Why MCP servers are becoming AI’s newest attack surface

| Source: AI News (ainews.com)

Tags: MCP, Model Context Protocol, Anthropic, Check Point, prompt injection, AI security, AI agents, cybersecurity

MCP hit 10,000+ active public servers by December 2025 — adopted by ChatGPT, Gemini, and every major coding assistant — while security tooling lags behind; vendors including Check Point now offer purpose-built AI firewalls defending agents against prompt injection and data leakage across MCP connections.

Details

Anthropic's Model Context Protocol, launched in November 2024, became the de facto standard for connecting AI agents to external tools and data sources in roughly 12 months. By December 2025, over 10,000 public MCP servers were active, backed by AWS, Google Cloud, and Azure, with every major AI platform — ChatGPT, Gemini, Microsoft Copilot, Cursor, and VS Code — integrated. The adoption speed is opening a security gap. Existing defenses were built for static systems, not for AI agents that dynamically query external tools and sensitive data at runtime. MCP's trust model assumes connected servers behave correctly, but attackers can embed prompt injection payloads in tool responses or exfiltrate data through compromised MCP servers — attack vectors that traditional firewalls do not cover. A new vendor category is emerging in response: AI firewalls purpose-built for AI infrastructure. These differ from conventional AI-powered network firewalls — instead of guarding networks against malware or intrusion, they protect AI agents, models, and tool connections from AI-specific threats. Check Point released its AI Network Firewall in July 2026 targeting this exact use case. The article is a market overview from AI News and names Check Point as one example; the full competitive landscape and specific technical mitigation approaches are not detailed in the available text.