Why MCP servers are becoming AI's newest attack surface
Discover how the rapid adoption of Model Context Protocol (MCP) servers has created a massive new attack surface for AI systems, posing severe security challenges.

Stock photo for illustration only, not from the actual event
- MCP became the preferred standard for connecting AI tools within just 12 months.
- Explosive growth has left security teams struggling to protect emerging AI infrastructure.
- OWASP highlights critical threats including tool poisoning, rug pull, and tool shadowing.
- Securing AI ecosystems requires a combination of AI firewalls and broad architecture controls.
As AI adoption gathers pace, so does the evolution of the infrastructure that supports it. New standards and connectors keep appearing, and the ones that catch on spread through the ecosystem within months rather than years. That speed strengthens what AI can do, but makes it very difficult for security teams to maintain sufficient protections.
MCP servers are a prime example of this phenomenon. MCP became the preferred standard for connecting AI agents to outside tools and data within 12 months of publication, and by December 2025 were being used by every major coding assistant and most leading LLMs. As a protocol, MCP has grown faster than most infrastructure standards, a rarity in the high-competition LLM space.

Stock photo for illustration only, not from the actual event
This adoption curve validated MCP as Anthropic’s protocol of choice for agent-tool connections, yet security solutions aren’t keeping up. The need for specialized AI firewalls is now highly visible, particularly with MCP servers acting as the connectors that let AI agents reach outside tools and data—making them the fastest-growing piece of AI infrastructure that this type of firewall must now contend with.
The growth of MCP servers has been astonishing. Anthropic launched MCP as an open standard in November 2024. In December 2025, Anthropic announced that more than 10,000 active public MCP servers were now running, with deployment support from AWS, Google Cloud, Azure, and other major providers. All leading AI platforms and coding assistants, including ChatGPT, Gemini, Microsoft Copilot, Cursor, and Visual Studio Code, now utilize MCP.
"This rapid growth is largely due to the real need for a standardised connection between AI systems and external tools and data."
AI News
The key advantage of an MCP server is that it allows AI agents, assistants, and coding tools to use a single interface to connect securely with multiple tools and data sources, instead of needing a custom connector. But MCP brought a whole new attack surface along with these advantages, at a speed that vastly outpaces any supporting security network. Existing AI defenses aren’t built for situations where AI agents dynamically access tools and sensitive systems.
From a cybersecurity perspective, when a new protocol scales faster than governance models, it creates what experts call a systemic blind spot. In the case of MCP, the emphasis on rapid developer integration often bypasses foundational vulnerability checks on tool descriptions and permission boundaries. This leaves AI agents prone to manipulation, effectively turning useful protocol connectors into primary vectors for data exfiltration and unauthorized system access.
OWASP, the Open Worldwide Application Security Project, has specified a number of serious threats that can affect MCP servers. Tool poisoning is a chief concern, taking prompt injection up a level by embedding malicious instructions in tool descriptions, schemas, or tool return values and using them to manipulate agent behaviour.
Rug pull attacks are unique to the emerging AI ecosystem. Here, an attacker changes a tool’s definition after a human has already approved it, exploiting the trust that approval created. Tool shadowing and cross-origin escalation attacks work similarly, with an attacker using a malicious server’s tool description to manipulate how an agent uses tools belonging to another, trusted server. An analysis conducted by Lakera, the AI security company Check Point acquired in 2025, reviewed 10,000 MCP servers and found that 40% carried exploitable weaknesses.

Stock photo for illustration only, not from the actual event
While MCP security is vital, it’s not the whole picture. Connecting through MCP servers is just one of many ways that AI agents can reach the tools and data they need. Securing them goes a long way towards preventing tool poisoning, unauthorised access, and data breaches, but it’s not enough on its own since agents can still interact with other systems without using MCP at all.
Fortunately, security teams have options. TrueFoundry’s AI Gateway provides infrastructure-layer governance, access control, and auditing for interactions between MCP tools and agents. Cisco has extended its AI Defense product to include agent-facing guardrails, MCP scanning, and real-time inspection of MCP traffic. Meanwhile, Check Point’s AI Network Firewall takes a network-centric approach, stitching AI security into customers' existing firewall infrastructure to discover MCP servers, inspect traffic, and enforce access policies.
Source: AI News
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment