Loading…
OWASP 25th Anniversary Virtual Conference (September)
Tuesday September 22, 2026 1:00pm - 1:55pm PDT
Every time we set up an MCP server, something felt off. Adding one is as simple as adding a JSON entry that points to a third-party process. Restart your client, and that server's outputs now flow directly into your agent's context — treated with the same trust as your own instructions. It can access whatever you've granted it — files, API tokens, tool outputs — with no verification that it's still the same code you originally approved. There are no signature checks, no permission reviews, and no clear way to know if what you installed today is still what's running next week.

That gap in trust is what this talk is about.

MCP servers are starting to show up everywhere as a way to extend AI agents with external tools. Unlike traditional plugins, they run inside the agent's workflow, which means they can see task context and credentials passed between tools.

Through live demos, we'll show two attack paths:

- A rogue server that looks legitimate from day one
- A remotely hosted server that operates correctly until a server-side update changes its behavior with no client notification and no re-authorization prompt

In both cases, nothing is "exploited" in the traditional sense. These attacks work because of the system's design. We demonstrate that the same malicious server is running in both Anthropic Claude Desktop and Visual Studio Code, showing this isn't tied to a single client but to a broader architectural issue.

You'll see how an attacker could exfiltrate sensitive data, access credentials, and observe or even influence multi-step agent workflows.

Then we'll walk through what you can actually do about it. That includes server allowlisting, version pinning, monitoring outbound connections from agent processes, auditing permissions, and treating MCP updates the same way you treat third-party code changes.

We'll close with a few things the ecosystem still needs to fix, such as signed updates, better visibility into permission changes, and stronger guarantees for plugin integrity.
Speakers
avatar for Sheshananda Reddy Kandula

Sheshananda Reddy Kandula

Test, Test
With 16 years of experience in application security across web, mobile, and API ecosystems, I focus on finding real-world vulnerabilities and building practical defenses across the SDLC. I hold OSWE, OSCP, and CISSP certifications and have worked on large-scale security programs in... Read More →
Tuesday September 22, 2026 1:00pm - 1:55pm PDT

Attendees (1)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link