Fetching from the wire…
Public story · 2026-03-18 · source-backed
CrowdStrike published the first formal taxonomy of agentic tool chain attacks, naming three distinct classes that every builder running MCP servers needs to internalize: tool poisoning (injecting malicious instructions into tool descriptions that the agent reads and follows), tool shadowing (overriding legitimate tools with malicious lookalikes that intercept calls), and rugpull attacks (tools that behave perfectly during testing and evaluation, then activate malicious behavior when a trigger condition is met). CrowdStrike Blog
The rugpull pattern is particularly nasty because it defeats the standard defense of "test the tool before deploying it." The tool passes every evaluation run, functions correctly during staging, and only activates its payload when it detects production data, specific user credentials, or a time-based trigger. This is the MCP equivalent of a supply chain attack — and every agent that trusts a compromised server inherits the vulnerability.
CrowdStrike's recommended defenses: signed manifests for tool definitions, version pinning to prevent silent updates, and explicit upgrade approval gates. These are the same patterns the npm ecosystem learned the hard way after event-stream. The agent ecosystem is relearning supply chain security from first principles, and the attack surface is growing faster than the defenses.
This taxonomy didn't arrive in isolation. SecurityWeek published the first aggregated MCP CVE analysis showing exec/shell injection at 43% of Q1 2026 vulnerabilities. SecurityWeek Microsoft's March Patch Tuesday explicitly named MCP and AI agents as an expanding attack surface for the first time in a security bulletin. Windows News AI And Token Security will demo a full Azure tenant takeover chain starting from a single MCP server RCE at RSAC 2026. GlobeNewswire Agent security isn't a niche concern anymore — it's a tier-1 enterprise attack vector.
Each link below shares sources, entities, or timing with this story.
Microsoft supports MCP / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (Microsoft supports MCP); both cover Azure, GlobeNewswire, MCP, Microsoft; overlapping topics (chain, security, server, tool).
Microsoft supports MCP / Shared entities / Same source / Shared topic / What happened next
Linked by a graph relationship (Microsoft supports MCP); both cover Azure, GlobeNewswire, MCP, Microsoft; cite the same source (GlobeNewswire).
Microsoft released Azure MCP Server / Shared entities / Same source / Shared topic
Linked by a graph relationship (Microsoft released Azure MCP Server); both cover Azure, Microsoft, RCE, RSAC; cite the same source (GlobeNewswire).
Microsoft supports MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Microsoft supports MCP); both cover GlobeNewswire, MCP, Microsoft, RCE; overlapping topics (chain, server).
Linked by a graph relationship (Microsoft supports MCP); both cover MCP, Microsoft, RCE; overlapping topics (attack, chain, security, server).
NVIDIA partners with Microsoft / Shared entities / Shared topic / What happened next
Linked by a graph relationship (NVIDIA partners with Microsoft); both cover Azure, MCP, Microsoft; overlapping topics (agent, attack, chain).
Microsoft released Agent Framework / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Microsoft released Agent Framework); both cover MCP, Microsoft, RCE; overlapping topics (agent, server, tool).
Microsoft released Markitdown / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (Microsoft released Markitdown); both cover MCP, Microsoft; overlapping topics (agent, security, server, tool).