How an Unauthenticated MCP Server Led to SSRF, LFI, and AWS Credential Theft
A real-world AIVigil finding from a customer environment. One unprotected AI integration endpoint with no login required. An attacker chained Server-Side Request Forgery, Local File Inclusion, and live AWS credential exfiltration into a potential full infrastructure takeover. This is how it happened, and how AIVigil found it first.
Written by
افتتاحية كلاودسك