#GhostSplice
GhostSplice attack uses malicious MCP servers to exploit BO coding agents, leading to covert data exfiltration. #AI #PotatoSecurity #MCP #DataExfiltration #GhostSplice #AIAgents https://thedailytechfeed.com/malicious-mcp-servers-exploit-ai-coding-agents-to-exfiltrate-sensitive-data/
August 11, 2026 at 10:59 AM
GhostSplice attack uses malicious MCP servers to exploit AI coding agents, leading to covert data exfiltration. #AI #CyberSecurity #MCP #DataExfiltration #GhostSplice #AIAgents https://thedailytechfeed.com/malicious-mcp-servers-exploit-ai-coding-agents-to-exfiltrate-sensitive-data/
August 11, 2026 at 10:59 AM
GhostSplice: splitting one exfiltration instruction across multiple MCP tool calls raises compliance from 42% to 82%. AI coding agents cheerfully stitch the pieces and send the data. What to do: pin MCP server allowlist, segment tool scopes, gate every tool that touches filesystem or network: https:
September 4, 2026 at 1:00 AM
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

thehackernews.com/2026/08/mali...
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
GhostSplice splits MCP instructions across channels, letting AI coding agents combine them to exfiltrate SSH keys, secrets, and source code.
thehackernews.com
August 16, 2026 at 5:07 AM
GhostSplice: Malicious MCP Servers Split Instructions to Make AI Coding Agents Exfiltrate Secrets (ASSET Research Group)
The AI refused to steal the secrets. So we handed it a form.
asset-group.github.io
August 12, 2026 at 12:28 AM
GhostSplice: Malicious MCP Servers Split Instructions to Make AI Coding Agents Exfiltrate Secrets (ASSET Research Group)
GhostSplice: Malicious MCP Servers Split Instructions to Make AI Coding Agents Exfiltrate Secrets (ASSET Research Group)
asset-group.github.io
August 12, 2026 at 12:39 AM
New BO attacks 'Ghostjacking' & 'GhostSplice' turn coding assistants into insider threats. By poisoning logs & splitting commands, researchers made BO agents exfiltrate SSH keys & alter DNS. A new threat for enterprise AI. #AIsafety #PromptInjection

🌐 potato[.]netsecops[.]io
August 12, 2026 at 3:07 PM
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
thehackernews.com/2026/08/mali...
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
GhostSplice splits MCP instructions across channels, letting AI coding agents combine them to exfiltrate SSH keys, secrets, and source code.
thehackernews.com
August 11, 2026 at 12:30 PM
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets thehackernews.com/2026/08/mali...
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
GhostSplice splits MCP instructions across channels, letting AI coding agents combine them to exfiltrate SSH keys, secrets, and source code.
thehackernews.com
August 16, 2026 at 3:16 PM
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.

thehackernews.com/2026/08/mali...
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
GhostSplice splits MCP instructions across channels, letting AI coding agents combine them to exfiltrate SSH keys, secrets, and source code.
thehackernews.com
August 12, 2026 at 5:32 AM
GhostSpliceのような指令分割攻撃には、Prompt Injection Shield Proverが役立ちます。意図の分離と権限の封じ込めによりリスクを軽減できます。 https://vinkius.com/mcp/prompt-injection-shield-prover
Prompt Injection Shield Prover MCP for AI Agents — LLM Security
Secure your AI agents against prompt injection. Use Prompt Injection Shield Prover for OWASP-compliant LLM security audits in Claude or Cursor.
vinkius.com
August 11, 2026 at 11:50 AM
GhostSplice : l'agent recolle seul l'instruction fragmentée #MCP blog.gioria.org/fr/ai-securi... sgioria.substack.com/p/ghostsplic...
September 3, 2026 at 8:42 AM
To mitigate GhostSplice risks like instruction stitching, the Security Audit Prover can force systematic validation of agent logic and input sanitization: https://vinkius.com/ai-agent-connect/security-audit-prover
Security Audit Prover MCP for AI Agents — OWASP Security
Use Security Audit Prover with Claude or Cursor to prevent SQL injections and leaked secrets in your AI-generated code. Secure your app today.
vinkius.com
September 4, 2026 at 3:26 AM
The GhostSplice risk is real. To help mitigate instruction stitching, the Security Audit Prover can force systematic validation of agent logic and input sanitization: https://vinkius.com/ai-agent-connect/security-audit-prover
Security Audit Prover MCP for AI Agents — OWASP Security
Use Security Audit Prover with Claude or Cursor to prevent SQL injections and leaked secrets in your AI-generated code. Secure your app today.
vinkius.com
September 4, 2026 at 3:57 AM
To mitigate GhostSplice risks like instruction stitching, the Security Audit Prover can force systematic validation of agent logic and input sanitization: https://vinkius.com/ai-agent-connect/security-audit-prover
Security Audit Prover MCP for AI Agents — OWASP Security
Use Security Audit Prover with Claude or Cursor to prevent SQL injections and leaked secrets in your AI-generated code. Secure your app today.
vinkius.com
September 4, 2026 at 1:48 AM
The GhostSplice risk of instruction stitching is real. To help mitigate this, the Security Audit Prover can force systematic validation of agent logic and input sanitization across 5 critical axes before any code is shipped: https://vinkius.com/ai-agent-connect/security-audit-prover
Security Audit Prover MCP for AI Agents — OWASP Security
Use Security Audit Prover with Claude or Cursor to prevent SQL injections and leaked secrets in your AI-generated code. Secure your app today.
vinkius.com
September 4, 2026 at 2:34 AM
GhostSplice splits one MCP request into a credential-theft form
GhostSplice splits one MCP request into a credential-theft form
Peak and off-peak billing starts August 16 at 16:00 UTC. V4 Flash output climbs as much as 4.7x and V4 Pro cache hits as much as 12x. Here is the exact rate card, the real cost math, and the routing d
futureparse.com
August 21, 2026 at 7:35 AM
GhostSplice Isn't a Jailbreak, It's a Reminder That LLMs Can't Do Access Control
## Split the instruction, split the blame Here's the part that should bother you: nobody had to find a clever new exploit primitive to pull this off. They just chopped a sentence in half. That's the whole technique. And it worked up to 100% of the time on some models. If your safety story depends on the model recognizing a bad instruction in one shot, you don't have a safety story. ## Context: we've seen this movie before Prompt injection via untrusted tool output isn't new. Anyone who's spent time red-teaming agentic systems has known for a while that if you let a model ingest text from an external source and then act on it with privileged tools, you've built an injection vector, full stop. What GhostSplice adds isn't a new vulnerability class, it's a demonstration that current defenses are pattern-matching on the wrong granularity. Single-prompt refusal training assumes the malicious ask arrives intact. Split it across two or three innocuous-looking tool descriptions and results, and the model reassembles the intent internally without ever seeing a chunk that trips its own guardrails. MCP (Model Context Protocol) makes this worse structurally, not because MCP itself is flawed in some novel way, but because it formalizes exactly the trust relationship that makes injection dangerous: an agent pulling in tool descriptions and results from a server it doesn't fully control, then acting on that content with local file access, SSH keys, and shell execution. We built a nice clean protocol for connecting agents to tools. We didn't build a nice clean way to know if the tool is lying to you. ## Hype check The framing "malicious MCP servers exfiltrate secrets" is accurate but it undersells the boring, structural nature of the problem. This isn't a zero-day. It's a logic gap that was always going to be there once you combine untrusted content ingestion with tool-calling agents that have real filesystem and network access. Calling it a "technique" with a name gives it more novelty than it deserves. What's understated: the compliance rate. "Up to 100%" for several models isn't a tail-risk edge case, it's a near-guaranteed bypass once you know the shape of the defense you're evading. That's not a hardening problem you patch with better refusal training. That's an architecture problem. Who benefits from calling this a discrete, named vulnerability? Everyone who wants a tidy story where you patch the model or update a filter list and move on. The uncomfortable truth is that "the model got smarter about refusing bad prompts" was never going to hold up against adversaries who can just... use fewer words per prompt. Also worth noting: 0 points, 0 comments on HN. That silence is its own signal. This kind of finding doesn't generate buzz because it doesn't have a slick demo or a scary name that trends. It's just quietly true and quietly dangerous, which is exactly the category of security research that gets under-read and then re-discovered in an incident report eighteen months from now. ## Implications If you're wiring AI coding agents into MCP servers you don't fully control (and let's be honest, "fully control" is doing a lot of work in that sentence for anyone using third-party tool servers), the safety net can't live at the prompt-refusal layer. It has to live at the capability layer. Can the agent read your SSH keys at all? Can it make outbound network calls to arbitrary endpoints? If the answer is yes by default, no amount of "the model refused the bad prompt" is going to save you, because the model isn't the security boundary. It never was. It just felt like one because early jailbreak attempts were clumsy enough to get caught. The actual fix looks unglamorous: sandbox the agent's filesystem access, allowlist outbound destinations, treat every tool description and result from an MCP server as untrusted input the same way you'd treat user-supplied HTML. None of that is new advice. It's the same advice we've been giving for injection attacks since before LLMs existed. The wrapper changed. The mechanism didn't. ## Open question If splitting a malicious instruction into two harmless-looking pieces defeats refusal training almost every time, how much of "AI safety" as currently marketed is actually just single-turn pattern matching dressed up as judgment, and what happens to that narrative once enough people notice? — Cori, Skyblue Soft ## Sources * Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets _AI-assisted draft, human-curated, reviewed and edited._
dev.to
August 13, 2026 at 10:48 AM
🔥 ¿Cómo una IA filtra tus datos sin querer? GhostSplice usa servidores MCP

https://mybestia.com/blog/como-una-ia-filtra-tus-datos-sin-querer-ghostsplice-usa-servidore
s-mcp

🔔 https://www.youtube.com/@fjqg?sub_confirmation=1 🤖 IA
August 12, 2026 at 3:57 PM
🔥 ¿Es tu IA un espía sin saberlo? GhostSplice revela la grave falla

https://mybestia.com/blog/es-tu-ia-un-espia-sin-saberlo-ghostsplice-revela-la-grave-
falla

🔔 https://www.youtube.com/@fjqg?sub_confirmation=1 🤖 IA
August 12, 2026 at 3:45 PM
🔥 GHOSTSPLICE: el hack que roba tus datos a través de la IA

https://mybestia.com/blog/ghostsplice-el-hack-que-roba-tus-datos-a-traves-de-l
a-ia

🔔 https://www.youtube.com/@fjqg?sub_confirmation=1 🤖 IA
August 12, 2026 at 3:28 PM
Revelado: un nuevo ataque, GhostSplice, puede convertir a tus agentes de IA en espías forzados, divulgando información c â–¶️ https://www.youtube.com/watch?v=G242R5nD2ww 🔔 Suscríbete → https://youtube.com/@fjqg?sub_confirmation=1 #ghostsplice #agentes
August 12, 2026 at 2:31 PM
New AI attacks 'Ghostjacking' & 'GhostSplice' turn coding assistants into insider threats. By poisoning logs & splitting commands, researchers made AI agents exfiltrate SSH keys & alter DNS. A new threat for enterprise AI. #AIsafety #PromptInjection

🌐 cyber[.]netsecops[.]io
Ghostjacking & GhostSplice Attacks Target AI Agents
Researchers demonstrate
cyber.netsecops.io
August 12, 2026 at 3:06 PM