Get the latest tech news

MCP Will Be Built Into Windows To Make an 'Agentic OS' - Bringing Security Concerns


It's like "a USB-C port for AI applications..." according to the official documentation for MCP — "a standardized way to connect AI models to different data sources and tools." And now Microsoft has "revealed plans to make MCP a native component of Windows," reports DevClass.com, "despite co...

A single prompt might, for example, fire off a workflow which queries data, uses it to create an Excel spreadsheet complete with a suitable chart, and then emails it to selected colleagues. Microsoft corporate VP David Weston noted seven vectors of attack, including cross-prompt injection where malicious content overrides agent instructions, authentication gaps because "MCP's current standards for authentication are immature and inconsistently adopted," credential leakage, tool poisoning from "unvetted MCP servers," lack of containment, limited security review in MCP servers, supply chain risks from rogue MCP servers, and command injection from improperly validated inputs. This will enable centralized enforcement of policies and consent, as well as auditing and a hook for security software to monitor actions.

Get the Android app

Or read this on Slashdot

Read more on:

Photo of Windows

Windows

Photo of mcp

mcp

Related news:

News photo

MCP is the coming of Web 2.0 2.0

News photo

In 3.5 years, Notepad.exe has gone from “barely maintained” to “it writes for you” | AI features in Windows are gradually becoming more widespread and inescapable.

News photo

Microsoft says Lumma password stealer malware found on 394,000 Windows PCs