Attackers are actively scanning for MCP servers — 49 distinct IPs probing over 14 days, and the new spec requires per-RFC-9207 issuer validation
The August 2026 MCP security digest (Aug 6) reports SANS ISC honeypot data of roughly 200 requests from 49 distinct source IPs hunting for MCP endpoints across fourteen days in July, alongside the MCP Specification 2026-07-28 which hardened authorization with issuer validation per RFC 9207 and header-based routing for policy enforcement. Two immediate actions it recommends cost minutes: grep your access logs for MCP endpoint paths, and verify your agent configuration files are not web-accessible. It also catalogs three research defenses worth tracking — ChainWatch (models MCP attacks as a six-stage kill chain, applying a Hidden Markov Model to tool-call sequences), SPELLSMITH (embeds security guidance directly into tool descriptions), and MTGuard (static plus dynamic analysis to block harmful invocations).
Source
↳ Follow the thread