Get the latest tech news
Exposed MCP servers across the internet
Knostic mapped 1,862 internet-exposed MCP servers via Shodan. 100 % lacked auth, revealing immature and risky GenAI endpoints.
Using Shodan and a suite of custom Python tools, we fingerprinted and mapped production servers that responded to unauthenticated, protocol-compliant handshake requests. By layering filters across content, transport, endpoints, and headers, we improved accuracy and developed a detailed map of exposed MCP servers. Our findings reveal a significant number of internet-exposed MCP servers operating in production environments, many lacking authentication or adequate safeguards.
Or read this on Hacker News