Security Research from the AI Agent Frontier
Research, tools, and talks for breaking and securing Agents
A Read-Only Account is All it Takes to Own a LiteLLM Server
Attackers are abusing a known flaw in Litellm’s admin API to escalate from a low privilege account to full server takeover
Security ResearchAI Agents & 0-Click Exploits: The New Battle Ground for AI Security
Tamir Ishay Sharbat
Autonomous Copilots: Is your Copilot flying solo?
Inbar Raz
Links and materials for Hacking Your Enterprise Copilot: A Direct Guide to Indirect Prompt Injections
Tamir Ishay Sharbat
TalksZenity Research Published at RSAC 2025
Copilots and agents are a new access vector; How to build an AppSec program that scales to the level of citizen development
Michael Bargury
TalksLinks and materials for Scaling AppSec With an SDLC for Citizen Development
Links, demos, tools and slides for RSAC 2025
Michael Bargury
TalksLinks and materials for Your Copilot Is My Insider
Links, demos, tools and slides for RSAC 2025
Michael Bargury
ToolsTechniques from Zenity's GenAI Attacks Matrix Incorporated into MITRE ATLAS to Track Emerging AI Threats
TL;DR: Zenity has partnered with MITRE ATLAS to integrate GenAI Attacks Matrix techniques into the MITRE ATLAS framework, ensuring organizations stay ahead of evolving AI threats. As part of this collaboration, we introduce into ATLAS a new case study and 8 new attack techniques and 4 subtechniques.
Marina Simakov
AI Agents: The New Frontier for Security Researchers
Inbar Raz
The Power of One SSRF Vulnerability: A Multi-Platform Threat
Dmitry Lozovoy
Inside Salesforce Einstein: A Technical Background
Tamir Ishay Sharbat
TalksScaling AppSec With an SDL for Citizen Development
A blog version for the talk presented at BlueHat 2024

Michael BarguryandDon Willits
TalksLinks and materials for Scaling AppSec With an SDL for Citizen Development
Links, demos, tools and slides for BlueHat 2024
Michael Bargury
Security ResearchSure, Let AI Browse the Internet—What Could Possibly Go Wrong?
Internet browsing for AI agents leads to 0click compromise but these mitigations can help
Michael Bargury
Security ResearchTTPs.ai for GenAI-Targeted Attacks
Guiding threat simulation and defense for Copilots and Agents
Michael Bargury
Security ResearchOver Permissions in Salesforce Einstein and Unexpected Consequences
Tamir Ishay Sharbat


