CyberSecurity News
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
AI summary
A malicious server connected to an AI coding assistant can secretly exfiltrate sensitive information, including SSH keys and customer data. This can be achieved by splitting a malicious request into smaller, seemingly routine fragments and sending them through existing channels. The approach allows the malicious server to bypass detection, even if a more direct attempt at theft is blocked. The fragments, when combined, enable the exfiltration of secrets without raising suspicion. The technique exploits the AI coding assistant's normal functionality to carry out the data theft.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

