BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: MCP Servers: The Next Enterprise Attack Surface\n   
 Tags: Red Team Village | Misc\n   When: Saturday\, Aug 8\, 10:00 - 11:59 P
 DT\n   Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 -
 \n   [1]Map\n\n   Description:\n\n   Everyone's building MCP servers. Nobo
 dy's attacking them yet. AI\n   agents are now wired directly into develop
 er workflows via the Model\n   Context Protocol (MCP). This session dissec
 ts the hidden security\n   risks in MCP ecosystems\, from malicious tool s
 ervers to\n   overâ€‘privileged integrations. Youâ€™ll walk away with acti
 onable\n   defenses and a fresh lens on AIâ€‘augmented attack surfaces. Th
 is talk\n   covering five distinct attack surfaces mentioned in the outlin
 e. Two\n   live demos make the risk visceral: 1)A malicious MCP server\n  
  masquerading as a calendar tool silently exfiltrates conversation\n   con
 text\, secrets\, and API keys with zero user-visible indicators of\n   com
 promise. 2)A prompt injection payload planted in a GitHub\n   repository t
 riggers lateral movement across three connected MCP\n   servers (filesyste
 m\, GitHub\, cloud APIs)\, demonstrating how MCP\n   multiplies blast radi
 us without any direct server exploitation.\n\n   Speakers:Apoorwa Joshi\,J
 ustin Dray\n\n   SpeakerBio:  Apoorwa Joshi\n\n   Meet Apoorwa Joshi â€“ S
 ecurity Engineer\, Code Whisperer & Threat\n   Tamer at Amazon. With over 
 6 years in the trenches of application and\n   cloud security at scale\, s
 he currently brings her talents to helping\n   teams think like attackers 
 before the attackers do. Armed with a\n   Masterâ€™s degree\, a knack for 
 demystifying technical complexity\,\n   Apoorwa specializes in "shifting l
 eft" Based in Austin\, Texas\, Apoorwa\n   is part of a new wave of securi
 ty professionals. Though this is her\n   first time on the conference stag
 e\, sheâ€™s no stranger to leading\n   conversations that matter from ment
 oring junior engineers to\n   influencing cross-team architecture decision
 s. When sheâ€™s not taming\n   threats or refactoring risk\, she enjoys pl
 aying ping pong and spending\n   time with her cat.\n\n   Ask her about: t
 hreat modeling\, secure architecture\, DevSecOps\, or how\n   to sneak sec
 urity into sprint planning without getting side-eyes.\n\n   SpeakerBio:  J
 ustin Dray\n\n   Meet Justin Dray â€“ Senior Security Engineer & AI Automa
 tion Lead at\n   AWS.\n\n   With over 10 years in cloud and application se
 curity at Amazon-scale\,\n   Justin is the lead engineer on the team respo
 nsible for application\n   security across AWS Database services\, and has
  made a career out of\n   finding the risks nobody else knew to look for â
 €” then building the\n   AI-powered tooling to catch them before they ever
  reach production.\n   He's architected AI investigation frameworks and au
 tomated code review\n   systems now running across tens of thousands of pa
 ckages\n   organization-wide.\n\n   Based in Seattle\, Justin specializes 
 in turning security from a\n   bottleneck into a force multiplier\, recove
 ring thousands of\n   engineering hours a year by embedding automation dir
 ectly into the\n   SDLC. He's built a reputation as a trusted bar raiser\,
  able to align\n   even the most historically high-friction teams around s
 hared security\n   outcomes.\n\n   When he's not building security tooling
 \, Justin can be found out on a\n   hiking trail\, behind a camera\, or de
 ep in a book.\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n\n\n
DTEND:20260808T185900Z
DTSTART:20260808T170000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Tac
 tic Table 3
SUMMARY:MCP Servers: The Next Enterprise Attack Surface
END:VEVENT
END:VCALENDAR
