The Model Context Protocol (MCP) is transforming how large language models interact with tools, data, and internal systems, but this new integration layer also opens up an attack surface that many teams don't yet understand. In this talk, we'll explain in simple terms how MCP works, what makes it powerful, and why it introduces unique risks that don't exist in traditional APIs. We'll review real-world attacks such as prompt injection, tool poisoning, credential leakage, and supply chain attacks, demonstrating how an attacker can manipulate the model to execute malicious code or access sensitive information.