S&P 500 5,235.18 +1.02%EUR/USD 1.0840 +0.21%GBP/USD 1.2710 +0.14%USD/JPY 149.50 −0.18%BRENT $82.40 −0.81%BTC $67,800 −0.21%GOLD $2,341 +0.55%NASDAQ 16,420.55 +0.74%S&P 500 5,235.18 +1.02%EUR/USD 1.0840 +0.21%GBP/USD 1.2710 +0.14%USD/JPY 149.50 −0.18%BRENT $82.40 −0.81%BTC $67,800 −0.21%GOLD $2,341 +0.55%NASDAQ 16,420.55 +0.74%
A daily business newspaper · Founded in 2026

Money Talk

Finance and markets: business, quotes, gold, energy and releases.

AI Agents Risk Enterprise Security Through Ungoverned MCP Servers

A scan of 15,465 Model Context Protocol servers has exposed significant security vulnerabilities, revealing that AI agents frequently connect to unmonitored infrastructure in China and Russia. This decentralized architecture bypasses a decade of enterprise cloud governance, allowing unauthorized access to sensitive internal data through consumer-grade network tunnels and abandoned domains.

AI Agents Risk Enterprise Security Through Ungoverned MCP Servers
Photo: Bio & News

The Model Context Protocol, introduced by Anthropic in late 2024, was designed to bridge AI agents with external data. However, OX Security researchers found that this open standard lacks inherent mechanisms to verify server identity, residency, or code integrity. Among 5,095 unique hostnames reviewed, 15.6% resolved to international infrastructure outside the United States. Furthermore, 0.45% of traffic bypassed corporate firewalls by routing through home networks and consumer-grade tunneling services, effectively removing these workflows from audit logs and centralized oversight.

The investigation also highlighted a low barrier for malicious exploitation. Researchers identified six abandoned domains that could be purchased for as little as $4, allowing attackers to impersonate trusted endpoints. In controlled tests, a malicious server utilized prompt injection to escalate a benign file request into unauthorized access to a sensitive .env file. According to Neatsun Ziv, CEO of OX Security, these findings underscore a shift where AI agents operate beyond traditional security perimeters, forcing companies to account for infrastructure they neither own nor control. As agents gain increased autonomy, the underlying servers they interact with become critical, yet often invisible, components of the enterprise attack surface.

Share article
TelegramXFacebook

When reusing this material a link to Money Talk is required.

Comments (0)

Leave a comment

No comments yet. Be the first!