CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Someone Is Scanning for Your MCP Servers and AI Assistant Credentials

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2377

As cited

Copy frozen at (site build).

ai security

Someone Is Scanning for Your MCP Servers and AI Assistant Credentials

Distributed scanners at internet scale are systematically probing for Model Context Protocol (MCP) servers, AI assistant configuration files, and locally exposed large language model endpoints, including sending valid JSON-RPC 2.0 handshakes to test for functional MCP implementations. The scanning activity, originating from 49 distinct IP addresses over a two-week period, also targets AI assistant credential and configuration files from tools like Claude and Cursor that developers may accidentally expose in web roots.

Why it matters: Organizations running MCP servers or accidentally exposing AI assistant configuration files face immediate risk of credential theft and unauthorized access to databases, file systems, and internal APIs that connected agents can reach; practitioners should audit web roots for .claude, .cursor, and .mcp files and ensure any internet-exposed MCP servers require authentication.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Someone Is Scanning for Your MCP Servers and AI Assistant Credentials

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Someone Is Scanning for Your MCP Servers and AI Assistant Credentials

An internet-wide scanning campaign is systematically probing for exposed Model Context Protocol (MCP) servers, artificial intelligence (AI) assistant configuration files, and locally running large language model (LLM) endpoints. Analysis of 14 days of web server logs revealed approximately 200 requests across these categories from 49 distinct source IP addresses, with attackers sending properly formed JSON-RPC 2.0 MCP protocol handshakes rather than blind vulnerability probes. The reconnaissance targets configuration files from tools like Claude and Cursor that developers may accidentally expose in web roots, indicating the scanners possess current, real-world knowledge of how these tools store credentials and settings.

Why it matters: Development teams and infrastructure operators who have deployed MCP servers, AI coding assistants, or LLM endpoints need to verify these services are not exposed to the internet or properly authenticated, as unauthenticated MCP servers expose a machine-readable inventory of databases, file systems, APIs, and tools that attackers can exploit at scale.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Someone Is Scanning for Your MCP Servers and AI Assistant Credentials

An internet-wide scanning campaign is systematically probing for exposed Model Context Protocol (MCP) servers, artificial intelligence (AI) assistant configuration files, and locally running large language model (LLM) endpoints. Analysis of 14 days of web server logs revealed approximately 200 requests across these categories from 49 distinct source IP addresses, with attackers sending properly formed JSON-RPC 2.0 MCP protocol handshakes rather than blind vulnerability probes. The reconnaissance targets configuration files from tools like Claude and Cursor that developers may accidentally expose in web roots, indicating the scanners possess current, real-world knowledge of how these tools store credentials and settings.

Why it matters: Development teams and infrastructure operators who have deployed MCP servers, AI coding assistants, or LLM endpoints need to verify these services are not exposed to the internet or properly authenticated, as unauthenticated MCP servers expose a machine-readable inventory of databases, file systems, APIs, and tools that attackers can exploit at scale.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary