Internet-wide reconnaissance is actively probing exposed AI infrastructure, with analysts observing systematic scans for Model Context Protocol (MCP) servers, AI assistant credential files, and unauthenticated model-serving endpoints. Over a two-week period, Apache and ModSecurity logs from a small web host recorded roughly 200 AI-related requests, including valid JSON-RPC 2.0 initialize handshakes sent to MCP services from 49 source IP addresses. The activity also searched for configuration and credential artifacts tied to tools such as Claude and Cursor, alongside checks for OpenAI-compatible /v1/models and Ollama /api/tags endpoints.
The probing went beyond simple path enumeration and showed attackers understand the targeted protocols and deployment patterns, suggesting opportunistic discovery of vulnerable AI environments at scale. The same activity included SSRF-style requests aimed at cloud metadata services and Kubernetes token locations, raising the risk that exposed agent tooling, MCP servers, or URL-fetching features could be abused to steal secrets, obtain cloud credentials, or pivot deeper into internal environments. Defenders were urged to review logs for MCP-related traffic, limit public exposure of AI services, secure assistant configuration files, harden fetch capabilities, and enforce metadata protections such as AWS IMDSv2 and required GCP metadata headers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
A two-week analysis of Apache and ModSecurity logs from a small web host found roughly 200 AI-related probe requests, including scanning for MCP servers, AI assistant credential files, exposed model endpoints, and SSRF targets. The observed activity came from multiple sources and indicated opportunistic internet-wide reconnaissance rather than a targeted intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.