MCP for agent-to-agent comms may be the riskiest p
2026年10月06日 06:262,203 次阅读
AI导读
The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.
In the past five months, Google and four other organizations—with little in ...
The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.
In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions.
Unexpected and hard to mitigate
Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol. The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action.Read full article
Comments
When Don Yansen ’63 arrived at the MIT AgeLab for a study on technology in caregiving for older adults, he didn’t plan to launch another company. But when he heard participants talk about how hard modern devices can be to use, he decided to develop an alternative.
Yansen, a serial entrepreneur w...
在人工智能领域,从实验室里的概念验证(Proof of Concept)到能够稳定运行的生产级系统,往往存在一道巨大的鸿沟。近期,业内专家深入剖析了构建生产级Agentic AI(自主智能体AI)系统的关键架构组件,揭示了那些将临时演示脚本与真正商业化应用区分开来的核心要素。这不仅是一次技术层面的梳理,更是对整个AI行业从狂热探索走向理性落地的深刻反思。
This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here.
Last Wednesday, Anthropic announced that earlier this year it had launched a molecular biology lab, where Claude agents read and conjecture about hard biology ...