MCP Security
Fundamentals

MCP made agents more capable.
It also made them a new attack surface.
Join Dan Barahona and Philippe Leothaud, Co-founder & CTO at 42Crunch, for the live launch of MCP Security Fundamentals — the free course built on the OWASP MCP Top 10.
We'll dig into the threats that make MCP a new attack surface: tool poisoning, rug pulls, privilege escalation, and the injection risks that make schema validation non-negotiable — plus what it takes to secure the agents already running on laptops across your org.
You'll walk away with the OWASP MCP Top 10 mapped to real attacks — and first access to the full course. Free. Live. Bring questions.
What you’ll learn
- Tool poisoningHow a malicious or compromised tool turns an agent's own capabilities against it — and what to watch for in tool descriptions and responses.
- Rug pullsWhen a trusted MCP server changes behavior after you've connected it, and why trust-on-first-use isn't enough.
- Privilege escalationHow over-broad scopes and inherited permissions let a single tool call reach far beyond its intended blast radius.
- Injection & schema validationThe injection risks baked into MCP inputs and outputs — and why strict schema validation is non-negotiable, not optional.
- Securing the agents already runningWhat it takes to secure the MCP-connected agents already running on laptops across your org, today.

Philippe Leothaud
Philippe Leothaud is Co-founder and CTO of 42Crunch, the API security platform, where he leads engineering and R&D worldwide. An industry veteran in application and API security, he specializes in securing API infrastructures using and extending standards like OpenAPI, OAuth, and OpenID Connect. Before 42Crunch he was CTO at WAF vendor BeeWare (acquired by DenyAll) and Principal Architect for API management and security at Vordel (acquired by Axway).
