2 min read · Hacker News
Over 21,000 Model Context Protocol Servers Exposed Without Basic Authentication
Security audits discovered over 21,000 internet-facing Model Context Protocol servers, with nearly 92% lacking OAuth. Developers must audit their local and remote tool endpoints to prevent unauthorized remote execution.
Why it matters. Exposed MCP servers allow remote attackers to invoke local shell commands and exfiltrate credentials from agentic developer workflows.