Technology & AI
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Source: Ars Technica - All content · Published

The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information. In the past five months, Google and four other organizat
The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information. In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis.
Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions. Unexpected and hard to mitigate Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government.
His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol . The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action.
Read full article Comments
Related stories

Poland's antitrust regulator accuses Google of unfair market practices
The penalty could be up to 10 percent of Google's annual revenue.
Engadget - Technology News & Expert Reviews ·
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
AI slop seems to be overwhelming bug bounty programs.
TechCrunch ·
Gemini Call for Me might tell your mom you’re running late
Google may be expanding its "Call for Me" AI feature beyond business calls so you can use it to send messages to friends and family. Android Authority reports finding a "Gemini Calling" introductory screen in an APK teardown with examples that include "Call Mom and tell her I wil
The Verge ·

Wikimedia links OpenAI agents to an outage and unauthorized activity
Wikimedia says it's "deeply concerned about the impact of 'rogue' AI agents on platforms like ours.
Engadget - Technology News & Expert Reviews ·
Instinct brings its AI agent to group chats, even for friends without an account
Instinct is launching group chats that let friends use its AI agent together for tasks like planning trips, organizing carpools, and coordinating events. The company says personal accounts remain separate, with permission required before personal agents share information or take
TechCrunch ·