The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.
In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions.
Unexpected and hard to mitigate
Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government’s interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol. The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action.
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
October 6, 2026
Licensing costs driving 90 percent of VMware users to explore options: Survey
October 6, 2026
கேபிள் TV-க்கு ஒரே போடு.. 1000+ லைவ் டிவி சேனல்.. 1000 ஜிபி டேட்டா.. 10+ ஓடிடி சந்தா.. அன்லிமிடெட் வாய்ஸ்!
October 6, 2026
Jio, Airtel தலையில் இடி.. மாதம் ரூ.205 க்கு 365 நாட்கள் வேலிடிட்டி.. ரூ.1 லட்சம் காப்பீடு.. வாய்ஸ் கால்கள்!
October 6, 2026
ஏர்டெல்லின் செம்ம பிளான்.. பட்ஜெட் விலையில் தினமும் 4ஜிபி டேட்டா.. 18 OTT சந்தா.. வாய்ஸ் கால்கள்.. எஸ்எம்எஸ்!
October 6, 2026
Paramount takes over Warner Bros in $110bn Hollywood merger
October 6, 2026
From films to streaming prices – how the Warner Bros deal could affect you
October 6, 2026
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
October 6, 2026
Biswas, Chauhan, Baloda hand India Under-19 advantage on day two
October 6, 2026
Cameron Green ruled out of first Test vs South Africa
October 6, 2026
Licensing costs driving 90 percent of VMware users to explore options: Survey
October 6, 2026