Cato CTRL™ Threat Research: PoC Attack Targeting Atlassian’s Model Context Protocol (MCP) Introduces New “Living off AI” Risk
ID: a0a20d83-bc81-5941-b2ea-c7deacfc724b
STIX ID: report--a0a20d83-bc81-5941-b2ea-c7deacfc724b
Feed Name: Cato Networks
This report demonstrates a proof-of-concept “Living Off AI” prompt-injection attack against Atlassian’s MCP and Jira Service Management in which malicious external tickets execute AI-driven actions with internal user privileges, enabling data exfiltration, injection of malicious links, and downstream command-and-control and lateral movement; the authors recommend applying GenAI security controls (e.g., CASB rules) to inspect, block, and audit MCP calls to mitigate the systemic risk of executing untrusted input in AI-integrated workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
