OX Security

19 stats3 reports

All Statistics

15.6% of analyzed MCP hostnames (796 of 5,095) resolve outside the United States, including 19 in China and 18 in Russia.

Data ResidencyAI InfrastructureCloud Governance

About 0.45% of analyzed MCP hostnames are proxied through home networks and consumer tunneling services.

AI InfrastructureConsumer NetworksOperational Risk

2.3% of analyzed MCP hostnames no longer resolve.

Domain SecurityAI InfrastructureOperational Risk

Insurance organizations have the highest proportion of critical findings at 1.76%.

InsuranceCritical Findings

After prioritization, the average organization manages 795 critical findings, up from 202 the prior year (nearly quadrupling).

Application SecurityCritical FindingsPrioritization

Average raw alerts per organization are 865,398, a 52% increase from 569,354.

Application SecurityRaw Alerts

40-50% of AI-generated code inflates coverage metrics with meaningless tests rather than validating logic.

AIAI Risks

90-100% of AI-generated code contains excessive inline commenting, which dramatically increases computational burden and makes code harder to check.

AIAI Risks

60-70% of AI-generated code lacks deployment environment awareness, generating code that runs locally but fails in production.

AIAI Risks

Six previously resolving MCP hostnames were unregistered and available for purchase for $4 to $12 per year.

Domain SecuritySupply Chain RiskAI Infrastructure

High Business Priority is the most frequent risk-elevating factor at 27.76%, followed by PII Processing at 22.08% and CVSS High Severity at 20.55%.

Application SecurityVulnerability Scoring

Critical findings constitute 0.092% of raw findings, up from 0.035%.

Application SecurityCritical Findings

80-90% of AI-generated code rigidly follows conventional rules, missing opportunities for more innovative, improved solutions.

AIAI Risks

80-90% of AI-generated code creates hyper-specific, single-use solutions instead of generalizable, reusable components.

AIAI Risks

80-90% of AI-generated code generates functional code for immediate prompts but never refactors or architecturally improves existing code.

AIAI Risks

40-50% of AI-generated code reimplements from scratch instead of using established libraries, SDKs, or proven solutions.

AIAI Risks

70-80% of AI-generated code violates code reuse principles, causing identical bugs to recur throughout codebases, requiring redundant fixes.

AIAI Risks

20-30% of AI-generated code over-engineers for improbable edge cases, causing performance degradation and resource waste.

AIAI Risks

40-50% of AI-generated code defaults to tightly-coupled monolithic architectures, reversing decade-long progress toward microservices.

AIAI Risks