AnalysisCybersecurityJune 30, 2026
Microsoft warns poisoned MCP tool descriptions can make AI agents leak data

Attackers can hijack AI agents by poisoning the plain-text description of MCP tools, making them send company data to outsiders without breaking any rules. Microsoft 365 Copilot and custom agents in Copilot Studio or Azure AI Foundry are vulnerable; the attack changes what the software actually does versus just biasing an output.
1 source
More stories today
- Work with docs, sheets, and slides in ChatGPT
- Lawmakers prepare AI 'kill switch' bill
- Rivian uses Databricks to deliver monthly AI fleet updates
- Dust co-founder discusses model-agnostic AI platform bet
- How regulated organizations can increase AI code velocity safely