news.mlab.sh
1 result
threat-intel

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server leveraging the Model Context Protocol (MCP) can silently exfiltrate sensitive data – including SSH keys, source code, and customer data – from AI coding assistants. The attack works by splitting requests into fragments and letting the agent stitch them together, even if individual fragments appe…

The Hacker News · Aug 11, 2026 High