Trend Micro: Exposed MCP Servers Nearly Triple to 1,467 — Attackers Now Compromising Host Cloud Services, Not Just Accessing Linked Data
Trend Micro's updated research shows exposed MCP servers surged from 492 to nearly 1,467 (roughly 3x), with a critical escalation: attackers are no longer limited to accessing data through MCP servers — they're now compromising the cloud services that host them. Attack chains include vulnerability exploitation, credential theft, lateral movement, and full cloud compromise. The research emphasizes that MCP servers acting as bridges for AI agents are being treated as cloud infrastructure attack surfaces. For builders: if you run MCP servers, treat them as production cloud infrastructure — network isolation, credential rotation, and monitoring are non-negotiable, not optional experimental tool configurations.
Source
↳ Follow the thread