New Research: MCP Servers Connect AI Agents to China, Russia, Home Networks and Abandoned Domains
NEW YORK, Sept. 24, 2026
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
New Research: MCP Servers Connect AI Agents to China, Russia, Home Networks and Abandoned Domains
PR Newswire
NEW YORK, Sept. 24, 2026
OX Security analysis of 15,465 published MCP servers reveals how AI agents are undermining a decade of cloud security governance, including connections to private home networks
NEW YORK, Sept. 24, 2026 /PRNewswire/ — OX Security today revealed that AI agents using Model Context Protocol (MCP) can connect to ungoverned infrastructure in China and Russia, home networks and abandoned domains, based on an analysis of 15,465 published MCP servers.
Of 5,095 unique hostnames analyzed, 15.6% resolved to infrastructure outside the United States, including 19 in China and 18 in Russia. Researchers also identified infrastructure associated with home networks and locally hosted machines using consumer tunneling services, as well as six abandoned domains available for registration for as little as $4.
The findings show how MCP is introducing a layer of AI infrastructure that sits outside the security and governance controls enterprises spent years building around their cloud environments.
Introduced by Anthropic in November 2024, MCP is an open standard that allows AI agents and applications to connect to external tools and data sources. But MCP itself does not establish where a server should run, who should operate it, what data it may receive, or whether the code deployed behind a live server matches its published source. Those decisions largely fall to the organizations and developers connecting to the servers.
“For the last decade, enterprises built cloud security around infrastructure they could see and control,” said Neatsun Ziv, cofounder and CEO of OX Security. “What this research shows is that AI agents are beginning to reach beyond those boundaries. As agents gain more access, more autonomy and more authority to act, the infrastructure they can reach becomes part of the security picture, whether enterprises control it or not.”
“Once we started to look at the core of marketplace MCP servers, we found that the security of each individual server and the whole infrastructure was a lot harder to validate than you might think,” said Moshe Siman Tov Bustan, Research Lead at OX Security. “You can inspect the code, but the server might contain a different version. Also, you don’t know who controls the server, what data they collect, or what they can change in future updates.”
Key Findings
- Data Residency Blind Spots: 15.6% of analyzed hostnames (796 of 5,095) resolved to infrastructure outside the United States, including 19 in China and 18 in Russia. MCP provides no protocol-level mechanism to enforce geographic boundaries or compliance.
- Enterprise Exposure Through Home Networks: 0.45% of analyzed hostnames routed through consumer ISP networks or personal tunneling tools, placing enterprise AI workflows outside centralized access controls and audit logging.
- Low-Cost Domain Takeover Paths: 2.3% of hostnames no longer resolved, including six unregistered domains available for purchase for $4 to $12 per year. Attackers could acquire these domains to impersonate original, trusted endpoints.
- Trust That Outlives the Original Permission: In security testing using Claude Code paired with Haiku 3.5, a malicious MCP server used prompt injection to turn a single “Always-Allow” permission for a benign file request into unauthorized access to a sensitive .env file without secondary user confirmation. The same attack was detected and blocked by Opus 4.6 and 4.7.
The findings show that MCP is creating connections to infrastructure whose location, operation and deployed code may not be governed or independently verified.
The complete report, “15,465 MCP Servers, 0 Governance,” including technical methodology and threat scenarios, is available at www.ox.security
About OX Security
OX Security is the first AI-native application security platform built to secure software from prompt to production runtime. Its platform includes VibeSec, OX Code, OX Cloud and OX Agentic Pentester. For more information, visit www.ox.security
View original content:https://www.prnewswire.com/news-releases/new-research-mcp-servers-connect-ai-agents-to-china-russia-home-networks-and-abandoned-domains-302888066.html
SOURCE OX Security


