344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth193
AI Infrastructure & MLOps175
Writing & Content Creation204
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support133
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
A security researcher found a way to make one AI agent pass malicious instructions to other trusted agents inside an organization’s network.
In short: A security researcher showed that some AI agents can be tricked into passing harmful instructions to other trusted agents, leading to data access and other risky actions.
More companies are using “AI agents,” which are software helpers that can do tasks like translating text or pulling data from a database. A new set of security reports suggests these agents can create an unexpected path for attackers.
Independent researcher Syed Anas Mohiuddin tested agents tied to several organizations, including Google and Rapid7. He found cases where an attacker could plant a malicious prompt (a hidden instruction in text) that one internal agent would read and then forward to other agents. Because the next agent “trusts” the first one, it may follow the bad instruction, like a coworker acting on a request that looks official.
The issue shows up in systems using Model Context Protocol, or MCP, which is a standard way for AI apps and agents to talk to each other inside a company network. Mohiuddin says MCP can have “trust gaps,” meaning the system may lose track of who is allowed to do what as tasks move between agents and tools.
In one example, a flaw in Google’s open source MCP database toolbox could be used to trigger server-side request forgery, or SSRF (when a server is tricked into making network requests it should not make). Rapid7 also fixed a related vulnerability, tracked as CVE-2026-97228, last month.
Security experts say the fixes are familiar, like stricter permission checks and treating anything an agent receives as untrusted, like a message from a stranger online. As more teams connect agents together, expect more attention on “zero trust” design, where each step must prove it has permission.
Source: Arstechnica