Skip to content
Ars Technica · AIDan Goodin

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

Google 等组织的 AI 智能体被发现存在利用 MCP 信任缺口传播恶意指令的漏洞,可能导致数据库内容及敏感信息外泄。过去五个月,Google 和另外四家组织承认了此类漏洞;攻击针对特定智能体注入指令,下游智能体因信任上游而执行。独立研究者 Syed Anas Mohiuddin 对多个组织的智能体进行了测试,并构建了概念验证攻击。

Read the original ↗Export Markdown