Model Context Protocol (MCP) servers are increasingly being adopted by Security Operations Center (SOC) teams to streamline threat intelligence workflows and enhance incident response capabilities. MCP servers enable AI agents to translate natural-language queries into structured tool interactions, allowing analysts to efficiently gather and correlate data from multiple sources without the need to manually switch between disparate platforms. This integration helps SOC teams investigate infrastructure, identify critical incidents, retrieve indicators of compromise (IOCs), and detect phishing domains from a unified interface, thereby accelerating triage and improving visibility across the threat landscape. The operational benefits of MCP servers are significant, as they reduce manual enrichment tasks and operational friction, enabling faster and more accurate responses to security incidents. However, the rapid adoption of MCP technology has introduced new security challenges, as the protocol was designed primarily for functionality rather than security. Security controls and frameworks for MCP are still in their infancy, leaving organizations exposed to both traditional and novel attack vectors. Recent security assessments have revealed that a substantial proportion of MCP server implementations are vulnerable to classic web application threats, including command injection, SQL injection (SQLi), server-side request forgery (SSRF), and directory traversal. Specifically, one assessment found that 43% of popular MCP server implementations contained command injection vulnerabilities, 22% allowed directory traversal or arbitrary file read, and 30% were susceptible to SSRF attacks. These vulnerabilities provide attackers with new entry points into organizations that have integrated MCP-based applications into their workflows. The security community is actively researching these risks, but the evolving nature of MCP means that new vulnerabilities may continue to emerge as the technology matures. Organizations are advised to approach MCP adoption with caution, ensuring that security considerations are prioritized alongside operational benefits. The combination of increased efficiency for SOC teams and the emergence of new attack surfaces underscores the need for robust security controls, regular vulnerability assessments, and ongoing monitoring of MCP server deployments. As agentic AI systems become more prevalent in business environments, the balance between innovation and security will be critical to maintaining resilient security operations. SOC teams must remain vigilant, leveraging the advantages of MCP servers while proactively addressing the associated risks to safeguard their organizations against evolving threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
SOCRadar published a blog outlining 10 threat intelligence use cases for MCP servers in SOC operations, including investigations into malicious IPs, phishing domains, credential leaks, ransomware infrastructure, and state-sponsored campaigns. The post highlights operational use of MCP for consolidating and automating threat intelligence workflows.
Akamai released a security blog post describing how to prevent command injection and SQL injection attacks in MCP-related environments. The publication marks a technical disclosure and defensive guidance event around MCP security risks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.