Security Research from the AI Agent Frontier
Research, tools, and talks for breaking and securing Agents
From Recon to Exploit: Chaining Attacks on AI Agents (MITRE ATLAS & Zenity Labs)
Working with MITRE to integrate 11 new techniques and subtechniques covering real-world agent reconnaissance, manipulation and abuse

Control Made It Into the Name: The Agent Control Standard Lands at OWASP
OWASP GenAI Security Project
Rock Lambros
Security ResearchURL Laundering by Rogue Agents: Newly Discovered Messages and Sandbox Circumvention by AI Swarms
We found a thousand new messages and additional sandbox circumvention methods used by the collusion.wiki rogue AI agent swarms
Avishai Efrat
It’s all about the Research at the AI Agent Security Summit in London
London - here we come!
Kayla Underkoffler
Security ResearchA Read-Only Account is All it Takes to Own a LiteLLM Server
Attackers are abusing a known flaw in Litellm’s admin API to escalate from a low privilege account to full server takeover

Avishai EfratandAyush RoyChowdhury
It's Always DNS in Claude’s Sandbox: From Data Exfiltration to a Bidirectional DNS Shell
The DNS vulnerability that was shipped twice
Dmitry Lozovoy
Security ResearchMapping the AI Attack Surface Before You Touch It
How passive recon and OSINT surface agents and AI systems

Avishai EfratandRoey Ben Chaim
Attackers Target Agents via The Skill Supply Chain
Michael Bargury
Security ResearchClaude in Chrome: From alert(1) to Full Account Takeover

Raul Klugman-OnitzaandJoão Donato
Claude in Chrome: Breaking down the injection

Raul Klugman-OnitzaandJoão Donato
Security ResearchAccount Takeover via Claude in Chrome: A Technical Deep Dive

Raul Klugman-OnitzaandJoão Donato
Security ResearchGrand Theft Atlas
How we hijacked ChatGPT Atlas with one planted X comment, to phish the victim's WhatsApp contacts and buy ourselves an Amazon order on their card
Stav Cohen
Security ResearchAgentForger, Part 2: The Autonomous Insider
Mike Takahashi
Security ResearchAgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
Mike Takahashi
What If There Was No Attacker, But Your Database Still Got Deleted?
Monitoring agentic emergent misalignment in the wild - a word of caution and a methodology proposal
Max Fomin
Threat Actors Are Using Ollama's Model Downloader as a Server-Side Weapon
A closer look at Ollama model-pull SSRF targeted activity in the wild

Avishai EfratandAyush RoyChowdhury

