Breakthroughs and research·October 6, 2026, 00:26
AI agents blindly trust each other, and attackers can exploit it
AI-generated and checked against the sources listed below.
Security researcher Syed Anas Mohiuddin has shown that attackers can send malicious instructions from one AI agent to another via the MCP protocol, because the agents trust each other. If your company has AI agents connected internally, it is worth asking the vendor how they are secured.

More and more companies use AI agents, that is, small programs that each have their own job, such as translation or data analysis. That opens a new door for attackers: they can get the agents to do things they should not, such as extracting content from databases or sensitive information about businesses and private individuals.
In the past six months, Google and four other organizations have acknowledged vulnerabilities of the same type. The attacker gets hold of one agent inside the network and has it pass malicious instructions on to the others. The technique is a special form of prompt injection, where the target is not the language model itself but a specific agent.
The problem is trust. Many of the small specialist agents have weak security barriers or none at all. And the agent further down the chain trusts the first one and simply goes along. Something the language model itself would have refused is thereby carried out anyway.
The independent researcher Syed Anas Mohiuddin tested agents from Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate and the US federal government, among others. His demonstration attacks exploit holes in MCP, Model Context Protocol, which is one way AI apps and agents can talk to each other inside an internal network.
Rapid7's Douglas McKee describes it like this: each link in the chain does exactly what it was built to do, and that is what makes it hard to detect. Each protocol checks its own front door, while no one keeps an eye on the hallway in between.
The severity varies. The vulnerability at Rapid7 scored only 2.7 out of 10 and was fixed last month. Google's was more serious at 8 out of 10. Here, a crafted request could get a database tool to follow a redirect to an internal endpoint and send requests on the attacker's behalf. Google has fixed it.
What does it mean for you? If you only use a single AI assistant privately, there is no reason to panic. If, on the other hand, your company runs several agents that hand off tasks to each other, use the coming weeks to ask your vendor or IT manager which agents may give each other tasks and whether there are controls between them. Also remember to update when fixes are released.
Source
Get the week's AI news in your inbox
Choose your level, topics and length. One email a week, unsubscribe at any time.
Subscribe to Promptly Newsletter



