Security News

AI Integration Tool 'MCP' Found Riddled with Governance Blind Spots

Infosecurity Magazine · 28 Sept 2026
Key Takeaway Before connecting AI tools to your business systems via MCP or similar protocols, review server permissions carefully and avoid blanket 'always-allow' approvals that can expose sensitive data.

Researchers at Ox Security have warned that Model Context Protocol (MCP) servers, which allow AI applications to connect easily to external tools and data, are creating a hidden governance gap in enterprise cybersecurity. Analysing over 15,000 MCP servers across public registries, the firm found nearly 16% of unique hostnames resolved to locations outside the US, including Russia and China, despite MCP having no built in concept of geographic region or data residency controls.

The report also found that more than 2% of analysed hostnames no longer resolved at all, meaning some domains were unregistered and could be bought by attackers to impersonate legitimate servers. Separately, testing on an AI coding assistant showed that once a user granted a single 'always-allow' permission to a server, it could then request and receive sensitive files, such as configuration files containing secrets, without further approval. This mirrors earlier findings from Backslash Security in June 2025, which identified hundreds of MCP servers exposed to local network attacks, some with severe flaws such as poor input validation and excessive permissions.

Together, these findings suggest that as businesses rapidly adopt AI tools built on MCP, security oversight is lagging well behind adoption, leaving gaps that traditional cloud security controls were designed to prevent.

Answering for this at board level? Our cyber governance framework ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.