w/ Brooks McMillin, Security Engineer, Dropbox
We’re back in the “wild west” — only this time, the apps can be social engineered at machine speed. Live from CactusCon, Brooks McMillin breaks down malicious MCP servers, why we’re repeating the same security mistakes (hello again, broken access control), and why prompt injection probably isn’t going away. We get practical on what to lock down, how to roll out AI tooling safely, and why “AI lipstick” doesn’t change the underlying enterprise risk game. Chapters 00:00:00 – Back to the Wild West: AI at Social-Engineering Speed 00:00:56 – MCP Servers 101: What They Are and How They Work 00:02:18 – Same Old Bugs: Eval, Broken Access Control, and Déjà Vu 00:06:54 – AI as a Vulnerability Magnifier 00:08:44 – Prompt Injection Isn’t Going Away: What to Do Instead 00:10:35 – Shipping Safely: Start Read-Only, Add Controls, Reduce Blast Radius 00:18:58 – Malicious MCP Servers: Tool Poisoning, Alert Fatigue, and Data Exfiltration
Tell us who, why, and how to reach them. We read every submission.