MCP Security

MCP Security examines the security of the Model Context Protocol as AI agents connect to tools, data, APIs, and enterprise systems. Coverage includes MCP servers, identity, authentication, authorization, delegated authority, tool security, credential exposure, prompt injection, supply chain risks, and attack paths—with a focus on how CISOs can govern and secure MCP as emerging enterprise infrastructure.
11
Sep
Prompt Injection Is Becoming an Execution Problem

Prompt Injection Is Becoming an Execution Problem

14 min read
10
Sep
The New AI Supply Chain

The New AI Supply Chain

The AI supply chain no longer delivers only software. Models, prompts, skills, MCP servers and runtimes can all shape execution. CISOs must start governing not only executable code, but executable meaning.
12 min read
23
Aug
The AI Supply Chain Can Execute Before the Application Does

The AI Supply Chain Can Execute Before the Application Does

AI artifacts are no longer passive data. DEF CON 34 shows how models, Skills, repositories and loaders can become execution paths — forcing CISOs to rethink supply-chain security, provenance and runtime authority.
14 min read
19
Aug
MCP Is Becoming Enterprise Infrastructure

MCP Is Becoming Enterprise Infrastructure

MCP is becoming enterprise infrastructure. As AI agents gain access to tools, identities and business systems, CISOs must govern not just integration — but the authority flowing through it.
15 min read
18
Aug
The Agent Is the New Attack Path

The Agent Is the New Attack Path

A safe model does not imply a safe agent. Agentic AI shifts the security problem from jailbreaks to authority: can an attacker make the system perform an authorized action for an unauthorized reason?
17 min read
18
Aug
When Data Becomes Instruction

When Data Becomes Instruction

AI agents are erasing the boundary between data and instruction. DEF CON 34 shows why untrusted context can become an indirect control plane—and why CISOs must secure the entire path from meaning to authority.
15 min read