# Researcher demonstrates attacks that spread instructions between AI agents

_Published Monday, October 5, 2026 at 8:04 PM EDT · Security, AI · Latest · Tier 2 — Notable_

![AI Chatbot Assistants on Glass Blocks, Artificial Intelligence Technology Concept. Digitally generated image. 3d render. — Primary](https://cdn.arstechnica.net/wp-content/uploads/2026/10/ai-agents-1152x648.jpg)

Independent researcher Syed Anas Mohiuddin demonstrated attacks that use one internal AI agent to pass malicious instructions to other agents, Ars Technica reported. Google and four other organizations have acknowledged related vulnerabilities over the past five months.

The attacks exploit trust gaps in Model Context Protocol, a standard used by AI applications and agents to communicate. An agent with weak safeguards can forward harmful instructions to another agent that trusts it. MCP servers store agent credentials, and carefully targeted prompts can cause servers to make unauthorized network requests. The demonstrations establish vulnerabilities, rather than evidence of attackers stealing data from those organizations.

## Sources

- [Ars Technica](https://arstechnica.com/security/2026/10/vulnerability-in-agents-from-google-and-others-exposes-structural-flaw-in-mcp/)

---
Canonical: https://techandbusiness.org/newswire/zisStU2mkMBh4FsHt-CmmW
Published: 2026-10-06T00:04:20.192Z
Story chronology: 2026-10-05T22:26:35.000Z
Retrieved: 2026-10-06T02:03:04.959Z
Publisher: Tech & Business (techandbusiness.org)
