BREAKING
Attackers Scan Web for MCP Servers
0IPs
distinct sources
0days
log window
0
AI-related requests
Recon Ahead of Adoption
What Attackers Probed
1POST /mcp handshakes
2.claude & .cursor secrets
3Exposed Ollama scans
Weak Spots vs Defenses
Weak Points
Plaintext long-lived tokens
Optional mutual auth
Low security visibility
Defenses
Mutual TLS
Short-lived tokens
Log and monitor endpoints
Assume Exposure From Day One
AI NEWS BLITZ
SANS finds adversaries are already probing the web for AI assistant infrastructure.