Fetching from the wire…
Public story · 2026-07-18 · high
Stars and verification badges showed no reliable link to whether a server was actually safe to run, per the audit.
Why now: The count comes from coverage dated July 18 and is sourced to GBHackers, with enough detail to stand as its own story.
An audit flagged 5,832 of 9,695 MCP servers for security issues, per GBHackers. Of those, 2,259 held exploitable bugs that go past a missing login check: arbitrary file access, command injection, SSRF, SQL injection. That's close to a quarter of every server the researchers pulled from popular directories.
The audit's other finding should change your shopping list: stars, commit activity, and verification badges did not reliably correlate with security posture. Those are the exact signals most developers use to decide which server to trust.
A separate framework, MCPPrivacyDetector, checked more than 10,000 real-world servers and found credentials, API keys, and personal data leaking at rates above 10%. Two different methodologies landed on the same conclusion: the ecosystem shipped fast and skipped the step where someone checks what these servers can touch.
The audit doesn't say which directories carry the worst servers, or whether the 2,259 exploitable ones cluster in file-system or database connectors. Until that breakdown exists, I'd read the source of any server before installing it, badge or no badge.
A related report this cycle found permission systems failing open at the parser layer instead of the policy layer. Same root problem: nobody's checking what the code can actually do before access is granted.
Each link below shares sources, entities, or timing with this story.
A large-scale audit across popular MCP directories found security issues in 5,832 of 9,695 servers, with 2,259 containing exploitable vulnerabilities that go beyond simple auth gaps: arbitrary file access, command injection, SSRF, SQL injection. GBHackers has the writeup. A se...
Zero Day Initiative scanned 19,000 servers and put 600 to 1,650 as exploitable, with 42% of vulnerable repos tracing to code AI coding tools wrote.
CrowdStrike's 2026 Global Threat Report shows 89% YoY increase in AI-enabled attacks, with average breakout time falling to 29 minutes (65% faster than 2024). Fastest recorded: 27 seconds. Data exfiltration began within 4 minutes in one case. Critically for builders: attackers...
1. Bloomberg — Claude/Mexico breach 2. The Hacker News — RoguePilot 3. AI Journal — Terra Security / CVE-2026-25724 4. GBHackers — CrowdStrike 2026 report 5. TechCrunch — Cowork plugins 6. Axios — xAI Grok Pentagon 7. HuggingFace — HyperNova 60B 8. METR — AI tools developer study
Two of the 11 bugs paid real bounties, $10,000 from Microsoft and $3,133.70 from Google.
The two judges scoring these 14,560 attacks disagreed by more than 3x on how often DeepSeek's agent partially complied.
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.