
KuppingerCole Analysts
Analyst Chat #317: MCP Is Just Another API, and That's the Bad News
MCP servers are showing up on the internet without authentication, malicious tool definitions are being injected into trusted projects, and three security teams are defending the same environment without sharing a single threat signal. In this week's episode, Matthias sits down with Alexei Balaganski, Lead Analyst and CTO at KuppingerCole Analysts, to dig into the real MCP security problem and why the answer isn't an MCP security product. Key Topics: β The LocalAI attack: 23 unprotected MCP servers, root access in minutes, military data exposed β Is MCP a new security problem or just a new label for old ones? β The Deadbugs attack: how tool descriptions were silently poisoned to manipulate AI agents β Who is responsible for MCP security: Anthropic, the vendor, or you? β Tool poisoning, prompt injection, and the gaps between AppSec, NetSec, and endpoint teams β Monday morning recommendations: what to actually do about MCP security right now "Models reason, APIs act, and identity grants the authority to act" Alexei Balaganski's one-line summary of why MCP security cannot be solved by a single tool or a single team. MCP is a symptom, not the disease, join KuppingerCole Analysts at the upcoming AIdentity & NHI Impact Day , CIAM Impact Day , and Identity-Centric Cybersecurity Summit events in Germany to continue this conversation in person.






