{"id":20466,"date":"2026-10-06T12:04:48","date_gmt":"2026-10-06T12:04:48","guid":{"rendered":"https:\/\/news.theck1.no\/?p=20466"},"modified":"2026-10-06T12:04:48","modified_gmt":"2026-10-06T12:04:48","slug":"mcp-for-agent-to-agent-comms-may-be-the-riskiest-protocol-youve-never-heard-of","status":"publish","type":"post","link":"https:\/\/news.theck1.no\/?p=20466","title":{"rendered":"MCP for agent-to-agent comms may be the riskiest protocol you&#8217;ve never heard of"},"content":{"rendered":"<p style=\"margin:0 0 1em; padding:0.6em 0.9em; border:1px solid #d0d7de; border-radius:6px; background:#f6f8fa; color:#444; font-size:0.9em;\"><strong>AI-rewritten:<\/strong> This is a summary of an article from Ars Technica, rewritten by AI (Qwen, running locally) to make it easier to read. The facts come from the original article &ndash; read it for the full story.<\/p>\n<div style=\"margin-bottom:1em; color:#666; font-size:0.9em;\"><strong>Ars Technica &bull;<br \/>\n                    Dan Goodin<br \/>\n                 &bull; October 5, 2026<\/strong><\/div>\n<hr\/>\n<p>AI agents are creating new risks as attackers exploit trust gaps between them. In the last five months, Google and four other organizations acknowledged vulnerabilities where one agent spreads harmful instructions to others inside a network. This technique targets specific agents like translators or data analysts. Their internal guardrails are often lax, causing them to follow directions from compromised peers because they explicitly trust each other.<\/p>\n<p><!--more--><\/p>\n<p>Independent researcher Syed Anas Mohiuddin tested agents from Google, JP Morgan Chase, and others using proof-of-concept attacks on the Model Context Protocol (MCP). MCP is a standard allowing AI apps to communicate within internal networks. Many special-purpose agents lack necessary guardrails, so an exploit that would normally be rejected by a Large Language Model succeeds instead. This can lead to server-side request forgery, where a web server makes unauthorized network requests on behalf of the attacker.<\/p>\n<p>Douglas McKee from Rapid7 explained that AI agents provide fresh connections for attackers to traverse networks. He noted that each protocol checks its own security while ignoring the trust between them. The vulnerabilities found had varying severity ratings; one in Google was rated 8, while another in Rapid7 was rated 2.7. Google&#8217;s issue involved a database toolbox failing to validate IP addresses or handle URL redirects properly.<\/p>\n<p>Mohiuddin calls this class of attack &quot;protocol pivoting,&quot; where an adversary uses one protocol to gain access and then exploits trust assumptions to escalate via a different protocol. Markus Vervier from X41 D-Sec argues the term should remain &quot;prompt injection,&quot; describing it as indirect because the malicious prompt can originate from a different communication method. Experts warn that organizations rushing to build agentic architectures have abandoned zero trust principles, treating input from tools like stranger input on the internet.<\/p>\n<div style=\"margin-top:2em; padding:1em; border-left:4px solid #0073aa; background:#f5f7fa;\">\n<p style=\"margin:0;\"><strong>Source:<\/strong> Ars Technica &bull;<br \/>\n                    Dan Goodin<br \/>\n                 &bull; October 5, 2026<\/p>\n<p style=\"margin:0.5em 0 0;\"><a href=\"https:\/\/arstechnica.com\/security\/2026\/10\/vulnerability-in-agents-from-google-and-others-exposes-structural-flaw-in-mcp\/\" target=\"_blank\" rel=\"noopener\">Read the original article at Ars Technica &rarr;<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>AI-rewritten: This is a summary of an article from Ars Technica, rewritten by AI (Qwen, running locally) to make it easier to read. The facts come from the original article &ndash; read it for the full story. Ars Technica &bull; Dan Goodin &bull; October 5, 2026 AI agents are creating new risks as attackers exploit<\/p>\n<p class=\"more-link\"><a href=\"https:\/\/news.theck1.no\/?p=20466\" class=\"themebutton2\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-20466","post","type-post","status-publish","format-standard","hentry","category-artificial-intelligence"],"_links":{"self":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts\/20466","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20466"}],"version-history":[{"count":0,"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts\/20466\/revisions"}],"wp:attachment":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20466"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20466"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20466"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}