InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

State of MCP Server Security 2025: What 5,200 Servers Reveal, and the Open-Source Fix You Can Use Today

Presented by

Tal Skverer, Head of Research at Astrix Security and Jonathan Sander, Field CTO

About this talk

MCP servers serve as the backbone that enables AI agents to access the tools, data, and context they need to operate. By connecting these agents to everything from internal APIs and databases to third-party SaaS systems, MCP turns isolated AI models into fully capable, action-driven agents. New research by Astrix Security analyzed more than 5,200 open-source MCP servers and surfaced systemic risks: 1. 53% rely on static API keys or PATs 2. Only 8.5% use OAuth applications 3. 79% pass keys via simple environment variables In this webinar, we will unpack the data, methodology, and what it means for your attack surface. To help tackle these challenges, Astrix introduces its new open-source MCP Secret Wrapper, a practical way to eliminate hardcoded credentials by fetching secrets from a vault at runtime. In this session, you will learn how to apply the wrapper for quick wins, how to enforce least-privilege and short-lived access at scale, and how to align with compliance without slowing down your teams.
Cloud Security Alliance: CloudBytes

Cloud Security Alliance: CloudBytes

80659 subscribers1017 talks
Educational series on cloud computing, security and privacy.
CSA CloudBytes was launched as a webinar series to help us educate the industry on all matters related to the cloud. Our channel is designed to inform our audience about trending topics, new technologies, and latest research. Learn more at cloudsecurityalliance.org. Join the Cloud Security Alliance on LinkedIn and follow us on twitter: @cloudsa
Related topics