Researchers have uncovered a new privacy risk with Shadow Escape that exploits the Model Context Protocol (MCP) businesses use to connect to LLMs. The attack enables hackers to steal volumes of data such as Social Security Numbers, medical records, and business information that use AI assistants without the user ever clicking a suspicious link or making a mistake.
The details can be found here: https://www.operant.ai/art-kubed/shadow-escape
Roger Grimes, CISO Advisor at KnowBe4, provided the following comments:
“I’m familiar with at least one other similar attack involving another, more popular AI tool, that the research plans to publicly release soon after practicing responsible disclosure with the vendor. They seem to be coming out of the woodwork so to speak. This zero-click attack is just going to be one of thousands coming out over the next few years. These initial reports are just the beginning stages of what promises to be years and years of new types of exploits. That’s because AI and the way they interact with other AIs and humans are just starting to be discovered and explored. The sheer amount of ways that any AI can interact with something else makes it far harder, if not impossible, for the vendor or a cyber defender to test before the AI is released.
“We didn’t do a great job at testing non-AI, more deterministic software and systems, to make sure they didn’t have vulnerabilities. Heck, we had over 40K separate publicly announced vulnerabilities last year and we are on our way to having over 47K this year. Non-deterministic AIs with the ability to have thousands of different types of interactions is just going to make that number explode. We are just now opening pandora’s box, and we are definitely not going to like what we see. I thought stuff was complex in the past. We will think of the past decades of vulnerabilities as the “good times” before AI everywhere arrived. It’s getting ready to be very stormy.”
Organizations need to look at the use of AI by their employees. They need to ensure that they are using only company approved AI tools and making sure that anything that connects to an LLM is secure. Otherwise, they are wide open to this sort of attack.
Related
This entry was posted on October 23, 2025 at 4:35 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Shadow Escape 0-Click Attack in AI Assistants Puts A Lot Of Data At Risk
Researchers have uncovered a new privacy risk with Shadow Escape that exploits the Model Context Protocol (MCP) businesses use to connect to LLMs. The attack enables hackers to steal volumes of data such as Social Security Numbers, medical records, and business information that use AI assistants without the user ever clicking a suspicious link or making a mistake.
The details can be found here: https://www.operant.ai/art-kubed/shadow-escape
Roger Grimes, CISO Advisor at KnowBe4, provided the following comments:
“I’m familiar with at least one other similar attack involving another, more popular AI tool, that the research plans to publicly release soon after practicing responsible disclosure with the vendor. They seem to be coming out of the woodwork so to speak. This zero-click attack is just going to be one of thousands coming out over the next few years. These initial reports are just the beginning stages of what promises to be years and years of new types of exploits. That’s because AI and the way they interact with other AIs and humans are just starting to be discovered and explored. The sheer amount of ways that any AI can interact with something else makes it far harder, if not impossible, for the vendor or a cyber defender to test before the AI is released.
“We didn’t do a great job at testing non-AI, more deterministic software and systems, to make sure they didn’t have vulnerabilities. Heck, we had over 40K separate publicly announced vulnerabilities last year and we are on our way to having over 47K this year. Non-deterministic AIs with the ability to have thousands of different types of interactions is just going to make that number explode. We are just now opening pandora’s box, and we are definitely not going to like what we see. I thought stuff was complex in the past. We will think of the past decades of vulnerabilities as the “good times” before AI everywhere arrived. It’s getting ready to be very stormy.”
Organizations need to look at the use of AI by their employees. They need to ensure that they are using only company approved AI tools and making sure that anything that connects to an LLM is secure. Otherwise, they are wide open to this sort of attack.
Share this:
Like this:
Related
This entry was posted on October 23, 2025 at 4:35 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.