Security Research from the AI Agent Frontier
Research, tools, and talks for breaking and securing Agents
9 ThreatsSweeping · 2h ago
Security ResearchAgentFlayer: ChatGPT Connectors 0click Attack
Tamir Ishay Sharbat
AI Enterprise Compromise - 0click Exploit Methods
Michael Bargury
Security ResearchAgentFlayer: When a Jira Ticket Can Steal Your Secrets
TL;DR: A 0click attack through a malicious Jira ticket can cause Cursor to exfiltrate secrets from the repository or local file system.
Marina Simakov
Why Aren’t We Making Any Progress In Security From AI
Guardrails Are Soft Boundaries. Hard Boundaries Do Exist.
Michael Bargury
Reconstructing a timeline for Amazon Q prompt infection
How a rogue GitHub commit, automation missteps, and a deceptive AI assistant led to one of the most bizarre prompt injection cases in recent memory.
Michael Bargury
Security ResearchAgentFlayer: When AIjacking Leads to Full Data Exfiltration in Copilot Studio
Tamir Ishay Sharbat
I Just Wanted to Take a Note — and Your Token Came Along
Dmitry Lozovoy
Security ResearchEchoLeak: A Reminder That AI Agent Risks Are Here to Stay
Marina Simakov
Security ResearchAgentFlayer: Discovery Phase of AI Agents in Copilot Studio
Tamir Ishay Sharbat
LLM vs. LLM: It's a MAD world.
Inbar Raz
Security ResearchAI Agents & 0-Click Exploits: The New Battle Ground for AI Security
Tamir Ishay Sharbat
Autonomous Copilots: Is your Copilot flying solo?
Inbar Raz
Links and materials for Hacking Your Enterprise Copilot: A Direct Guide to Indirect Prompt Injections
Tamir Ishay Sharbat
TalksZenity Research Published at RSAC 2025
Copilots and agents are a new access vector; How to build an AppSec program that scales to the level of citizen development
Michael Bargury
TalksLinks and materials for Scaling AppSec With an SDLC for Citizen Development
Links, demos, tools and slides for RSAC 2025
Michael Bargury

