|

Why MCP servers are becoming AI’s newest attack surface

As AI adoption gathers tempo, so does the evolution of the infrastructure that helps it. New requirements and connectors hold showing, and those that catch on unfold via the ecosystem inside months somewhat than years. That velocity strengthens what AI can do, however makes it very troublesome for safety groups to take care of adequate protections.

MCP servers are a primary instance. MCP turned the popular customary for connecting AI brokers to exterior instruments and knowledge inside 12 months of publication, and by December 2025 had been being utilized by each main coding assistant and most main LLMs. As a protocol, MCP has grown sooner than most infrastructure requirements, a rarity within the high-competition LLM house. This adoption curve validated MCP as Anthropic’s protocol of alternative for agent-tool connections, however safety options aren’t maintaining.

Various cybersecurity distributors are constructing merchandise to shut that hole. Many of them describe what they’re constructing as an “AI firewall,” however that time period is doing double obligation proper now. One which means is an older, AI-powered firewall that defends a community in opposition to typical threats like malware and intrusion. The different, newer which means, and the one we’ll concentrate on right here, is a firewall constructed particularly to defend AI itself: its fashions, brokers, and the instruments they hook up with, from threats like immediate injection and knowledge leakage. Check Point’s AI Network Firewall, launched in July 2026, belongs to this second class.

Nowhere is the necessity for AI firewalls extra seen proper now than with MCP servers, the connectors that allow AI brokers attain exterior instruments and knowledge, and the fastest-growing piece of AI infrastructure that such a firewall now has to take care of.

How MCP turned AI’s default connector customary in a few yr

The progress of MCP servers has been astonishing. Anthropic launched MCP as an open customary in November 2024. In December 2025, Anthropic introduced that greater than 10,000 active public MCP servers had been now working, with deployment help from AWS, Google Cloud, Azure, and different suppliers. All the main AI platforms and coding assistants, together with ChatGPT, Gemini, Microsoft Copilot, Cursor and Visual Studio Code, now use MCP.

This speedy progress is basically as a result of actual want for a standardised connection between AI techniques and exterior instruments and knowledge. The key benefit of an MCP server is that it permits AI brokers, assistants, and coding instruments to make use of a single interface to attach securely with a number of instruments and knowledge sources, as a substitute of needing a customized connector.

But MCP introduced an entire new attack surface together with these benefits, at a velocity that vastly outpaces any supporting safety community. Existing AI defenses aren’t constructed for conditions the place AI brokers dynamically entry instruments and delicate techniques, and as we’ll see, analysis findings present simply how huge that hole truly is.

What truly goes flawed when an MCP server has a weak spot

OWASP, the Open Worldwide Application Security Project, has specified quite a few serious threats that can affect MCP servers. Tool poisoning is a chief concern, taking immediate injection up a degree by embedding malicious directions in software descriptions, schemas, or software return values and utilizing them to govern agent behaviour.

Rug pull assaults are distinctive to the rising AI ecosystem. Here, an attacker modifications a software’s definition after a human has already accepted it, exploiting the belief that approval created. Tool shadowing and cross-origin escalation assaults work equally, with an attacker utilizing a malicious server’s software description to govern how an agent makes use of instruments belonging to a different, trusted server.

These vulnerabilities are not uncommon, both. An evaluation performed by Lakera, the AI safety firm Check Point acquired in 2025, reviewed 10,000 MCP servers and located that 40% carried exploitable weaknesses.

Other threats are acquainted however made extra sinister. Attackers use MCP servers for knowledge exfiltration by covertly inserting delicate data into in any other case professional software calls like searches and emails. Or they exploit the server’s broader permissions by granting it extra entry than the duty actually wants, creating a bigger publicity.

Why MCP safety shouldn’t be the identical as agent safety

While MCP safety is significant, it’s not the entire image. Connecting via MCP servers is only one of many ways in which AI brokers can attain the instruments and knowledge they want.

Securing them goes a good distance in the direction of stopping software poisoning, unauthorised entry, and knowledge breaches, but it surely’s not sufficient by itself. Agents can nonetheless work together with different techniques with out utilizing MCP in any respect.

This makes MCP safety only one thread in a broadly woven AI safety tapestry. When you take into account distributors for an MCP server safety resolution, that you must take a look at them inside the better context. It’s necessary to guage how successfully they safe MCP-specific interactions and dangers, however you’ll nonetheless want further controls to guard your AI ecosystem, so examine how effectively the answer integrates with the remainder of your safety stack.

Who is constructing for this hole proper now

The excellent news is that safety groups have choices. Various corporations provide safety options that embrace MCP servers and keep in mind their function in AI infrastructure. TrueFoundry’s AI Gateway offers infrastructure-layer governance, entry management, and auditing for interactions between MCP instruments and brokers. Cisco has prolonged its AI Defense product to incorporate agent-facing guardrails, MCP scanning, and real-time inspection of MCP site visitors, designed to detect and block unsafe conduct.

Check Point’s AI Network Firewall takes a distinct strategy. Its providing is network-centric, stitching AI safety into its clients’ current firewall infrastructure. The firewall addresses worker, AI utility, and AI agent interactions with MCP in addition to different connections between AI techniques and exterior knowledge and instruments. It discovers MCP servers, inspects MCP site visitors, and enforces insurance policies round agent entry.

Security tends to lag every time infrastructure scales this quick, and MCP is following the identical sample. We’re at the moment seeing distributors and organisations attempting out totally different options to an rising downside, whether or not that’s an AI-aware network-level firewall, infrastructure-level governance, or devoted AI guardrails. Which strategy wins out issues far lower than whether or not safety groups shut that hole earlier than an MCP-specific attack forces the problem.

The put up Why MCP servers are becoming AI’s newest attack surface appeared first on AI News.

Similar Posts