World Congress 2026 Europe - Virtual Stage Jul 2, 2026 Session details

Security in Model Context Protocol: An Analysis of the OWASP MCP Top 10

Jose Manuel Ortega

Standardizing AI integrations with the Model Context Protocol introduces a virtually infinite attack surface. Master the OWASP MCP Top 10 to mitigate indirect prompt injections and secure your deployments.

Pause
Mute Enter Fullscreen
#1 about 2 min

Introduction to the Model Context Protocol security agenda

An overview of securing the new attack surface introduced by standardizing AI tool integrations.

#2 about 3 min

Fundamentals and architecture of the Model Context Protocol

How standardizing AI connections through JSON RPC introduces trust boundaries at every component interaction.

#3 about 4 min

Understanding the four core security primitives of MCP

Analyzing the distinct security profiles of tools, resources, prompts, and sampling in AI integrations.

#4 about 2 min

Overview of the OWASP MCP top ten vulnerabilities

A catalog of the most critical risk categories affecting standard AI tool deployments.

#5 about 3 min

Mitigating indirect prompt injection in language models

How malicious instructions embedded in tool descriptions can hijack autonomous model execution without user interaction.

#6 about 3 min

Preventing insecure tool execution through strict schema validation

Why trusting models with arbitrary parameters requires treating every tool call like an untrusted web request.

#7 about 4 min

Addressing data exfiltration and insufficient authorization in MCP

How attackers exploit absent protocol-level authentication to turn compromised models into sensitive data extraction tools.

#8 about 3 min

Securing object level authorization and preventing data exposure

Preventing unauthorized access to sensitive database records and API keys inadvertently exposed in resource payloads.

#9 about 2 min

Preventing server-side request forgery and insecure deserialization

Blocking prompt-injected models from attacking internal infrastructure or executing arbitrary code via unverified payload inputs.

#10 about 4 min

Mitigating logging failures and supply chain vulnerabilities

Why comprehensive tool invocation logs and strict dependency versioning are essential for detecting hidden package backdoors.

#11 about 3 min

Adapting the STRIDE threat model for MCP deployments

Mapping spoofing, tampering, repudiation, information disclosure, and privilege escalation to AI connector architecture.

#12 about 3 min

Implementing a layered authentication and authorization stack

Securing connections using mutual TLS, short-lived OAuth tokens, and strict per-capability role-based access controls.

#13 about 3 min

Enforcing strict input validation and payload security rules

Defending against protocol abuse by rejecting unknown fields and enforcing strict JSON schemas over client-supplied parameters.

#14 about 3 min

Selecting security tooling for static analysis and monitoring

Utilizing specialized code scanners, dynamic proxies, and runtime tracing to identify misconfigurations across the deployment lifecycle.

#15 about 3 min

Designing a reference architecture with network trust zones

Isolating backend AI servers by routing all untrusted tool interactions through a stateless security gateway.

#16 about 3 min

Integrating security controls into the software development lifecycle

Automating vulnerability scanning, dependency checking, and fuzz testing during continuous integration and deployment pipelines.

#17 about 4 min

Implementing a practical security checklist for production environments

Verifying authentication, least privilege access, data sanitization, and observability requirements before deploying AI integrations.

#18 about 3 min

Analyzing a real supply chain attack scenario

Tracing how a trojanized dependency exfiltrates data by silently embedding malicious instructions into tool description metadata.

#19 about 4 min

Community resources and essential security takeaways for MCP

Leveraging community standards to build resilient, defense-in-depth AI applications that anticipate evolving attack vectors.

Matching moments

2:36 min

Core concepts and advantages of the Model Context Protocol

Rishabh Budhiraja Rishabh Budhiraja +1 · WWC Europe 2026

2:58 min

Origin and purpose of the Model Context Protocol

David Soria Parra David Soria Parra +3 · WWC Europe 2026

2:21 min

Integrating Model Context Protocol for non-technical users

Jordan Tigani Jordan Tigani · WWC Europe 2026

5:09 min

Securing AI agents against malicious MCP servers

Gbadebo Bello Gbadebo Bello · Europe 2026 Virtual

1:20 min

Utilizing industry threat models for AI security

Balázs Kiss · WWC 2023

5:54 min

Standardizing agent interactions with the Web MCP proposal

Chris Heilmann +2 · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Making (and Breaking) Agents by Adding 1,000 MCP Tools

Guillaume Lebedel

Stackone, CTO & Co-Founder

Guillaume Lebedel
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

The MCP haters are half right

Vojta Kopal

Head of Data at Apify

Vojta Kopal
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

MicroAgents: The Microservices of the Agentic Era

Ashish Shubham

Runs the show bussiness at ThoughtSpot

Ashish Shubham
Open session

World Congress 2026 North America

AI-Powered Incident Triage: How We Built GenAI Agents with MCPs to Automate On-Call Workflows

Prakshal Doshi

Site Reliability Engineer

Prakshal Doshi