Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

2026-07-01T01:24:10Ze65f4b37dbc33634b6cb8354c7e2c194ac32871014e58b1eda16a7d29f8476b9
active-exploitationai-securitybotnetbrowser-extension-malwarecredential-leakcritical-vulnerabilitiescrypto-minerinfostealerlangflowlibssh2loadbalancermalwareoracle-e-business-suitepoisoned-tool-descriptionsremote-code-executionrustducksimplehelpsupply-chainwebkit

What happened

A batch of high-impact security reports: multiple critical and actively exploited vulnerabilities (notably Langflow CVE-2026-33017, SimpleHelp CVE-2026-48558, Progress Kemp LoadMaster CVE-2026-8037, Oracle E-Business Suite CVE-2026-46817, and libssh2 CVE-2026-55200) are being weaponized in the wild. Coverage also highlights rapid malware evolution (RustDuck botnet rebuilt in Rust), supply-chain and package-hijack deployments of infostealers and miners, malicious browser/extension campaigns (credential and search interception, clipper extensions), widespread leakage of LLM/API keys in iOS apps,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
e65f4b37dbc33634b6cb8354c7e2c194ac32871014e58b1eda16a7d29f8476b9
Enrichment time
2026-07-01T01:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.