Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Texas city demands $2M for public records on Flock usage

    Etched fields funding offers at $40B+ valuation, sources say

    MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»AI News»MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of
    AI News

    MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of

    By No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    AI Chatbot Assistants on Glass Blocks, Artificial Intelligence Technology Concept. Digitally generated image. 3d render.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    “AI agents give attackers a fresh set of connections to walk across,” Douglas McKee, director of vulnerability intelligence at Rapid7, told Ars. “Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work. Every piece in that chain did exactly what it was designed to do, which is what makes this so tricky to catch. Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between.”

    CVE-2026-97228, the vulnerability Mohiuddin found in Rapid7’s network, carried a severity rating of only 2.7 out of 10. Rapid7 fixed it last month.

    The vulnerability affecting Google was more severe, with a rating of 8. It stemmed from an MCP toolbox for databases (googleapis/mcp-toolbox) initializing its HTTP client with no use of a CheckRedirect policy, a series of settings that control how a server is to handle cases of a URL either returning an error or redirecting to a different URL. Google’s HTTP client also failed to validate target IP addresses.

    “A crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests on the attacker’s behalf,” Mohiuddin explained. Google’s fix involved applying an allow-list of IP ranges and block lists. “It rejects an unsafe base URL at startup instead of on first request. That is what a real SSRF guard looks like. It is also more work than most MCP servers have done.”

    Mohiuddin is calling the class of attack “protocol pivoting” because the exploits work when an app or server uses MCP to assign a task to an agent and the agent then forwards malicious instructions to another agent using a different communication method such as Google’s Agent-to-Agent (A2A) protocol, used for inter-agent delegation, or emerging standards such as the Agent Network Protocol. Often, he says, trust or authorization gets effectively lost in translation. He described protocol pivoting as “a multi-step attack in which an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities only accessible via a different protocol.”

    agenttoagent comms heard MCP Protocol riskiest Youve
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleLucid Motors’ EV output falls to lowest level in almost 2 years
    Next Article Etched fields funding offers at $40B+ valuation, sources say
    • Website

    Related Posts

    AI News

    Texas city demands $2M for public records on Flock usage

    AI News

    Etched fields funding offers at $40B+ valuation, sources say

    AI News

    Lucid Motors’ EV output falls to lowest level in almost 2 years

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Texas city demands $2M for public records on Flock usage

    0 Views

    Etched fields funding offers at $40B+ valuation, sources say

    0 Views

    MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Texas city demands $2M for public records on Flock usage

    0 Views

    Etched fields funding offers at $40B+ valuation, sources say

    0 Views

    MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.