Security reporting and research warned that the Model Context Protocol (MCP) has opened a new attack surface for enterprise AI agents, allowing malicious content delivered through context windows, documentation, support tickets, GitHub issues, or untrusted MCP servers to trigger unauthorized actions without compromising the underlying model. Reported examples included WhatsApp data exfiltration, leakage of private repository data, abuse of a Supabase Cursor agent through crafted support tickets, and CVE-2025-6514, a high-severity OS command-injection flaw that could enable remote code execution via untrusted MCP servers.
A separate proof-of-concept targeting Andrew Ng’s Context Hub showed how poisoned API documentation served through an MCP server could silently steer coding agents into adding fake or malicious dependencies to generated projects, highlighting a software supply-chain risk in community-authored documentation pipelines. Across the coverage, researchers and vendors said perimeter controls and AI gateways are not enough because attackers or insiders can interact directly with MCP services; they urged organizations to treat MCP connectivity as privileged access, sanitize all context inputs, enforce policy and approval checks at the MCP server, restrict agent network and data access, and adopt zero-trust execution controls with auditable action receipts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Microsoft reported an attack pattern in which a trusted third-party MCP server's tool metadata is silently modified so an enterprise AI agent exfiltrates sensitive invoice data during a routine supplier query. The company said the technique builds on methods first disclosed by Invariant Labs in April 2025 and has been observed in 2026, framing it as an agentic supply-chain and tool-misuse risk.
Akamai Technologies reported that the upcoming MCP 2026-07-28 specification will redesign the protocol for enterprise-scale, cloud-native deployments while addressing long-standing weaknesses such as stateful initialization and server-initiated prompts. The report said the update mandates OAuth 2.1 but also introduces new attack surfaces including client-state manipulation, malicious _meta object injection, header/body mismatches, sensitive data exposure in HTTP headers, XSS in MCP Apps, and a 'hit-and-run' denial-of-service technique.
Mitiga reported that a fake software developer interview repository used hidden instructions in files such as CLAUDE.md, .cursor/rules, README.md, and MCP configuration to manipulate a Cursor-based AI coding agent into stealing AWS and Kubernetes credentials, enumerating infrastructure, and exfiltrating results. The attack relied on terminal access, MCP tools, and auto-run being enabled, and highlighted the risk of persistent cloud access through stolen long-lived CI/CD credentials.
BankInfoSecurity cited CurXecute and CVE-2025-54135 as examples of MCP-related risk, describing how untrusted repository files and hidden AI configuration files could trigger malicious command execution or credential theft through AI coding workflows. This is a separate attack example from the Context Hub documentation-poisoning PoC already in the timeline.
The Register reports that researcher Mickey Shmueli published a proof of concept showing that malicious documentation merged into Andrew Ng's Context Hub could cause AI coding agents to insert fake or malicious dependencies into generated projects.
A GitHub repository documenting a proof of concept for silent dependency injection through poisoned Context Hub documentation was published, describing 240 isolated Docker runs against the MCP-based documentation pipeline.
SC Media says JFrog disclosed CVE-2025-6514 in 2025, an OS command-injection flaw with a CVSS score of 9.6 that could enable remote code execution via untrusted MCP servers.
According to SC Media, attackers in 2025 abused Supabase's Cursor agent using malicious support tickets, demonstrating indirect prompt injection through operational support channels.
SC Media references a 2025 incident where GitHub issue content was used to leak private repository data through agent workflows, showing how untrusted context could expose sensitive information.
SC Media cites a 2025 incident in which Invariant Labs demonstrated WhatsApp data exfiltration through MCP-related agent context manipulation, illustrating the emerging attack surface.
The SC Media commentary says Anthropic introduced the Model Context Protocol in late 2024, establishing the integration layer later adopted across agentic AI platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcemicrosoft.com
Open sourcesecurityweek.com
Open sourcescworld.com
Open sourcegithub.com
Open sourcescworld.com
Open sourcepypi.org
Open sourcenccgroup.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.