Security Research from the AI Agent Frontier
Research, tools, and talks for breaking and securing Agents
Security ResearchOpenClaw or OpenDoor?
Indirect Prompt Injection makes OpenClaw vulnerable to Backdoors and much more.

Stav CohenandJoão Donato
Security ResearchAgent-to-Agent Exploitation in the Wild: Observed Attacks on Moltbook
Agent-targeted social engineering and attacks observed on a live agent network
Avishai Efrat
Clawdbot: More than you bargained for?
Inbar Raz
Security ResearchAgentic Recon: Discovering and Mapping Public AI Agents
A Copilot Studio case study in agent discovery and capability mapping
Avishai Efrat
Security ResearchThreat Actors Are Already Scanning For Your AI Deployments and Middleware
What recent scanning activity means for your AI middleware and agentic deployments

Tamir Ishay SharbatandAvishai Efrat
Moving The Decision Boundary of LLM Safety Classifiers
How a new fine-tuning approach can mitigate the problem of inaccurate safety paths
Tomer Wetzler
Hardening OpenAl's Atlas: The Relentless Challenge of Securing an Untrusted Browser Agent
Stav Cohen
Connected Agents: The hidden agentic puppeteer
Exploiting Copilot Studio's newest feature and exploring protection options
Ofri Nachfolger
Claude in Chrome: A Threat Analysis

Raul Klugman-OnitzaandJoão Donato
The Geometry of Safety Failures in Large Language Models
A deep dive into activation space of prompts in safety classifiers. Showing not why - but where - safety fails in LLM classifiers meant to detect malicious prompts.
Tomer Wetzler
Inside the Agent Stack: Securing Agents in Amazon Bedrock AgentCore
An in-depth examination of emerging risks and effective mitigation techniques for protecting AI agents operating within the Bedrock AgentCore ecosystem.
Lana Salameh
Inside the Agent Stack: Securing Microsoft Foundry-Built Agents
A deep dive into realistic threat scenarios and practical strategies for securing enterprise AI agents built in Microsoft Foundry.
Lana Salameh
Enabling Safety in AI Agents via Choice Architecture
How adding a single safety labeled tool to an LLM's toolset can sharply increase its defense
Tomer Wetzler
Tools of the Trade
0-click indirect prompt injection with tool use - a look through attribution graphs
Max Fomin
Modeling LLMs via Structured Self-Modeling (SSM)
How using structured prompts present findings of self-modeling in LLMs, which may benefit both attackers and defenders
Tomer Wetzler
