AI agents, MCP servers are becoming the bridge between models and the real world. They connect agents to tools, databases, APIs, file systems, internal services, and external workflows.



Which got me thinking:



What happens when these servers are exposed to the internet?



So I decided to find out.



I analyzed 492 publicly accessible MCP servers and ran a series of behavioral security tests against them.



The goal wasn't exploitation.



The goal was understanding how these systems behave when they encounter adversarial inputs.






How I Scanned Them



For each MCP server, I performed a combination of:




  • Tool enumeration

  • Permission boundary analysis

  • Prompt injection testing

  • Command execution testing

  • Context manipulation testing

  • Behavioral security evaluation



The focus wasn't traditional vulnerability scanning.



Instead, I wanted to answer a different question:




Can an attacker influence what an AI-connected tool does simply by manipulating instructions?




Unfortunately, the answer was often yes.






The Most Surprising Finding



Out of the 492 MCP servers analyzed:



43% showed signs of command injection susceptibility.



Not because they were running outdated software.



Not because authentication was broken.



But because many systems implicitly trusted agent-generated instructions.



That trust created risk.






Pattern #1: Natural Language Becomes Shell Commands



One common pattern looked something like this:



A user asks:



"List all files in the project."



The MCP server converts that request into a shell command.



The problem is that weak validation often means the same pathway can process far more than intended.



When agent-controlled input reaches shell execution, things can get dangerous very quickly.



One-line fix:



Never pass agent-controlled input directly into shell execution. Use allowlisted commands and structured parameters.






Pattern #2: Free-Form Instructions Become Database Queries



Another recurring issue involved database access.



The agent receives a natural language request.



The request is transformed into a query.



Without strict controls, the scope of that query can expand far beyond what was originally intended.



The result isn't always a traditional injection vulnerability.



Sometimes it's simply excessive access.



One-line fix:



Use parameterized queries and strict scope enforcement. Never generate queries directly from free-form instructions.






Pattern #3: Tool Chaining Creates New Capabilities



This was probably the most interesting category.



Individually, the tools looked safe.



A search tool.



A file access tool.



An HTTP request tool.



Nothing unusual.



But when chained together by an autonomous agent, entirely new capabilities emerged.



Search became retrieval.



Retrieval became extraction.



Extraction became transmission.



The issue wasn't the tools.



It was the combination.



One-line fix:



Validate permissions at every tool boundary, not just when the agent starts.






The Bigger Problem



After reviewing hundreds of MCP servers, one thing became clear.



Most security teams are still thinking about AI infrastructure using traditional application security models.



They're asking:




  • Is authentication enabled?

  • Is the API protected?

  • Is the network secure?



Those questions still matter.



But AI systems introduce something new.



Behavioral security.



The system isn't necessarily compromised.



It's persuaded.



And that's a fundamentally different challenge.






Why I Built a Tool for This



After manually evaluating hundreds of MCP servers, it became obvious that this process doesn't scale.



That's why I built a framework to automate:




  • MCP discovery

  • Behavioral testing

  • Prompt injection evaluation

  • Command injection detection

  • Permission boundary analysis

  • Tool-chain security testing



The goal isn't to find bugs.



The goal is to identify risky behavior before attackers do.






Final Thoughts



The biggest lesson from scanning 492 MCP servers wasn't that AI systems are insecure.



It was that many of them trust instructions far more than they should.



As AI agents gain access to more tools, more data, and more autonomy, security can no longer stop at infrastructure.



We need to test behavior too.



That's one of the reasons I started building Crucible — an open-source security framework for testing AI agents, MCP servers, and agentic systems against real-world adversarial scenarios.






cybersecurity #artificialintelligence #opensource #githubopensource #security #buildinpublic #aiagents

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten I Scanned 492 MCP Servers Exposed to the Internet. Here's What I Found.

Thematisch verwandte Begriffe: Scanned, Servers, Exposed, Internet · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY Kritische Sicherheitsmeldung
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger • Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick