Get the latest tech news

Exposed MCP servers across the internet


Knostic mapped 1,862 internet-exposed MCP servers via Shodan. 100 % lacked auth, revealing immature and risky GenAI endpoints.

Using Shodan and a suite of custom Python tools, we fingerprinted and mapped production servers that responded to unauthenticated, protocol-compliant handshake requests. By layering filters across content, transport, endpoints, and headers, we improved accuracy and developed a detailed map of exposed MCP servers. Our findings reveal a significant number of internet-exposed MCP servers operating in production environments, many lacking authentication or adequate safeguards.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of internet

internet

Photo of mcp

mcp

Photo of mapping mcp servers

mapping mcp servers

Related news:

News photo

AI agents will change work and society in internet-sized ways, says AWS VP

News photo

Internet-safe iPhone for children goes on sale for £99 a month

News photo

How a few online users make the internet – and humanity – look worse than they are