AgentBaiting: How Attackers Use Fortune 500 Brands & GitHub to Deliver Malware

Island security researchers Chris Gaun and Oleg Zaytsev sat down with John Hammond, one of the most recognized names in cybersecurity education, for a candid 30-minute conversation about what they found when they audited the AI tool ecosystem — and what it means for any organization deploying AI agents today.

Webinar Overview

After scanning more than 30,000 MCP servers and 450,000 AI tools, Island's security team found 7,600 malicious GitHub repositories built to deceive users and AI agents alike into installing malware. The attack doesn't rely on malicious code. It relies on plain English instructions that no scanner catches.

You’ll come away understanding:

  • What AgentBaiting is and how the fake Git campaign evolved into an AI-native attack vector
  • Why 50% of the MCP servers Island scanned had at least one security finding, and what that means for organizations deploying AI agents
  • How plain English prompt injection evades traditional security scanners and why that changes your threat model
  • Why AI agents are being targeted as attack surfaces in their own right, not just as delivery mechanisms
  • What an MCP gateway approach looks like and how organizations can gain visibility into the tools their agents a

Speakers

Oleg Zaytsev
Lead Security Researcher
Chris Gaun
VP, Product Marketing
John Hammond
Cybersecurity Educator

Who should attend

Security practitioners, CISOs, and IT leaders who are deploying AI agents or evaluating MCP integrations — and anyone responsible for understanding how the AI tool supply chain introduces new risk into the enterprise.