| |
Over 21,000 internet-facing MCP (Model Context Protocol) server instances are currently exposed, with 92% of production servers lacking basic OAuth authentication, according to recent security research. The vulnerability landscape has shifted from theoretical risk to systemic reality, creating tension between protocol designers and the security community, particularly over disagreements about the STDIO transport model's architecture—which Anthropic maintains is "by design" while security researchers argue represents a fundamental flaw. The recent transfer of MCP governance to the Linux Foundation provides a neutral venue to decide whether the protocol requires architectural hardening or if security should remain primarily a developer responsibility.
Read Full Article →
← More Tech news