Threat
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
First reported · Discovered arstechnica.com
Page published
Earliest dated coverage: 5 Oct 2026 · First observed: 7 Oct 2026 · Latest dated coverage: 5 Oct 2026
Coverage timeline
Single-source incident — one report is available.
Why it matters
MCP's assumption that internal agents can trust each other lets attackers chain prompt injection across an agent network to reach internal endpoints and exfiltrate sensitive data, a structural weakness affecting millions of organizations deploying AI agents.
Independent researcher Syed Anas Mohiuddin demonstrated a cross-agent prompt-injection technique that abuses trust gaps in the Model Context Protocol (MCP), where one compromised internal agent passes malicious instructions to downstream agents that implicitly trust it. Proof-of-concept attacks against agents from Google, JP Morgan Chase, Weaviate, Rapid7, and government bodies led to server-side request forgery and data exfiltration; Google's MCP database toolbox flaw (rated 8) and Rapid7's CVE-2026-97228 have both been fixed.