Researchers and security firms disclosed multiple ways attackers can manipulate AI agents and coding assistants into exposing sensitive data or executing malicious actions. In one case, Invariant Labs showed GitHub integrations built on the Model Context Protocol (MCP) could be abused to access private repositories, while Adversa AI reported a two-click exploit in Cursor that can trick developers into installing a malicious MCP server through a deeplink argument-injection flaw and a misleading confirmation dialog. Because MCP servers run with the user’s privileges, a successful attack could lead to arbitrary command execution, theft of source code and secrets, and full compromise of a developer workstation.
Separate academic research found that AI agents can also be subverted through poisoned but trusted-looking data rather than explicit prompt injection. A study covered by Nature showed agents from OpenAI, Anthropic, and Google often accepted doctored datasets and altered README files, producing manipulated conclusions, while another paper introduced agent data injection (ADI), in which attackers tamper with fields such as sender names, button IDs, or tool history to trigger misclicks, unauthorized purchases, fraudulent merge approvals, or attacker-command execution. Researchers said current defenses remain weak because agents do not reliably distinguish trusted from untrusted data, although measures such as MCP allowlisting, randomized identifiers, and stronger provenance tracking can reduce risk.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The ADI researchers said they reported the issue to affected vendors after finding all tested models from OpenAI, Anthropic, and Google vulnerable. They also said there was no public evidence of in-the-wild exploitation.
Dark Reading reported that Adversa AI found a two-click Cursor AI exploit combining deeplink argument injection with a misleading confirmation dialog to hide malicious MCP server installation commands. Cursor said it had reopened investigation of the bug after a third-party security vendor had previously closed the report.
Nature reported on a new arXiv study finding that autonomous AI agents from Anthropic, OpenAI, and Google could be misled by manipulated datasets that resembled legitimate ones. The study found agents accepted altered datasets about half the time on average and warned that weak provenance checking creates scientific integrity risks.
Researchers from Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft posted a paper on July 6 describing agent data injection (ADI), a new attack class that corrupts trusted-looking data fields to manipulate AI agents. The paper demonstrated proof-of-concept attacks against web agents and coding assistants, including unauthorized purchases, attacker-command execution, and fraudulent merge decisions.
Invariant Labs published a report describing a vulnerability involving GitHub MCP that could allow access to private repositories via MCP.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcedarkreading.com
Open sourcenature.com
Open sourceinvariantlabs.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.