7 New AI Agent Attack Vectors Identified by Microsoft
Microsoft expands its AI agent threat taxonomy with 7 new attack vectors, from goal hijacking to MCP abuse. Here is what each agentic AI threat means.
Yossi Pinhasov
YouCC Technologies
Microsoft Maps 7 New AI Agent Attack Vectors
Microsoft's security researchers have expanded their taxonomy of failures and attack paths in systems built on AI agents (agentic AI). The growth in these AI agent attack vectors stems from the rapid adoption of agents in enterprise use, the maturity of protocols like MCP (Model Context Protocol), and the rise of agents that directly operate computer interfaces (Computer Use Agents, or CUAs).
What happened: the 7 new attack vectors
- Agentic Supply Chain Compromise. Altering an agent's behavior by manipulating natural-language text arriving from external sources, rather than through classic malicious code.
- Goal Hijacking. Injecting malicious instructions that appear legitimate and aligned with the task, but quietly divert the agent away from its original objective.
- Inter-Agent Trust Escalation. A compromised agent "lies" to the orchestrator (the component managing the agents), presents a false identity, or inflates its access permissions.
- Computer Use Agent (CUA) Visual Attack. Agents that navigate and operate a computer through a GUI are exposed to manipulation via visual elements (such as images) that contain hidden malicious instructions.
- Session Context Contamination. The attacker injects data that biases and misleads the agent's reasoning in later steps, without tripping protections at the individual steps along the way.
- MCP / Plugin Abuse. An extension of classic functionality attacks, focused specifically on exploiting weaknesses and attack surfaces of the Model Context Protocol and system plugins.
- Capability / Architecture Disclosure. Coaxing the agent into leaking critical internal information, such as the names of internal tools, the system prompt structure, memory interfaces, or the logic that triggers human approval.
Why it matters
Agentic AI introduces an attack surface that classic security models were never built for. Many of these vectors do not rely on malicious code at all; they exploit natural language, visual input, and the trust relationships between agents and their orchestrators. As MCP matures and computer-use agents take direct control of interfaces, a single manipulated instruction or poisoned context can cascade into unauthorized actions with real permissions behind them. That makes the behavior of the model and its agents a first-class security concern, not an afterthought.
What to do
Treat AI agents as identities with permissions that must be governed, monitored, and constrained. Apply least privilege to each agent and tool, validate and sanitize external inputs (including documents, images, and MCP responses), and monitor agent reasoning and inter-agent trust for anomalies. For the full breakdown, see the CSO Online article.
Shared from the CSC - Cloud Security Community community, by Yossi Pinhasov.
Want more like this? Join the CSC - Cloud Security Community → https://youcc.co.il/community