chiprook
← Security
SecurityOctober 6, 2026, 05:26

Vulnerability in Google and other AI agents exposes structural flaw in MCP

Independent researcher Syed Anas Mohiuddin found a "protocol pivoting" attack that relays malicious instructions between internal AI agents via MCP and A2A. A Rapid7 flaw was rated 2.7 out of 10, while Google's was rated 8; both have been fixed.

Vulnerability in Google and other AI agents exposes structural flaw in MCP
#Google#Rapid7#MCP
Read next
Security

Researcher finds SSRF flaws in MCP servers from Google, Anthropic, Microsoft and Weaviate

Security

Bifrost MCP gateway hit by critical 9.8 vulnerability

Security

GitHub's AI agent found 24 Android app vulnerabilities

Security

CISA adds two Zammad flaws to Known Exploited Vulnerabilities catalog