Pluto finds 147 unauthenticated MCP servers open on the internet
Pluto’s Sept 24 research scanned public MCP endpoints and confirmed 147 of 179 findings accepted unauthenticated calls—including root exec shells, production SQL/CMS tools, and a Swiss municipal citizen workflow. Most still listen today; they recommend authenticating tools/call, scanning your own perimeter, and authorizing per tool.