TGViewer
Daily Security Daily Security @ethers_security · 4.02K subscribers
Post #360 671

Forwarded from AISecHub

State of MCP Server Security 2025: 5,200 Servers, Credential Risks - https://astrix.security/learn/blog/state-of-mcp-server-security-2025/

We analyzed over 5,200 unique, open-source MCP server implementations to understand how they manage credentials and what this means for the security of the growing AI agent ecosystem.

- 88% of MCP servers need credentials to function
- 53% rely on static API keys and Personal Access Tokens (PAT)
- Only 8.5% use modern OAuth authentication
- 79% store API keys in basic environment variables

#MCP #ModelContextProtocol #AIAgents #AgentSecurity #CredentialSecurity #SecretsManagement #OAuth #APIKeys #PATs #SecretRotation #LeastPrivilege #AstrixSecurity
Astrix Security State of MCP Server Security 2025: Research Report | Astrix 5K+ MCP servers analysis: 53% use insecure hard-coded credentials. Read the 2025 research and download the open-source MCP Secret Wrapper to mitigate risks.
  • ❤ 1
More from @ethers_security
  1. Sep 24, 2026photo post
  2. Sep 24, 2026🚨🚨Bitget wallets may have been hacked after $174 million moves across chains 🚨🚨 [sourc…
  3. Aug 8, 2026Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages Recommendation: • If you id…
  4. Aug 1, 2026Great resource to study AI and different types of AI vulnerabilities https://riskatlas.pri…
  5. Jun 9, 2026Claude Fable is out. As you can see, the new model claims to have been significantly impro…
  6. Apr 23, 2026PASSWORD MANAGER 'BITWARDEN' CLI WAS COMPROMISED IN A SUPPLY CHAIN ATTACK ⚠️ BITWARDEN CLI…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →