Attackers Exploit MCP Trust Gaps to Hijack AI Agents Across 5 Organizations
Updated
Updated · Ars Technica · Oct 5
Attackers Exploit MCP Trust Gaps to Hijack AI Agents Across 5 Organizations
3 articles · Updated · Ars Technica · Oct 5
Summary
Five organizations, including Google, have acknowledged AI-agent flaws in the past five months that let one compromised internal agent pass malicious instructions to others.
MCP—the Model Context Protocol used for agent-to-agent communication—creates the opening because downstream agents explicitly trust upstream ones, while many specialized agents have weak or no prompt-injection guardrails.
Syed Anas Mohiuddin tested agents tied to Google, JP Morgan Chase, Weaviate, Rapid7, the French government and the US federal government, showing prompts could trigger data theft and server-side request forgery.
The risk is widening as millions of organizations adopt AI agents, with MCP servers often holding agent credentials that can turn a single prompt injection into broader internal compromise.
How can one compromised AI agent silently turn your company's internal tools into an unstoppable data-stealing network?
When autonomous AI assistants blindly trust each other, what stops a single hidden prompt from executing devastating cyberattacks?
2,388 Organizations Exposed: Inside the 2026 Agentjacking Wave and the Model Context Protocol Security Meltdown
Overview
In 2026, rapid enterprise adoption of Anthropic's Model Context Protocol (MCP) created a vast, unmonitored attack surface. Security researchers uncovered the 'agentjacking' vulnerability, where attackers exploited Sentry’s unauthenticated error reporting and AI coding agents’ implicit trust. By sending crafted error events to Sentry, attackers could trick AI assistants into executing malicious commands with full developer privileges, leading to silent credential theft. Despite notification, Sentry only applied a narrow content filter, leaving the root architectural flaw unresolved. This systemic risk prompted urgent security guidance from the NSA and CISA, and new regulatory mandates under the EU AI Act, forcing organizations to rethink AI agent security and governance.