Back Infosecurity-Magazine MCP Is Creating Major Governance Gaps, Researchers Warn
Model Context Protocol (MCP) servers are creating a silent enterprise governance gap which threatens to undermine cybersecurity efforts as AI deployments proliferate, according to new research from Ox Security.
MCP connects AI applications to external tools and data in a standardized manner, so that developers don’t have to write custom code each time they want to connect AI to an API or database.
However, in so doing, it might also be exposing organizations to cloud security risks that data residency requirements, zero trust boundaries, granular IAM policies and continuous supply-chain audits are meant to mitigate, Ox Security claimed in a new report.
That report, 15,465 MCP Servers, 0 Governance , has been produced from analysis across three public registries: mcp-official-registry, cline-marketplace and github-mcp-registry.
The report found that nearly 16% of the 5095 unique hostnames it analyzed resolved outside the US, in countries including Russia and China.
“MCP has no protocol-level concept of geographic region,” it warned. “An enterprise can enforce strict residency controls on its own cloud workloads while its AI agents connect freely to servers sitting outside those same controls.”
Over 2% of the hostnames no longer even resolve, with some currently unregistered and available to buy, meaning a threat actor could impersonate the servers they used to point to, the report continued.
The Ox Security team also flagged that when they tested Claude Code with Haiku 3.5 and granted a single “always-allow” permission, it enabled subsequent malicious activity without requiring human approval.
“A malicious MCP server first asked for access to a harmless file. The user approved it with an always-allow permission,” it explained.
“The server then requested a sensitive file, .env among them, and got it, with no further prompt required. Anthropic’s response, in short: once always-allow is granted, that’s the documented behavior, and model-level detection of malicious content is a best-effort heuristic, not a security boundary.”
MCP Risk Proliferates
A Backslash Security report from June 2025 based on analysis of 7000 MCP servers found hundreds exposed to anyone on the same local network via a vulnerability dubbed “NeighborJack.” Around 70 had severe flaws, including unchecked input handling and excessive permissions.
In April 2026, Ox Security released another report , this time highlighting what it claimed is a “critical, systemic” vulnerability in MCP which could enable arbitrary command execution on any vulnerable system.
The vendor claimed that as many as 200 open source projects, 150 million downloads, 7000+ publicly accessible servers and up to 200,000 vulnerable instances could be exposed by the vulnerability.
The report described it not as a traditional flaw but “an architectural design decision baked into Anthropic’s official MCP SDKs across every supported programming language.”
The model maker dismissed the report as “expected behavior,” leaving the AI supply chain to work on fixes to patch the individual open source projects which it impacts.
Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection News 5 November 2025
Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection
Infosecurity Europe: Patch Responsibility Remains Up for Grabs as AI Unearths Decades of Flaws News 3 June 2026
Infosecurity Europe: Patch Responsibility Remains Up for Grabs as AI Unearths Decades of Flaws
Over 75% of Organizations Experience Microsoft 365 Governance Issues News 24 September 2026
Over 75% of Organizations Experience Microsoft 365 Governance Issues
Shadow AI is Exposing the Same Governance Failures Cybersecurity Teams Have Ignored For Years Opinion 10 June 2026
Shadow AI is Exposing the Same Governance Failures Cybersecurity Teams Have Ignored For Years
FIRST CEO Calls for Global CVE Collaboration amid AI Vulnerability Tsunami Interview 17 April 2026
FIRST CEO Calls for Global CVE Collaboration amid AI Vulnerability Tsunami
What’s Hot on Infosecurity Magazine?
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
Researchers Identify AliExpress Phishing Domains Before Registration
Ransomware Attacks Reach Record High for 2026
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
UK Government Shifts to Service-Led Cyber Governance After Stinging Audit
AI-Driven Cloud Threats and Defenses: Securing AI-Powered Environments
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
From APIs to Agents: How to Secure AI at Enterprise Scale
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
