AnalysisCybersecurityAugust 11, 2026

GhostSplice attack splits MCP instructions to steal secrets via AI coding agents

Read original source →thehackernews.com

ASSET Research Group's GhostSplice technique lets a malicious MCP server split a harmful request across tool descriptions and results, so AI coding agents exfiltrate SSH keys and source code without a single obviously malicious instruction. Tests show the same model can refuse in one client and exfiltrate in another.

1 source

More stories today

Open the live feed