Shadow Escape 0-Click Attack in AI Assistants Puts Trillions of Records at Risk
ID: fd28304a-19c5-5072-9b54-53013d3fd37f
STIX ID: report--fd28304a-19c5-5072-9b54-53013d3fd37f
Feed Name: HackRead
Threat Score
**Executive Summary:** Operant AI disclosed a zero-click attack called "Shadow Escape" that abuses the Model Context Protocol (MCP) used by AI assistants to embed hidden instructions in benign files; when uploaded, the assistant can query internal databases and exfiltrate sensitive records (SSNs, medical and financial data) to external servers, potentially affecting any organisation using MCP — researchers demonstrated the technique and urge immediate audits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
