logo

Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)

ID: b4744526-e054-503d-a6cf-d1dfe9e45d52

STIX ID: report--b4744526-e054-503d-a6cf-d1dfe9e45d52

Feed Name: SANS ISC Diary

Threat Score
55/100

Date Published: 2026-07-13

Date Updated: 2026-07-13

...
...

A two-week log analysis found widespread, distributed scanning looking for exposed AI-agent infrastructure: valid MCP JSON-RPC handshakes to discover tools/data sources, targeted requests for AI-assistant config and credential files (e.g., /.claude/mcp.json, HEAD on .credentials.json), probes for unauthenticated LLM endpoints (GET /v1/models, GET /api/tags), and SSRF attempts against cloud metadata endpoints. The activity appears opportunistic but mature (multiple source IPs, efficient HEAD checks), so defenders should hunt for POST /mcp, block exposed model endpoints, prevent web-serving of developer config/credential files, and harden fetch-style endpoints and metadata protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.