{"data":{"id":"98c2578a-aa6f-4e23-a96a-d50a3ab3ef41","title":" The risk hiding behind exposed MCP servers","summary":"The Model Context Protocol (MCP, a system that lets AI agents use remote software tools) is being deployed across many cloud environments, but security features are lagging behind adoption. Researchers found that about 1 in 6 cloud environments expose at least one unauthenticated MCP server (servers anyone on the Internet can access without logging in), and these exposed servers often reveal sensitive data like employee information and business records, allow changes to production systems, or even grant access to cloud credentials. MCP servers are particularly risky because they automatically describe all their capabilities in a machine-readable format, making it easy for attackers to discover what they can do, and because one generic tool can interact with any MCP server worldwide.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://www.wiz.io/blog/the-risk-hiding-behind-exposed-mcp-servers","publishedAt":"2026-07-28T15:58:22.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["rag_poisoning","data_extraction"],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["Anthropic","Model Context Protocol","MCP"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-28T15:58:22.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}