Recent discussions in the cybersecurity community have brought attention to the potential risks associated with AI agents and their interactions, particularly how they can be exploited by malicious actors. Douglas McKee, Director of Vulnerability Intelligence at Rapid7, outlined a troubling dynamic where AI agents can inadvertently relay harmful directives. As he explained, the process begins with a piece of compromised text embedded in content; an AI agent reads and forwards it to another agent, which operates under a false sense of trust. This cascading action occurs across various protocols that were never designed to scrutinize their interconnections, creating a blind spot in security oversight.
Among the vulnerabilities identified recently was CVE-2026-97228, found within Rapid7’s network. Although it carried a lower severity score of 2.7 out of 10, the flaw was addressed and fixed last month. In contrast, another vulnerability impacting Google was significantly more concerning, rated at 8 out of 10. This issue was linked to the MCP toolbox for databases, specifically its failure to implement a CheckRedirect policy when initializing its HTTP client. Such a lapse allowed unvalidated target IP addresses, which could lead to dangerous redirect scenarios.
Security researcher Mohiuddin, who discovered the flaw, indicated that an attacker could exploit this vulnerability by crafting specific path parameters that would lead the toolbox to redirect requests to an internal endpoint, effectively using the system to launch attacks without direct user interaction. In response, Google has enacted a more robust security mechanism, involving an allow-list and block list for IP addresses. This measure ensures that unsafe URLs are rejected at startup rather than at the moment of the initial request, thereby strengthening the overall protection against server-side request forgery (SSRF).
Mohiuddin has categorized this type of threat under “protocol pivoting,” a term he coined to represent this class of multi-step attacks. The technique exploits the trust assumptions between different protocols when an application or server delegates tasks to agents. It becomes particularly concerning when malicious instructions are exchanged through alternate communication protocols like Google’s Agent-to-Agent protocol or the newer Agent Network Protocol. Essentially, the trust established in one context can be leveraged to compromise other systems.
The implications of such vulnerabilities highlight significant threats to organizations, particularly those with interdependent systems reliant on agents for performing delegated tasks. The lack of scrutiny between these operational layers allows adversaries to orchestrate complex attacks that can escalate to higher privileges or capabilities through trust misuse. In terms of the MITRE ATT&CK framework, these incidents align with multiple tactics and techniques, primarily initial access, privilege escalation, and potentially lateral movement as attackers pivot from one compromised area of a network to another.
Business owners should remain vigilant, recognizing that the very technologies designed to improve efficiency may also introduce new vulnerabilities. With the integration of AI agents becoming so pervasive, it is critical for organizations to assess their security protocols continuously, ensuring that each component in their operational framework is not only robust on its own but also secure in its interactions with other systems. As the cybersecurity landscape evolves, so too must the strategies employed to safeguard organizational assets against emerging threats.