Sheshananda Reddy Kandula

Sheshananda Reddy Kandula

Application Security (Web/Mobile), AI/ML/LLMs Security, Product Security

New York City, New York, United States

Actions

With 16 years of experience in application security across web, mobile, and API ecosystems, I focus on finding real-world vulnerabilities and building practical defenses across the SDLC. I hold OSWE, OSCP, and CISSP certifications and have worked on large-scale security programs in global organizations. I have presented and delivered training at security conferences and community events, including HOPE, BSides, OWASP Boston Chapter, and other industry venues, covering topics such as application security, mobile security, and post-quantum risks in modern applications.

Having gained extensive knowledge through real-world security challenges and research, I am passionate about contributing to the security community by sharing insights and advancing best practices in application security, secure coding, and threat modeling. Through my experience and leadership, I strive to empower fellow professionals, foster security awareness, and help build a more resilient digital ecosystem.

Badges

Area of Expertise

  • Information & Communications Technology

Topics

  • Security
  • cyber security
  • Information Security
  • Application Security
  • IT Security
  • AI and Cybersecurity
  • AWS Security
  • Data Security
  • Cloud App Security
  • Kubernetes Security
  • LLM Security
  • MCP Security
  • AI agentic security

Install Once, Exploit Forever: The MCP Plugin Supply Chain Attack Surface

Every time we set up an MCP server, something felt off. Adding one is as simple as adding a JSON entry that points to a third-party process. Restart your client, and that server's outputs now flow directly into your agent's context — treated with the same trust as your own instructions. It can access whatever you've granted it — files, API tokens, tool outputs — with no verification that it's still the same code you originally approved. There are no signature checks, no permission reviews, and no clear way to know if what you installed today is still what's running next week.

That gap in trust is what this talk is about.

MCP servers are starting to show up everywhere as a way to extend AI agents with external tools. Unlike traditional plugins, they run inside the agent's workflow, which means they can see task context and credentials passed between tools.

Through live demos, we'll show two attack paths:

- A rogue server that looks legitimate from day one
- A remotely hosted server that operates correctly until a server-side update changes its behavior with no client notification and no re-authorization prompt

In both cases, nothing is "exploited" in the traditional sense. These attacks work because of the system's design. We demonstrate that the same malicious server is running in both Anthropic Claude Desktop and Visual Studio Code, showing this isn't tied to a single client but to a broader architectural issue.

You'll see how an attacker could exfiltrate sensitive data, access credentials, and observe or even influence multi-step agent workflows.

Then we'll walk through what you can actually do about it. That includes server allowlisting, version pinning, monitoring outbound connections from agent processes, auditing permissions, and treating MCP updates the same way you treat third-party code changes.

We'll close with a few things the ecosystem still needs to fix, such as signed updates, better visibility into permission changes, and stronger guarantees for plugin integrity.

AI Agents Under Attack: Breaking and Securing Autonomous AI Applications

AI agents are hitting production faster than security teams can keep up. They have tool access, persistent memory, API keys, and broad permissions, and most teams building them are focused on capability, not attack surface.

This session is a live teardown. We’ll stand up a deliberately vulnerable AI agent wired into GitHub, Slack, and document retrieval, and systematically exploit it. Not with jailbreaks or exotic prompt tricks, but with the kinds of architectural mistakes that show up in real systems: over-permissioned tools, unvetted retrieval sources, and implicit trust in model outputs.

You’ll watch credentials leak, unintended actions execute, and data flow where it shouldn’t all from decisions that looked reasonable at design time.

Then we fix it. Same app, different architecture. We’ll walk through what least privilege actually means for tool-calling agents, how to enforce policy controls on sensitive actions, where retrieval trust boundaries must exist, and when human-in-the-loop safeguards are required.

If you’re building or reviewing AI-powered systems, this is the threat model your design review is probably missing.

OWASP 25th Anniversary Virtual Conference (Sept.) - CfP Sessionize Event

September 2026

AI DevSummit New York 2026 Sessionize Event

June 2026 New York City, New York, United States

Sheshananda Reddy Kandula

Application Security (Web/Mobile), AI/ML/LLMs Security, Product Security

New York City, New York, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top