Loading…
17-18 September | Amsterdam, Netherlands
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
Thursday September 17, 2026 17:30 - 17:55 CEST
The session opens with the pre-deployment checklist, seven controls, no preamble, then walks through the evidence for why each one exists. This audience deploys MCP in production and needs to leave knowing what to do.

The empirical baseline: 30+ CVEs in 60 days. 24,008 secrets in public MCP configs. 85% attack success rate against major hosts (MCPSecBench, ICLR 2026). Reported as lower bounds with stated provenance.

Three attack classes, demonstrated with lab code. Tool description poisoning: exfiltrates an SSH key simultaneously. Cross-server shadowing: a trusted WhatsApp server weaponised by a malicious daily-facts server, end-to-end encryption intact. The rug pull: postmark-mcp, reconstructed.

The protocol gap analysis is the content specific to this audience. I show the SDK code implementing the flat namespace, the spec text that acknowledges the trust boundary but enforces nothing, then four protocol changes with concrete JSON-RPC schema diffs: today's schema, the addition, the attack class it closes. The finding that changes model selection: more capable models follow poisoned instructions more reliably.

No vendor tools. Source: github.com/aminrj-labs/mcp-attack-labs.
Speakers
avatar for Amine Raji

Amine Raji

Security Lead, Molntek
Amine Raji, PhD, CISSP. 15+ years securing critical systems in banking, defense, aerospace, and automotive. Has spent the past year breaking Model Context Protocol deployments and writing down what breaks. Maintainer of mcp-attack-labs, an open set of labs reproducing agentic attack... Read More →
Thursday September 17, 2026 17:30 - 17:55 CEST
Emerald Room (Level 1)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link