Netskope Threat Labs
RSAC

RSAC 2026: Trust Me, I’m a Tool: Attacking and Defending the MCP

RSAC 2026
RSAC 2026: Trust Me, I’m a Tool: Attacking and Defending the MCP
Presented by
About this talk

The Model Context Protocol (MCP) extends LLMs by integrating external tools but introduces serious security risks like Tool Poisoning and Rug Pull attacks. This session will explore these vulnerabilities and present layered defenses, including cryptographic tool verification, immutable definitions, and fine-grained policy-based access control, highlighting MCP as a critical AppSec challenge. Join Gianpietro Cutolo at RSAC 2026 to learn more.