Hush Security Finds Hardcoded Secrets in 12% of Public MCP Credential Slots
Hush Security found hardcoded secrets in 12% of credential slots across roughly 82,000 public Model Context Protocol configuration files, the company said in a press release. The files were used by coding agents including Claude Code, Cursor, VS Code, Windsurf, Gemini, OpenAI Codex and JetBrains.
The exposed credentials included GitHub personal access tokens, Anthropic and OpenAI API keys, Slack and Notion workspace tokens, and database connection strings with embedded passwords. Hush said 55% of the secrets lacked recognizable token patterns used by tools such as gitleaks and GitHub secret scanning.
Among credentials with a defined scope, 53% provided access across an organization, account, workspace or database. Of those with a defined expiry policy, 80% did not expire by default. Hush also found 1,394 secrets in current files and 243 deleted secrets that remained accessible through Git history.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly, AI Programming Weekly or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Sep 17 Carbon 9 Defense Wins 2026 Splunk Public Sector Partner Award Sep 17 Amplifier Security Adds AI Agent Controls to Workforce Security Platform Sep 16 AWS MSP Validation Checklist 8.0 Adds 24 AI Controls Sep 16 Footprint Raises $25 Million for AI Compliance Platform Sep 16 Quest Software Expands Identity Security for Rogue AI AgentsCybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Industry analysis
2025 Global Business Services Agenda: Gen AI Takes Center Stage
This industry analysis by The Hackett Group explores the transformative impact of generative artificial intelligence (Gen AI) on global business services (GBS) in 2025. The study highlights the shift from exploration to acceleration of Gen AI initiatives, with 89% of executives advancing these projects to improve customer satisfaction, innovate products, and reduce costs. The report also discusses the challenges and strategies for successful Gen AI adoption, emphasizing the need for a technology-enabled operating model and the importance of reskilling the workforce.
Read moreYou may also like
US Agencies Accuse Chinese AI Firms of Industrial Scale Model Distillation
Anthropic Assesses Four Incidents Where Claude Models Reached the Real Internet
Senate Opens Inquiry Into OpenAI Agents' Hugging Face Hack
Anthropic Attributes Its Largest Measured Distillation Campaign to Alibaba
Harness Survey Finds AI Agent Controls Lag Enterprise Confidence
Daily AI Brief: the AI news that matters, in your inbox.