Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

New Microsoft research shows how attackers can hijack AI agents that act on a user’s behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider.

The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no alarm may fire.

The work comes from Microsoft Incident Response and its

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

AI Meets Cryptography 2: What AI Found in OpenVM’s ZkVM

AI Meets Cryptography 2: What AI Found in OpenVM’s ZkVM Source: Hacker News

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors A lot of security problems still begin with someone doing a completely normal thing. Cloning a

Russia Used Cellebrite on Jailed Activist’s iPhone Months After Sales Cutoff

Russia Used Cellebrite on Jailed Activist’s iPhone Months After Sales Cutoff Russian authorities used Cellebrite’s UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in