Security Research from the AI Agent Frontier
Research, tools, and talks for breaking and securing Agents
9 ThreatsSweeping · 2h ago
Featured
From Recon to Exploit: Chaining Attacks on AI Agents (MITRE ATLAS & Zenity Labs)
Working with MITRE to integrate 11 new techniques and subtechniques covering real-world agent reconnaissance, manipulation and abuse
Security ResearchSure, Let AI Browse the Internet—What Could Possibly Go Wrong?
Internet browsing for AI agents leads to 0click compromise but these mitigations can help
Michael Bargury
Security ResearchTTPs.ai for GenAI-Targeted Attacks
Guiding threat simulation and defense for Copilots and Agents
Michael Bargury
Security ResearchOver Permissions in Salesforce Einstein and Unexpected Consequences
Tamir Ishay Sharbat
Security ResearchOutsmarting Copilot: Creating Hyperlinks in Copilot 365
Dmitry Lozovoy
Security ResearchThe Long and Winding Road of DLP Patches in Power Platform
Reviewing Microsoft's Fix for the 'All You Need Is Guest' DLP Bypass
Avishai Efrat
TalksA Summary of Zenity Research Published at BlackHat 2024
New Attack Vectors Discovered for Initial Access and Post-Compromise
Michael Bargury
TalksCopilot Vulnerable to RCE: A New Attack Vector Into The Enterprise
We Need To Address Promptware Now
Michael Bargury
Security ResearchPhantom References in Microsoft Copilot

Tamir Ishay SharbatandGal Malka
TalksLinks and materials for Living off Microsoft Copilot
Links, source code, tools and slides for BlackHat USA 2024
Michael Bargury
Security ResearchIndirect Prompt Injection: Advanced Manipulation Techniques
Tamir Ishay Sharbat
TalksLinks and materials for 15 Ways to Break Your Copilot
Links, source code, tools and slides for BlackHat USA 2024
Michael Bargury
Indirect Prompt Injection: From Initial Success to Robustness
Tamir Ishay Sharbat
TalksResearch Drop for Hacker Summer Camp 2024
More information on hacking Microsoft Copilot, Copilot Studio, powerpwn, and what to do next
Michael Bargury
Security ResearchRAG Poisoning: All You Need is One Document
Tamir Ishay Sharbat
Security ResearchPhishing is Dead, Long Live Spear Phishing
Lana Salameh

