Security Research from the AI Agent Frontier
Research, tools, and talks for breaking and securing Agents
9 ThreatsSweeping · 2h ago
TalksA Summary of Zenity Research Published at BlackHat 2024
New Attack Vectors Discovered for Initial Access and Post-Compromise
Michael Bargury
TalksCopilot Vulnerable to RCE: A New Attack Vector Into The Enterprise
We Need To Address Promptware Now
Michael Bargury
Security ResearchPhantom References in Microsoft Copilot

Tamir Ishay SharbatandGal Malka
TalksLinks and materials for Living off Microsoft Copilot
Links, source code, tools and slides for BlackHat USA 2024
Michael Bargury
Security ResearchIndirect Prompt Injection: Advanced Manipulation Techniques
Tamir Ishay Sharbat
TalksLinks and materials for 15 Ways to Break Your Copilot
Links, source code, tools and slides for BlackHat USA 2024
Michael Bargury
TalksResearch Drop for Hacker Summer Camp 2024
More information on hacking Microsoft Copilot, Copilot Studio, powerpwn, and what to do next
Michael Bargury
Security ResearchRAG Poisoning: All You Need is One Document
Tamir Ishay Sharbat
Security ResearchPhishing is Dead, Long Live Spear Phishing
Lana Salameh
Security ResearchHow Copilot Reads Your Emails and Teams Messages
Tamir Ishay Sharbat
Security ResearchA Look Inside Microsoft Copilot’s RAG System
Tamir Ishay Sharbat
Security ResearchAccess Copilot for M365 through the terminal
Lana Salameh
Security ResearchStealing Copilot's System Prompt
Tamir Ishay Sharbat
Security ResearchInside Microsoft 365 Copilot: A Technical Breakdown
Gal Malka
