The Model Context Protocol, introduced by Anthropic in late 2024, was designed to bridge AI agents with external data. However, OX Security researchers found that this open standard lacks inherent mechanisms to verify server identity, residency, or code integrity. Among 5,095 unique hostnames reviewed, 15.6% resolved to international infrastructure outside the United States. Furthermore, 0.45% of traffic bypassed corporate firewalls by routing through home networks and consumer-grade tunneling services, effectively removing these workflows from audit logs and centralized oversight.
The investigation also highlighted a low barrier for malicious exploitation. Researchers identified six abandoned domains that could be purchased for as little as $4, allowing attackers to impersonate trusted endpoints. In controlled tests, a malicious server utilized prompt injection to escalate a benign file request into unauthorized access to a sensitive .env file. According to Neatsun Ziv, CEO of OX Security, these findings underscore a shift where AI agents operate beyond traditional security perimeters, forcing companies to account for infrastructure they neither own nor control. As agents gain increased autonomy, the underlying servers they interact with become critical, yet often invisible, components of the enterprise attack surface.





Comments (0)
No comments yet. Be the first!