Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.

The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

How to Secure Enterprise AI: From Adoption to Incident Readiness

How to Secure Enterprise AI: From Adoption to Incident Readiness The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy

Meta’s AI Models Are Powering the First Wave of Genesis Mission Projects

Meta’s AI Models Are Powering the First Wave of Genesis Mission Projects Source: Hacker News