Skip to content

Karios

Tech news

Support me 1

Gaming History Podcast (GR)

  • Gaming History – Επεισόδιο 27 – Sega Dreamcast
  • Gaming History – Επεισόδιο 26 – Psygnosis
Primary Menu
  • Home
  • Books
  • Shop
    • Browse Shop
    • Cart
    • Checkout
    • Orders
    • Account details
    • Lost password
  • Articles
    • All Articles
    • Games
    • DIY
    • Retro
  • Gaming History Podcast (GR)
  • Contact me
  • News

MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of

admin Posted on 16 hours ago 2 minutes read
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

​Trust gaps in the new protocol spread malicious prompts from one agent to another. 

The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.

In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions.

Unexpected and hard to mitigate

Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government’s interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol. The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action.

Read full article

Comments

 Ars Technica – All content Read More

About The Author

admin

See author's posts

Post navigation

Previous: Cable lobby to sue Trump FCC over repeal of national TV ownership cap
Next: Licensing costs driving 90 percent of VMware users to explore options: Survey

Related

OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
  • News

OpenAI agents tried to hack Wikipedia tools and flooded it with traffic

admin Posted on 2 hours ago
Licensing costs driving 90 percent of VMware users to explore options: Survey
  • News

Licensing costs driving 90 percent of VMware users to explore options: Survey

admin Posted on 2 hours ago
Cable lobby to sue Trump FCC over repeal of national TV ownership cap
  • News

Cable lobby to sue Trump FCC over repeal of national TV ownership cap

admin Posted on 18 hours ago

Listen on Apple Music

You may have missed

OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
  • News

OpenAI agents tried to hack Wikipedia tools and flooded it with traffic

admin Posted on 2 hours ago
Licensing costs driving 90 percent of VMware users to explore options: Survey
  • News

Licensing costs driving 90 percent of VMware users to explore options: Survey

admin Posted on 2 hours ago
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
  • News

MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of

admin Posted on 16 hours ago
Cable lobby to sue Trump FCC over repeal of national TV ownership cap
  • News

Cable lobby to sue Trump FCC over repeal of national TV ownership cap

admin Posted on 18 hours ago

If you are located in Europe, you can buy my new sci-fi fantasy book “Ground Zero” directly from me for a better price than Amazon.