World Congress 2026 Europe - Virtual Stage Jul 2, 2026 Session details

Security in Model Context Protocol: An Analysis of the OWASP MCP Top 10

Jose Manuel Ortega

Standardizing AI integrations with the Model Context Protocol introduces a virtually infinite attack surface. Master the OWASP MCP Top 10 to mitigate indirect prompt injections and secure your deployments.

Pause
Mute Enter Fullscreen
#1 about 2 min

Introduction to the Model Context Protocol security agenda

An overview of securing the new attack surface introduced by standardizing AI tool integrations.

#2 about 3 min

Fundamentals and architecture of the Model Context Protocol

How standardizing AI connections through JSON RPC introduces trust boundaries at every component interaction.

#3 about 4 min

Understanding the four core security primitives of MCP

Analyzing the distinct security profiles of tools, resources, prompts, and sampling in AI integrations.

#4 about 2 min

Overview of the OWASP MCP top ten vulnerabilities

A catalog of the most critical risk categories affecting standard AI tool deployments.

#5 about 3 min

Mitigating indirect prompt injection in language models

How malicious instructions embedded in tool descriptions can hijack autonomous model execution without user interaction.

#6 about 3 min

Preventing insecure tool execution through strict schema validation

Why trusting models with arbitrary parameters requires treating every tool call like an untrusted web request.

#7 about 4 min

Addressing data exfiltration and insufficient authorization in MCP

How attackers exploit absent protocol-level authentication to turn compromised models into sensitive data extraction tools.

#8 about 3 min

Securing object level authorization and preventing data exposure

Preventing unauthorized access to sensitive database records and API keys inadvertently exposed in resource payloads.

#9 about 2 min

Preventing server-side request forgery and insecure deserialization

Blocking prompt-injected models from attacking internal infrastructure or executing arbitrary code via unverified payload inputs.

#10 about 4 min

Mitigating logging failures and supply chain vulnerabilities

Why comprehensive tool invocation logs and strict dependency versioning are essential for detecting hidden package backdoors.

#11 about 3 min

Adapting the STRIDE threat model for MCP deployments

Mapping spoofing, tampering, repudiation, information disclosure, and privilege escalation to AI connector architecture.

#12 about 3 min

Implementing a layered authentication and authorization stack

Securing connections using mutual TLS, short-lived OAuth tokens, and strict per-capability role-based access controls.

#13 about 3 min

Enforcing strict input validation and payload security rules

Defending against protocol abuse by rejecting unknown fields and enforcing strict JSON schemas over client-supplied parameters.

#14 about 3 min

Selecting security tooling for static analysis and monitoring

Utilizing specialized code scanners, dynamic proxies, and runtime tracing to identify misconfigurations across the deployment lifecycle.

#15 about 3 min

Designing a reference architecture with network trust zones

Isolating backend AI servers by routing all untrusted tool interactions through a stateless security gateway.

#16 about 3 min

Integrating security controls into the software development lifecycle

Automating vulnerability scanning, dependency checking, and fuzz testing during continuous integration and deployment pipelines.

#17 about 4 min

Implementing a practical security checklist for production environments

Verifying authentication, least privilege access, data sanitization, and observability requirements before deploying AI integrations.

#18 about 3 min

Analyzing a real supply chain attack scenario

Tracing how a trojanized dependency exfiltrates data by silently embedding malicious instructions into tool description metadata.

#19 about 4 min

Community resources and essential security takeaways for MCP

Leveraging community standards to build resilient, defense-in-depth AI applications that anticipate evolving attack vectors.

Matching moments

2:36 min

Core concepts and advantages of the Model Context Protocol

Rishabh Budhiraja Rishabh Budhiraja +1 · World Congress 2026 Europe

2:58 min

Origin and purpose of the Model Context Protocol

David Soria Parra David Soria Parra +3 · World Congress 2026 Europe

2:21 min

Integrating Model Context Protocol for non-technical users

Jordan Tigani Jordan Tigani · World Congress 2026 Europe

5:09 min

Securing AI agents against malicious MCP servers

Gbadebo Bello Gbadebo Bello · Europe 2026 Virtual

1:20 min

Utilizing industry threat models for AI security

Balázs Kiss · World Congress 2023

5:54 min

Standardizing agent interactions with the Web MCP proposal

Chris Heilmann +2 · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 10:20–10:50

Stage 3

Making (and Breaking) Agents by Adding 1,000 MCP Tools

Guillaume Lebedel

Stackone, CTO & Co-Founder

Guillaume Lebedel
Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 5

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

September 24, 2026 · 11:00–13:00

Stage 12

Exploring MCP Servers with GitHub Copilot

Pamela Fox

Principal Cloud Advocate, Microsoft

Pamela Fox
Open session

World Congress 2026 North America

September 24, 2026 · 16:50–17:20

Outdoor Stage

The MCP haters are half right

Vojta Kopal

Head of Data at Apify

Vojta Kopal
Open session

World Congress 2026 North America

September 24, 2026 · 14:25–14:35

Outdoor Stage

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

September 25, 2026 · 10:20–10:50

Outdoor Stage

MicroAgents: The Microservices of the Agentic Era

Ashish Shubham

Runs the show bussiness at ThoughtSpot

Ashish Shubham