AnalysisCybersecurityJune 30, 2026

Microsoft warns poisoned MCP tool descriptions can make AI agents leak data

Attackers can hijack AI agents by poisoning the plain-text description of MCP tools, making them send company data to outsiders without breaking any rules. Microsoft 365 Copilot and custom agents in Copilot Studio or Azure AI Foundry are vulnerable; the attack changes what the software actually does versus just biasing an output.

1 source

More stories today

Open the live feed
Microsoft warns poisoned MCP tool descriptions can make AI agents leak data — AIBriefs