Poisoned descriptions in Model Context Protocol (MCP) tools enable attackers to abuse AI agents into sharing data while security control mechanisms remain silent.
Poisoned MCP tool descriptions can trick AI agents into exfiltrating business-critical data to external systems while each individual step appears legitimate.
A fake Perplexity extension on the Chrome Web Store was discovered intercepting search queries and browsing data, transmitting them to attackers’ servers.
Even GPT-4.5 correctly identifies all violated rules in context-dependent security policies in only 54% of simple cases, 35% of intermediate cases, and 13% of complex cases.
282 iOS AI apps expose API keys and backend credentials unprotected over the network, enabling fraudulent use of paid services on third-party accounts.
BEC is an organized business model with specialized division of labor that demands comprehensive technical and procedural countermeasures rather than point-in-time email filtering.