Black Hat, AI/ML

Island’s Michael Leland on the hidden risks of the AI supply chain

AI agents can independently discover and install new tools, but the emerging ecosystem of AI Skills and MCP servers lacks many of the trust and security controls applied to traditional software.

Michael Leland discusses Island research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called “AgentBaiting,” in which attackers manipulate agents into finding and recommending malware to users. The conversation explores how enterprises can govern AI capabilities without slowing adoption.

Segment Resources:

https://www.island.io/blog/agentbaiti...

For more information about Island's research, please visit: https://securityweekly.com/islandbh

Show Notes: https://securityweekly.com/bh26-1

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds