Executive Summary
In October 2026, OX Security's analysis of 15,465 publicly indexed Model Context Protocol (MCP) servers revealed critical security gaps in AI supply chain infrastructure. The research found no security guardrails or review processes across major MCP marketplaces, with 15.6% of servers hosted outside the US, including 19 in China and 18 in Russia. Additionally, 0.45% of servers operated through consumer tunneling services on personal machines, while 2.3% existed on dangling domains that could be hijacked for $4-12. The study exposed how MCP's rapid adoption has created unvetted pathways for AI agents to access external resources, bypassing enterprise security controls.
This analysis highlights the emerging risks in AI supply chain security as organizations rapidly integrate AI agents and tools without proper governance frameworks, creating new attack vectors that traditional security measures don't address.
Why This Matters Now
AI agent adoption is accelerating rapidly in enterprises, but security frameworks haven't kept pace. MCP servers represent a new attack surface where malicious actors can intercept AI workflows, exfiltrate sensitive data, or inject malicious responses into business processes.
Attack Path Analysis
Attackers exploit unvetted MCP servers in enterprise AI workflows by deploying malicious servers on compromised infrastructure or expired domains, then leveraging agent trust relationships to access sensitive data and establish persistent command channels. The attack progresses through AI agent privilege abuse, lateral movement across cloud workloads, covert data exfiltration to foreign jurisdictions, and potential business disruption through compromised AI decision-making processes.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers register expired MCP server domains or deploy malicious servers on personal infrastructure using tunneling services like ngrok, then publish them to unvetted marketplaces to be discovered by enterprise AI agents
MITRE ATT&CK® Techniques
Compromise Software Supply Chain
Spearphishing Attachment
Exploit Public-Facing Application
Web Protocols
Exfiltration to Cloud Storage
Drive-by Compromise
Match Legitimate Name or Location
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Data Discovery and Classification
Control ID: DA.L2
DORA – Third-party Risk Management
Control ID: Article 28
NIS2 Directive – Supply Chain Security Measures
Control ID: Article 21
NYDFS 23 NYCRR 500.11 – Third Party Service Provider Security Policy
Control ID: 500.11(a)
PCI DSS 4.0 – Third Party Service Provider Management
Control ID: 12.8.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
High supply chain risk from MCP server vulnerabilities, unvetted AI integrations, and potential data exfiltration through compromised development tools and workflows.
Information Technology/IT
Critical exposure to AI supply chain attacks through MCP servers, requiring enhanced zero trust segmentation and egress security for client environments.
Financial Services
Severe compliance violations from uncontrolled MCP data flows to foreign jurisdictions, bypassing established governance frameworks and regulatory requirements.
Health Care / Life Sciences
HIPAA violations through unvetted MCP servers potentially routing protected health information to unauthorized jurisdictions and personal infrastructure.
Sources
- Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servershttps://thehackernews.com/2026/10/welcome-to-jungle-what-we-found-inside.htmlVerified
- OX Security Research Report - 15,465 MCP Servers, 0 Governancehttps://www.ox.security/Verified
- Model Context Protocol Official Documentationhttps://modelcontextprotocol.io/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would constrain malicious MCP server attacks by limiting AI agent network reach, segmenting workload access, and controlling egress paths to foreign jurisdictions. Multi-stage segmentation would likely reduce the attack's blast radius across cloud environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely limit AI agent connectivity to only approved MCP server endpoints, potentially reducing reachability to malicious servers on unauthorized infrastructure or expired domains.
Control: Zero Trust Segmentation
Mitigation: Identity-scoped access controls would likely restrict the scope of credentials available to AI agents, potentially limiting the privilege level of tokens that could be exposed to malicious MCP servers.
Control: East-West Traffic Security
Mitigation: Microsegmentation between cloud workloads would likely constrain lateral movement paths, potentially limiting attacker reach even when using compromised AI agent credentials to access backend systems and additional cloud resources.
Control: Multicloud Visibility & Control
Mitigation: Network visibility controls would likely provide enhanced monitoring of MCP communication patterns, potentially enabling detection of anomalous command channels even when disguised as legitimate agent-server traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely restrict data flows to foreign jurisdictions, potentially limiting exfiltration paths even when attackers attempt to use legitimate MCP communication channels to bypass traditional data loss prevention controls.
While segmentation controls may limit the scope of affected systems, compromised AI agents could still impact business operations and data integrity within their authorized access boundaries, though with reduced blast radius.
Impact at a Glance
Affected Business Functions
- AI Agent Workflows
- Data Processing Pipelines
- Enterprise Software Development
- Third-Party Integration Management
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of enterprise data through unvetted MCP servers including 15.6% hosted outside the US, with 19 servers in China and 18 in Russia. Risk includes corporate data, proprietary information, and sensitive business communications processed by AI agents connecting to these servers.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate AI agents and MCP communications within secure network boundaries
- • Deploy egress security controls to monitor and filter outbound MCP traffic to prevent data exfiltration to unauthorized jurisdictions
- • Enable multicloud visibility and anomaly detection to identify suspicious MCP server interactions and malformed requests
- • Establish encrypted traffic inspection capabilities to analyze MCP protocol communications for malicious payloads
- • Create governance policies for AI agent deployments including MCP server vetting, code signing, and origin verification requirements



