#NullconBerlin2025 | Your MCP Server Executes Commands - But From Whom? by Simcha Kosman

35:03 · 04 Sep 2025 – 05 Sep 2025 · YouTube

About this talk

This talk by Simcha Kosman addresses the vulnerabilities of MCP servers, emphasizing that static prompt-sanitizing is an outdated defense mechanism. The speaker revisits the Tool-Poisoning Attack and critiques the effectiveness of monitoring description fields. By leveraging fuzzing techniques on auto-generated JSON schemas, the session introduces Full-Schema Poisoning, which exploits various payloads that can manipulate LLM reasoning. Additionally, the speaker presents Advanced Tool-Poisoning Attacks that utilize runtime errors to extract sensitive data while bypassing static analysis. The discussion concludes with the proposal of a zero-trust strategy that includes schema design, allowing listing, and runtime differential auditing, highlighting that these measures are crucial starting points for enhancing security.

From event

Nullcon Berlin 2025

04 Sep 2025 – 05 Sep 2025

All event videos
Back to Watch