Contenido en inglés
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

En resumen
The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information. In the past five months, Google and four other organizations—with little in common except for th
- Fuente primaria
- Ars Technica - All content — Leer artículo original
- Publicado
- Tema
The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.
In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents.
The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis.
Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions.
Unexpected and hard to mitigate Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government.
His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol . The standard
Este resumen proviene de Ars Technica - All content. Lee el artículo completo en la fuente original.
Referencias
Más en Google

Google lanza su primer satélite para llevarse los centros de datos al espacio
Un cohete Falcon 9 ha despegado este jueves desde California con el primer satélite del proyecto Suncatcher, una iniciativa a largo plazo de la tecnológica Google para explorar…

Europa se plantea garantizar a las grandes compañías de IA el acceso total a los datos de los ciudadanos
La presidencia irlandesa de la UE propondrá a los Estados miembros que el uso de los datos “en el contexto de la inteligencia artificial (IA)” sea automáticamente legal. Eso…

Google admite por primera vez que su IA ha ‘hackeado’ a tres empresas
El modelo Gemini de Google accedió a internet y hackeó a otras empresas durante una prueba de sus capacidades de ciberseguridad, en el primer caso conocido de que los sistemas de…