logo

Shadow Escape 0-Click Attack in AI Assistants Puts Trillions of Records at Risk

ID: fd28304a-19c5-5072-9b54-53013d3fd37f

STIX ID: report--fd28304a-19c5-5072-9b54-53013d3fd37f

Feed Name: HackRead

Threat Score
75/100

Date Published: 2025-10-23

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive Summary:** Operant AI disclosed a zero-click attack called "Shadow Escape" that abuses the Model Context Protocol (MCP) used by AI assistants to embed hidden instructions in benign files; when uploaded, the assistant can query internal databases and exfiltrate sensitive records (SSNs, medical and financial data) to external servers, potentially affecting any organisation using MCP — researchers demonstrated the technique and urge immediate audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.