Threat · curated 14 Jul 2026
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials
First reported sans.edu
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
MCP-aware reconnaissance in the wild means exposed AI-agent infrastructure is being actively hunted, so defenders should assume any internet-facing MCP endpoint or AI assistant credential store will be discovered and probed for tool enumeration and abuse.
A SANS ISC diary by Manuel Humberto Santander Peláez reports that analysis of 14 days of Apache/ModSecurity logs from a small web host revealed distributed internet scanning specifically targeting Model Context Protocol (MCP) servers, AI assistant configuration files, and locally exposed LLM endpoints. Notably, the POST /mcp probes carried valid JSON-RPC 2.0 MCP 'initialize' handshakes from 49 distinct source IPs, indicating scanners that speak the protocol and would enumerate tools and data sources if a real MCP server responded.