What happened
Attackers sent unauthenticated requests to the /mcp_message endpoint on internet-exposed nginx-ui instances. With no credentials required (empty whitelist = allow-all), all 12 privileged MCP tools were accessible. Active exploitation confirmed with PoC published.