Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
Microsoft has issued a warning about a new attack vector targeting AI agents that use the Model Context Protocol (MCP). Attackers can…
Microsoft has issued a warning about a new attack vector targeting AI agents that use the Model Context Protocol (MCP). Attackers can…
In May 2025, Invariant Labs showed a similar prompt injection attack against GitHub's MCP server, using public issues to hijack agents and…
Prompt Shields is a Microsoft product that helps defend against prompt injection attacks, including those targeting MCP tool descriptions.
Adversa AI, an AI security company, disclosed a novel attack technique called Cryptographic Context Injection that can exfiltrate private data from AI…
A new attack technique called BioShocking, discovered by security firm LayerX, exploits AI browsers and assistants by tricking them into leaking user…
Perplexity's Comet AI browser was among six agents manipulated by the BioShocking attack to copy and send SSH login credentials to an…
SafeBreach, a cybersecurity company, demonstrated an indirect prompt injection attack that could hijack Gemini's Android Utilities agent via notification content, which Google…
A new macOS malware called Gaslight uses embedded prompt injection strings and fake debugging data to confuse AI-assisted malware analysis tools. It…
CVE-2025-54136, known as MCPoison, is a vulnerability in Cursor discovered by Check Point Research. It allows an attacker to get an MCP…
AI agents are increasingly deployed in enterprise environments, inheriting permissions and executing tasks autonomously, often bypassing traditional identity governance controls. This article…