AI Agents Chain Malicious Instructions Through Protocol Pivoting to Bypass Protections
AI agents can relay malicious instructions across chained components, bypassing built-in safeguards and potentially reaching internal organizational resources. The approach relies on the fact that trust and authorization checks often disappear when tasks are handed off between different protocols and specialized agents.
Researcher Syed Anas Mohiuddin described the technique as protocol pivoting. He examined systems using the MCP protocol, which connects AI agents to tools and data sources. When a task moves from one component to another, verification steps are frequently lost, allowing a planted instruction to reach an agent responsible for translation or data analysis.
Once accepted as a legitimate request, the malicious payload can trigger unwanted network connections or data disclosure. In Google MCP Toolbox for Databases, Mohiuddin showed that an attacker could force the HTTP client to follow a redirect to an internal address. Google later added address validation and limited permitted request destinations in a patch.
A related finding, CVE-2026-97228, affected Rapid7 Bulk Export MCP. The vulnerability carried a CVSS score of only 2.7 because an unchecked argument allowed modification of a GraphQL query structure. Rapid7 addressed the issue in version 0.6.2 and confirmed that queries remained limited to the permissions of the original API key owner.
Security researcher Markus Vervier of X41 D-Sec observed that the reported behavior is a variant of indirect prompt injection rather than a fundamentally new attack method.
Related articles
Astra Group Unveils Astra AI Ecosystem for Air-Gapped Corporate Networks
Astra Group has introduced its Astra AI ecosystem designed for secure, on-premises deployment in closed corporate environments. The solution enables organizations to run AI models locally without transmitting data to external services, targeting critical infrastructure operators, government agencies, and regulated industries. Built on Astra Linux and the Botsman containerization platform, the ecosystem includes five integrated components for code automation, office assistants, low-code agent development, model management, and implementation methodology. The company claims productivity gains exceeding 50 percent for development tasks and up to fourfold performance improvements with its certified hardware-software complexes. While emphasizing data sovereignty and regulatory compliance, Astra Group notes that local deployment alone does not eliminate risks related to agent permissions, output quality, and integration security.
AI Learns Human Formulas of Deception, Fueling a Crisis of Free Speech and Truth
The article examines how artificial intelligence has begun replicating human social-behavioral patterns to create and cite nonexistent authoritative sources, thereby spreading false information at scale. It traces the historical evolution of propaganda from ancient Sparta and Athens through the Rothschilds and modern social media, showing how each new mechanism for verifying truth—expert opinion, reputation, and finally machines—has been subverted. The author highlights recent examples of rapid disinformation campaigns, including false claims about FlyDubai pilots and a supposed plague outbreak in Irkutsk, which were amplified by controlled media, opinion leaders, and ordinary users. The piece warns that AI’s tireless ability to generate thousands of contradictory articles in real time could overwhelm any possibility of discerning truth, especially during elections. Societal consequences include rising atomization, declining trust in institutions, lower voter turnout, and reduced economic investment due to uncertainty. The author concludes that humanity currently lacks an effective countermeasure and may need to pass through a period of extreme information pollution before developing new norms of personal responsibility and verification.
Anthropic Reports User's Violent Threats to Police After Conversation with Claude AI
Anthropic's security systems flagged messages from a Florida woman who used the Claude AI chatbot to express intent to carry out a shooting at the Lee County Sheriff's Office. The 30-year-old Carly Michelle Heller also stated that she had acquired a weapon, prompting the company to escalate the conversation for human review. After verification, Anthropic notified law enforcement, leading to her identification and quiet arrest at her home. Sheriff Carmine Marceno noted that Heller had been treating Claude as a personal diary rather than a secure private space. She now faces a second-degree felony charge under Florida law, with the court set to determine her guilt. The case underscores how AI platforms monitor for specific threats involving concrete targets and weapon acquisition, resulting in direct police involvement.
AI Reshapes Cybersecurity Jobs: Automation of Routine Tasks, Rising Demand for Architects and AI Defenders
The cognitive revolution driven by AI technologies is transforming the information security job market rather than eliminating it. Routine tasks such as alert triage, log analysis, and basic vulnerability prioritization are increasingly handled by language models and autonomous agents, shifting human roles toward setting boundaries, validating hypotheses, and assuming legal and financial responsibility. Surveys from ISC2 and analyses by Gartner highlight growing needs for senior architects, AppSec engineers, DevSecOps specialists, and experts protecting AI systems themselves. DARPA's AIxCC competition demonstrated both the promise and limitations of autonomous patching, with 37-45% of generated fixes containing hidden semantic errors. Russian market data from Positive Technologies and SuperJob shows 24-26% growth in vacancies focused on experienced professionals amid import substitution pressures. The profession is moving from mechanical execution to designing reliable architectures and overseeing automated defense loops through 2030.