AI News AI资讯 2h ago Updated 2h ago 更新于 2小时前 49

Why MCP servers are becoming AI's newest attack surface MCP 服务器为何成为 AI 最新攻击面

MCP (Model Context Protocol) became the dominant standard for connecting AI agents to external tools within 12 months of its November 2024 launch, with over 10,000 active public servers by December 2025 and support from all major cloud providers and AI platforms. The rapid adoption of MCP has created a significant security gap, with 40% of analyzed MCP servers found to carry exploitable weaknesses, including tool poisoning, rug pull attacks, and data exfiltration vectors. A new category of "AI f MCP协议在发布12个月内成为AI代理连接外部工具和数据的默认标准,至2025年12月已有超过10,000个活跃公共MCP服务器,被ChatGPT、Gemini、Copilot等主流平台集成 40%的MCP服务器存在可利用的安全弱点,OWASP定义了工具投毒、rug pull攻击、工具影子攻击等新型威胁向量 "AI防火墙"概念兴起,专指保护AI模型、代理及连接工具免受提示注入和数据泄露的防护方案,Check Point于2026年7月发布相关产品 安全厂商如Check Point、Cisco、TrueFoundry正在推出MCP服务器安全解决方案,涵盖流量检查、策略执行和基础设施层治理 MCP

70
Hot 热度
72
Quality 质量
68
Impact 影响力

Analysis 深度分析

TL;DR

  • MCP (Model Context Protocol) became the dominant standard for connecting AI agents to external tools within 12 months of its November 2024 launch, with over 10,000 active public servers by December 2025 and support from all major cloud providers and AI platforms.
  • The rapid adoption of MCP has created a significant security gap, with 40% of analyzed MCP servers found to carry exploitable weaknesses, including tool poisoning, rug pull attacks, and data exfiltration vectors.
  • A new category of "AI firewalls" is emerging to defend AI models, agents, and their tool connections from prompt injection and data leakage, distinct from traditional AI-powered network firewalls.
  • MCP security is only one component of a broader AI security strategy, as agents can interact with external systems through multiple pathways beyond MCP.
  • Security vendors including Check Point, Cisco, and TrueFoundry are releasing products to address MCP-specific threats, ranging from network-centric firewalls to infrastructure-layer governance and real-time traffic inspection.

Why It Matters

The explosive growth of MCP as the default connector standard for AI agents means that security infrastructure is struggling to keep pace with adoption, creating a widening vulnerability window that organizations must address. For AI practitioners and security teams, understanding these emerging threats and available defenses is critical to safely deploying agent-based systems that interact with external tools and sensitive data.

Technical Details

  • MCP launched as an open standard by Anthropic in November 2024 and achieved widespread adoption by December 2025, with 10,000+ active public servers supported by AWS, Google Cloud, and Azure, and integrated into ChatGPT, Gemini, Microsoft Copilot, Cursor, and VS Code.
  • Key attack vectors include tool poisoning (malicious instructions embedded in tool descriptions, schemas, or return values), rug pull attacks (post-approval modification of tool definitions), tool shadowing, and cross-origin escalation attacks, as categorized by OWASP.
  • Lakera's analysis of 10,000 MCP servers revealed that 40% contained exploitable weaknesses, with additional risks around data exfiltration through covert insertion of sensitive information into legitimate tool calls and excessive permission grants.
  • Emerging security solutions include Check Point's AI Network Firewall (network-centric, integrated with existing firewall infrastructure), Cisco's AI Defense extension (agent-facing guardrails and real-time MCP traffic inspection), and TrueFoundry's AI Gateway (infrastructure-layer governance, access control, and auditing).

Industry Insight

  • Organizations deploying AI agents should treat MCP security as a necessary but insufficient layer, evaluating solutions within the broader context of their AI security stack and ensuring integration with existing controls.
  • The "AI firewall" market is rapidly evolving with competing approaches—network-centric, infrastructure-layer, and agent-facing—requiring security teams to carefully assess which model aligns with their architecture and threat landscape.
  • The 40% vulnerability rate in MCP servers signals that the ecosystem is still immature from a security perspective, and teams should prioritize scanning, monitoring, and least-privilege access policies for any MCP servers they adopt.

TL;DR

  • MCP协议在发布12个月内成为AI代理连接外部工具和数据的默认标准,至2025年12月已有超过10,000个活跃公共MCP服务器,被ChatGPT、Gemini、Copilot等主流平台集成
  • 40%的MCP服务器存在可利用的安全弱点,OWASP定义了工具投毒、rug pull攻击、工具影子攻击等新型威胁向量
  • "AI防火墙"概念兴起,专指保护AI模型、代理及连接工具免受提示注入和数据泄露的防护方案,Check Point于2026年7月发布相关产品
  • 安全厂商如Check Point、Cisco、TrueFoundry正在推出MCP服务器安全解决方案,涵盖流量检查、策略执行和基础设施层治理
  • MCP安全仅是AI安全生态的一环,企业需将其整合到更全面的安全架构中,因为AI代理还可通过非MCP途径访问外部系统

为什么值得看

这篇文章揭示了AI基础设施安全领域的核心矛盾:技术采用速度远超安全防护能力。对于AI从业者和企业安全团队而言,理解MCP协议的安全风险及现有防护方案,对构建安全的AI代理生态系统至关重要。

技术解析

  • MCP(Model Context Protocol)由Anthropic于2024年11月作为开放标准发布,核心优势是允许AI代理通过单一接口连接多个工具和数据来源,无需定制连接器。至2025年12月获得AWS、Google Cloud、Azure支持,并被所有主流AI平台和编码助手集成。
  • OWASP识别的MCP特有威胁包括:工具投毒(在工具描述、schema或返回值中嵌入恶意指令)、rug pull攻击(人类审批后攻击者修改工具定义)、工具影子攻击和跨源升级攻击。Lakera对10,000个MCP服务器的分析显示40%存在可利用弱点。
  • Check Point AI Network Firewall(2026年7月发布)采用网络中心方法,集成到现有防火墙基础设施,具备MCP服务器发现、流量检查和策略执行能力,覆盖员工、AI应用和AI代理的交互。
  • Cisco AI Defense扩展了MCP扫描和实时流量检查功能,TrueFoundry AI Gateway提供基础设施层治理、访问控制和审计,三者代表了不同的安全架构思路。
  • 文章强调MCP安全不等于AI代理安全,代理还可通过非MCP途径访问外部系统,因此需要多层防护和与现有安全栈的整合。

行业启示

  • AI基础设施标准化进程加速(MCP在12个月内成为事实标准),安全厂商需快速响应新型威胁向量,企业应优先评估MCP服务器的安全风险并选择具备实时检测和策略执行能力的解决方案。
  • "AI防火墙"作为新兴安全品类正在形成,传统网络安全厂商(如Check Point、Cisco)通过扩展产品线进入该领域,反映了AI安全从应用层向基础设施层延伸的趋势。
  • 企业需建立全面的AI安全策略,将MCP防护与整体安全架构整合,避免单一防护盲区,同时关注OWASP等标准组织发布的MCP安全指南。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Agent Agent LLM 大模型 Deployment 部署