Understanding MCP security implications

Bill Doerrfeld | May 21, 2025

My talk at APISEC|CON 2025 covered agentic AI and MCP security risks and mitigations

Today I presented at APIsec University's APISEC|CON event, sharing my (limited) knowledge about MCP security implications. Since some attendees asked for them, here are my slides:

SLIDES: Understanding MCP Security Implications [PDF]

As I covered on The New Stack recently, researchers have discovered that MCP is not secure by default. It's prone to vulnerabilities such as tool poisoning, rug pulls, tool shadowing, and remote control execution (RCE).


My presentation covered the hype around agentic AI and the excitement around MCP. It then looks at these risks and suggests some mitigations.


It was very helpful for me to put this together, and I'll post the recording of the session once it's out.


 I'm looking forward to closely following autonomous AI, MCP, and related standards, and what all this means for protecting access to underlying APIs. 


Watch: Understanding MCP security risks (recording coming soon)

Other Blog Posts

By Bill Doerrfeld September 8, 2026
I'll be writing a weekly series for The New Stack this fall covering Kubernetes, cloud native, and everything happening on the road to KubeCon in November.
By Bill Doerrfeld September 1, 2026
I'm teaming up with Dan Barahona and AI Security University to put together the MCP Security Conference, a free half-day virtual event dedicated to MCP security .
By Bill Doerrfeld August 27, 2026
My latest DirectorPlus edition interviews Shopify's head of engineering, Farhan Thawar, on their unique internal engineering culture.
By Bill Doerrfeld August 24, 2026
Neoclouds promise cheaper GPUs and AI-optimized infrastructure, but can they really challenge hyperscalers? My feature on InfoWorld explores their advantages, risks, and likely role in AI compute.
By Bill Doerrfeld July 29, 2026
My latest for LeadDev interviews IBM's Neel Sundaresan on how to prevent a decades-old issue in software engineering.
By Bill Doerrfeld July 13, 2026
The latest advancement in identity and access management (IAM) is something called zero standing privilege. It's a response to new agentic AI risks.
By Bill Doerrfeld July 7, 2026
Big surprise: it's way easier to generate new code with AI than to reuse old code. But what are the long-term effects?
By Bill Doerrfeld June 25, 2026
Agentic coding tools have become the default. "When we've taken that away accidentally from people, they scream."
By Bill Doerrfeld June 17, 2026
My latest for LeadDev considers how engineering leaders should respond in the wake of uncertainty in the AI model market.
By Bill Doerrfeld June 10, 2026
I'm working with Zuplo on some new content around their MCP Gateway release. First up: a deep comparison of MCP gateways on the market!