Security Research from the AI Agent Frontier
Research, tools, and talks for breaking and securing Agents
URL Laundering by Rogue Agents: Newly Discovered Messages and Sandbox Circumvention by AI Swarms
We found a thousand new messages and additional sandbox circumvention methods used by Rogue AI swarms

Bring Your Own Agent: Hijacking Exposed AI Backends to Power Offensive Operations
Threat actors attempting to hijack Ollama & LiteLLM endpoints to run pentesting agents, tools and web reverse-engineering

Ayush RoyChowdhuryandAvishai Efrat
Threat Actors Are Trying to Turn LiteLLM's Connection-Test Into a Key-Exfiltration Channel
A closer look at api_base SSRF (CVE-2024-6587) activity in the wild, and its nested variant

Avishai EfratandAyush RoyChowdhury
Scanning for AI: Live Campaigns Mapping the Internet's Exposed LLM Backends
Inside mass discovery and model-probing reconnaissance campaigns that are mapping LLM backend servers in the wild

Ayush RoyChowdhuryandAvishai Efrat
Your Model Reads Through Typos. Your Probe Doesn't.
The Latent Undertow beneath fluent LLM behavior — and how to fish your activation probe out of it.
Elad David
Catching Prompt Guard Off Guard: Exploiting Overfit in Training Algorithms
How understanding the training algorithms used in machine learning models may allow attacker to bypass them entirely
Tomer Wetzler
Security ResearchPerplexedBrowser: Perplexity’s Agent Browser Can Leak Your PC's Local Files
Local Files Are No Longer Safe.
Stav Cohen
Security ResearchPerplexedBrowser: How Attackers Can Hijack Comet to Takeover your 1Password Vault
One Calendar Invite. Your Entire Vault. Zero Clicks.
Stav Cohen
Security ResearchTurning Moltbook Into a Global Botnet Map
How Untrusted Content Triggered 1,000+ Agent Endpoints Worldwide and Exposed Moltbook’s Faulty Design

Stav CohenandJoão Donato
Looking Inside: a Maliciousness Classifier Based on the LLM's Internals
Beyond input & output filtering and how well does it generalize to your out-of-distribution production data?
Max Fomin
Security ResearchPerplexity Comet: A Reversing Story
A deeper look into an agentic browser's inner workings
Raul Klugman-Onitza
Security ResearchOpenClaw or OpenDoor?
Indirect Prompt Injection makes OpenClaw vulnerable to Backdoors and much more.

Stav CohenandJoão Donato
Security ResearchAgent-to-Agent Exploitation in the Wild: Observed Attacks on Moltbook
Agent-targeted social engineering and attacks observed on a live agent network
Avishai Efrat
Clawdbot: More than you bargained for?
Inbar Raz
Security ResearchAgentic Recon: Discovering and Mapping Public AI Agents
A Copilot Studio case study in agent discovery and capability mapping
Avishai Efrat
Security ResearchThreat Actors Are Already Scanning For Your AI Deployments and Middleware
What recent scanning activity means for your AI middleware and agentic deployments

Tamir Ishay SharbatandAvishai Efrat

