📊 Key Data
  • 8,000+ publicly accessible MCP servers exposed to unauthenticated queries
  • 80% of organizations expected to have AI agents consuming the majority of APIs by 2028
  • 50% of API security breaches projected to be tied to AI exploitation by 2028
🎯 Expert Consensus

Experts agree that securing autonomous AI agents requires integrated solutions like the CrowdStrike-Salt Security partnership, combining endpoint telemetry with API logic analysis to monitor and contain AI-driven risks.

about 10 hours ago
The MCP Dilemma: How CrowdStrike and Salt Security Are Securing the Silicon Workforce

The MCP Dilemma: How CrowdStrike and Salt Security Are Securing the Silicon Workforce

PALO ALTO, Calif. – September 16, 2026 – Enterprise artificial intelligence has fundamentally crossed the Rubicon. The era of passive generative AI—where models simply answered questions or drafted emails—has been rapidly eclipsed by the deployment of autonomous agentic systems. These AI agents hold credentials, invoke internal APIs, and take consequential actions on behalf of human users. Yet, as these silicon workers are granted the keys to the corporate kingdom, they have introduced severe, systemic blind spots into enterprise security perimeters.

Today, Salt Security announced an expanded integration with the CrowdStrike Falcon platform, a move designed to illuminate and control this rapidly expanding attack surface. By embedding its Agentic API platform directly into CrowdStrike Falcon Foundry, Falcon Next-Gen SIEM, and Falcon Firewall Management, Salt is bridging the critical gap between endpoint execution and AI application logic. The partnership complements CrowdStrike’s native AI Detection and Response (AIDR) capabilities, offering a unified mechanism to govern the underlying architecture of autonomous AI: the Model Context Protocol (MCP).

The Rise of the Silicon Workforce and the MCP Blind Spot

To understand the significance of this integration, one must examine the mechanics of how modern AI agents interact with enterprise data. Autonomous agents do not execute tasks by talking; they do so by calling APIs and utilizing the Model Context Protocol. Developed and open-sourced by Anthropic, MCP functions as a universal translator—a digital USB-C port that decouples model logic from proprietary integrations, allowing agents to access local file systems, enterprise databases, and external third-party software.

However, while MCP solved massive integration fragmentation for developers, it introduced profound operational vulnerabilities. Official MCP SDKs have historically struggled with default standard I/O (STDIO) process execution without strict parameter sanitation, exposing hosts to arbitrary remote code execution. Furthermore, the protocol's optional authorization profiles have led to staggering exposures. Recent internet-wide scans documented over 8,000 publicly accessible MCP servers bound to open interfaces, responding to unauthenticated queries.

This creates a playground for indirect prompt injection and "confused deputy" attacks. In a widely documented exploit vector, an attacker can post an issue containing hidden injection instructions on a public repository. When an internal corporate AI agent is instructed to scan issues via its MCP server, the model blindly follows the untrusted external instruction, leveraging its authenticated access to exfiltrate private code.

"Most enterprises can tell you which AI agents they have approved. Far fewer can follow the full path those agents take once they begin acting across the business," said Roey Eliyahu, co-founder and CEO at Salt Security. "An agent may start with a legitimate prompt, but risk can emerge later through an over-permissioned tool, an MCP connection, or an API call. By combining Salt's Agentic API capabilities with the power of the AI-native Falcon platform, we're giving joint customers deeper visibility and control over agent activity across the enterprise."

Bypassing the Proxy: The Mechanics of Integration

For Chief Information Security Officers (CISOs), the operational hurdle of securing AI has been deployment friction. Traditional API security platforms require inline reverse proxies, sidecars, or network tapping gateways. In highly distributed, agent-driven environments, these architectural chokepoints introduce unacceptable latency and operational overhead.

The Salt and CrowdStrike integration circumvents this entirely by utilizing CrowdStrike Falcon Foundry. Through a certified application, joint customers can deploy Salt’s sensor module using their existing Falcon endpoint sensor. Utilizing CrowdStrike’s Real Time Response (RTR) engine, the deployment requires no additional network gateways.

Once active, Salt provides a dual-engine visibility layer. Its Agentic Security Posture Management (AG-SPM) continuously scans code repositories and external perimeters to inventory MCP tools, permissions, and exposed endpoints. Simultaneously, its runtime detection engine monitors live tool execution calls and JSON-RPC payloads, building a behavioral baseline of normal agent activity.

These findings are not siloed. They stream directly into CrowdStrike Falcon Next-Gen SIEM, where agent discovery metadata and behavioral anomalies are correlated with Falcon’s existing endpoint, identity, and cloud telemetry. When Salt detects an anomaly—such as an internal agent suddenly querying a sensitive financial database outside its established baseline—it triggers an automated containment workflow. Through Falcon Firewall Management, SecOps teams can push dynamic host-level firewall policies to instantly sever network communication to the rogue MCP server, all without taking down the underlying host system.

The Venture-to-Platform Pipeline

Beyond the technical mechanics, today's announcement highlights a broader strategic shift in cybersecurity market dynamics: the rapid consolidation of specialized AI governance into massive endpoint protection platforms.

The relationship between these two companies did not materialize overnight. In 2022, CrowdStrike’s strategic investment vehicle, Falcon Fund, participated in Salt Security's funding rounds. This venture-to-platform pipeline is a calculated playbook. CrowdStrike recognizes that as AI agents proliferate, runtime execution on the endpoint remains the ultimate control plane. Rather than yielding the API and MCP security market to standalone startups, CrowdStrike is incubating specialists and weaving their deep protocol dissection capabilities directly into the Falcon fabric.

This creates a formidable division of labor. CrowdStrike’s flagship Falcon Guardian handles local OS process execution, memory monitoring, and sub-millisecond prompt injection detection. Salt Security layers on deep API payload inspection, comprehensive MCP server discovery, and sensitive data schema mapping. For enterprise buyers suffering from acute sensor fatigue, the ability to activate best-of-breed agentic security through an existing CrowdStrike contract and sensor footprint is highly compelling.

Governing the Unsupervised Insider

The urgency for this unified approach is underscored by stark market projections. Industry analysts at Gartner forecast that by 2028, 80% of organizations will see AI agents consume the majority of their APIs, completely overtaking human developer traffic. Furthermore, over half of API security breaches are expected to be directly tied to AI exploitation.

Security operations centers are currently facing a daunting transition. Analysts who spent the last decade triaging human-centric phishing alerts and credential stuffing attacks must now monitor autonomous agent swarms operating at machine speed. The phenomenon of "shadow agents"—where employees deploy unvetted AI tools or local MCP servers to connect coding assistants to corporate repositories—means that the perimeter has already been bypassed.

Standard Web Application Firewalls cannot identify if an AI agent, properly authenticated via OAuth, has been hijacked via prompt injection to exfiltrate database records through a standard REST API. It requires a correlated timeline that maps the initial endpoint process, the user identity, the tool call dispatched over MCP, and the downstream API payload.

By fusing Salt Security’s granular API logic analysis with CrowdStrike’s ubiquitous endpoint telemetry and automated firewall containment, enterprises are finally being handed a playbook to govern their silicon workforce. As autonomous agents take on increasingly critical roles within the global economy, the ability to monitor, trace, and instantly contain their actions is no longer an experimental luxury—it is a foundational requirement for corporate survival in the AI era.

Topics & Related

Sector:
Cybersecurity
Theme:
Agentic AI
Event:
Partnership

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 50357