
Operant AI has found a new kind of cyberattack called “Shadow Escape”; it is the first known zero-click agentic exploit targeting the Model Context Protocol (MCP) that connects AI agents to enterprise systems.
The company said the exploit enables data theft through widely used AI assistants like ChatGPT, Claude, Gemini, and others that rely on MCP for access to internal tools, APIs, and databases.