Reco’s State of Agent Security 2026 found that 80% of enterprise AI tools operate without IT oversight, with SMBs estimated to use 414 unsanctioned AI tools per 1,000 employees. The ungoverned deployments create material visibility, identity, access-control, and data-exfiltration risks as employees connect AI services and agents to enterprise data and systems outside established security controls.
Reco’s review of 500 npm-hosted Model Context Protocol (MCP) servers found many exposed remotely without authentication and capable of shell execution, local-file access, and outbound network connections—permissions that prompt-injection attacks could abuse to steal data or compromise systems. The company also identified 637 vulnerabilities affecting AI agents and LLM tools, including 525 disclosed in the previous 18 months and at least 111 rated critical; it urged organizations to inventory AI tools and integrations, reduce unnecessary OAuth scopes, vet marketplace tools, and retain an emergency kill switch for each agentic tool.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Reco released its State of Agent Security 2026 report, based on enterprise telemetry, an analysis of 500 npm-hosted MCP servers, and National Vulnerability Database records. The report found that 80% of enterprise AI tools operated without IT oversight and highlighted risky MCP server capabilities and growing AI-related vulnerability disclosures.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.