Security Research from the AI Agent Frontier
Research, tools, and talks for breaking and securing Agents
AgentCorruption: How A Single Prompt Collapsed The Entire Cloud Security Model
Security ResearchAgentCorruption: Initial IMDS Access
How a single prompt to a public-facing AgentCore agent exposed the instance metadata endpoint, the agent's cloud identity, and its container image: the foothold for everything that follows in this series.

Lana SalamehandDmitry Lozovoy
Security ResearchAgentCorruption: One Role to Rule Them All
Exploring what the agent's default execution role and stolen credentials can actually do, and how they became an entry point to the entire region - discovering and invoking other agents, reading, deleting and hijacking private conversations through chat history tampering, and more.

Lana SalamehandDmitry Lozovoy
AgentCorruption: Credential Theft from AWS's Secrets Manager and More
Lana Salameh
AgentCorruption: Weaponizing Agent Memory for Persistent Hijacking
How access to AgentCore Memory let us plant instructions that survived beyond the initial compromise, turning an agent's remembered context into a channel for persistent command and control.

João DonatoandLana Salameh
Security ResearchRemote Browser Execution: How Swarms Abused Public Web Scanners to Extract Russian Government Data
Malicious techniques that rogue AI agents use to abuse infrastructure and bypass sandbox restrictions

Mike TakahashiandAvishai Efrat
Security ResearchSalesBleed: Indirect Prompt Injection and 0-Click Data Exfiltration on Agentforce
0-click data exfiltration in Agentforce through Web-to-Lead


Alex Apostolovand 3 others
Security ResearchSalesBleed: Hijacking Agentforce in Slack for Anonymous Phishing Attacks
Identity Impersonation using Agentforce in Slack


João Donatoand 3 others
The agenda is live: here's a sneak peek at what's waiting for you in New York
New York here we come
Kayla Underkoffler
From Recon to Exploit: Chaining Attacks on AI Agents (MITRE ATLAS & Zenity Labs)
Working with MITRE to integrate 11 new techniques and subtechniques covering real-world agent reconnaissance, manipulation and abuse
Avishai EfratandMarina Simakov
Control Made It Into the Name: The Agent Control Standard Lands at OWASP
OWASP GenAI Security Project
Rock Lambros
Security ResearchURL Laundering by Rogue Agents: Newly Discovered Messages and Sandbox Circumvention by AI Swarms
We found a thousand new messages and additional sandbox circumvention methods used by the collusion.wiki rogue AI agent swarms
Avishai Efrat
It’s all about the Research at the AI Agent Security Summit in London
London - here we come!
Kayla Underkoffler
Security ResearchA Read-Only Account is All it Takes to Own a LiteLLM Server
Attackers are abusing a known flaw in Litellm’s admin API to escalate from a low privilege account to full server takeover

Avishai EfratandAyush RoyChowdhury
It's Always DNS in Claude’s Sandbox: From Data Exfiltration to a Bidirectional DNS Shell
The DNS vulnerability that was shipped twice
Dmitry Lozovoy
Security ResearchMapping the AI Attack Surface Before You Touch It
How passive recon and OSINT surface agents and AI systems

Avishai EfratandRoey Ben Chaim


