Cyber Defence Digest
Publication Date: 1 July 2026Coverage Period: May – June 2026
This special edition highlights emerging security risks associated with the Model Context Protocol (MCP), AI agents, connected tools, and enterprise AI integrations. As organisations increasingly adopt AI-powered workflows, securing MCP ecosystems has become a key operational priority.
⚠ Untrusted MCP Servers
Risk Level: 🔴 CriticalAffected: MCP Clients & AI Agents
How: AI assistants connected to untrusted MCP servers may receive malicious tools or manipulated data capable of influencing AI behaviour.
Impact: Enterprise data leakage | Credential exposure | Supply-chain compromise
Defence: Connect only to trusted MCP servers, verify server identity, restrict available tools, and continuously monitor server activity.
Reference: Model Context Protocol Specification
⚠ Excessive Tool Permissions
Risk Level: 🔴 CriticalAffected: Enterprise AI Agents
How: AI agents granted unrestricted access to email, cloud storage, source code, databases, or browsers can perform unintended actions if compromised or manipulated.
Impact: Unauthorised actions | Data exposure | Business process abuse
Defence: Apply least privilege, require user approval for high-risk actions, and review permissions regularly.
Reference: Enterprise AI Security Best Practices
⚠ Prompt Injection Through MCP Integrations
Risk Level: 🟠 HighAffected: MCP-enabled Applications
How: Hidden instructions embedded within emails, documents, web pages, or retrieved content manipulate AI behaviour through connected MCP tools.
Impact: Incorrect AI actions | Information disclosure | Automation abuse
Defence: Treat external content as untrusted, validate retrieved information, isolate high-risk workflows, and implement user confirmation for sensitive actions.
Reference: OWASP Top 10 for LLM Applications
⚠ Malicious MCP Tool Supply Chain
Risk Level: 🟠 HighAffected: MCP Tool Ecosystem
How: Compromised or malicious MCP tools may return manipulated responses, execute unauthorised operations, or exfiltrate enterprise information.
Impact: Supply-chain compromise | Persistent access | Sensitive data theft
Defence: Install MCP tools only from trusted publishers, verify updates, digitally sign internal tools, and continuously monitor tool activity.
Reference: Software Supply Chain Security Guidance
⚠ Identity and Secret Management
Risk Level: 🟠 HighAffected: MCP Servers & Connected Services
How: Poor management of API keys, OAuth tokens, and service credentials increases the risk of unauthorised access to connected enterprise systems.
Impact: Account compromise | Lateral movement | Cloud service abuse
Defence: Store secrets securely, rotate credentials regularly, implement short-lived tokens, and monitor authentication activity.
Reference: Identity Security Best Practices
⚠ Enterprise Governance for MCP
Risk Level: 🟡 AdvisoryAffected: Enterprise AI Deployments
How: Rapid adoption of MCP without governance may introduce unmanaged AI integrations and excessive trust between AI agents and enterprise services.
Impact: Compliance risks | Operational disruption | Increased attack surface
Defence: Maintain an inventory of MCP servers and tools, implement Zero Trust principles, log AI activity, and conduct regular security assessments.
Reference: NIST AI RMF | Enterprise AI Governance