Model Context Protocol (mcp) Servers - Tool

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
October 31, 2025
Last Seen
February 12, 2026

Model Context Protocol (mcp) Servers is a tool tracked across 5 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity February 12, 2026.

Overview

Model Context Protocol (mcp) Servers are infrastructure that host and manage model contexts for AI-driven tools and agents, serving as a protocol-layer backbone for cross-agent interactions. Based on recent AI-security reporting, context handling and code-execution features create high-value attack surfaces, making MCP servers a significant risk vector in enterprise cybersecurity.

Related Threat Clusters

  • Claude AI Vulnerability Allows Data Theft via Code Interpreter Exploit

    A vulnerability in Anthropic’s Claude AI has been identified, allowing attackers to exploit the code interpreter feature to exfiltrate sensitive enterprise data. Security researcher Johann Rehberger demonstrated that…

    1 article · Updated November 4, 2025
  • Emergence of Agentic AI Raises Governance and Security Challenges

    In 2026, the rise of agentic AI is transforming how businesses operate, particularly in the financial services sector. This new technology allows for autonomous decision-making, which increases the potential impact of…

    3463 articles · Updated February 10, 2026
  • Rise in AI Model Theft and Misuse by Threat Actors

    Google's Threat Intelligence Group (GTIG) reports an increase in attempts to extract and replicate AI model logic, with state-backed and financially motivated attackers leveraging generative AI for reconnaissance,…

    13 articles · Updated February 12, 2026
  • Chinese Hackers Utilize AI for Cyberattacks on US Companies

    Chinese hackers have leveraged artificial intelligence tools to conduct cyberattacks, with Anthropic, a major US company, reporting a recent incident. The attacks utilize AI models capable of writing code, scanning…

    14 articles · Updated November 29, 2025
  • Claude AI Vulnerability Allows Data Exfiltration via Code Interpreter

    A vulnerability in Anthropic’s Claude AI has been identified, allowing attackers to exploit the code interpreter feature through indirect prompt injection. This exploit enables the extraction of sensitive user data,…

    2 articles · Updated November 4, 2025

Recent Intelligence Reports

  • Google report exposes ways threat actors use AI to speed up attacks — Sdxcentral · February 12, 2026
  • Proofpoint Acquires Acuvity to Deliver AI Security and Governance Across the Agentic Workspace — Proofpoint · February 12, 2026
  • Agentic AI Security: Keep Your Cyber Hygiene Failures from Becoming a Global Breach — Tenable · December 1, 2025
  • Claude AI vulnerability exposes enterprise data through code interpreter exploit — Csoonline · October 31, 2025

CVSS v3.1 Breakdown