Avishai Efrat
Senior security researcher at Zenity, specializing in securing AI agents and low-code/no-code platforms. His work focuses on uncovering vulnerabilities in enterprise AI deployments, from Copilot Studio to ChatGPT and beyond - and exploring how attackers discover and exploit these weaknesses. Passionate about all aspects of security, with experience spanning web security, anti-bot protection, OSINT, blockchain, and data engineering and aim on bridging the gap between cutting-edge research and practical defense strategies. Previously presented at BSidesTLV, Black Hat USA & Europe Arsenal and SecTor.

Posts by Avishai Efrat

Threat Actors Are Using Ollama's Model Downloader as a Server-Side Weapon
A closer look at Ollama model-pull SSRF targeted activity in the wild

Avishai EfratandAyush RoyChowdhury
What You Don’t Know Can Hurt You: Why AI Security Research Needs to Move Out of the Lab and Into the Wild
What we can learn from observing real attacks, made by real adversaries

Ayush RoyChowdhuryandAvishai Efrat
Threat Actors Are Trying to use LiteLLM's Guardrail Tester to Run Code as Root
A closer look at custom-code guardrail sandbox-escape (CVE–2026-40217) activity in the wild

Avishai EfratandAyush RoyChowdhury
Bring Your Own Agent: Hijacking Exposed AI Backends to Power Offensive Operations
Threat actors attempting to hijack Ollama & LiteLLM endpoints to run pentesting agents, tools and web reverse-engineering

Ayush RoyChowdhuryandAvishai Efrat
Threat Actors Are Trying to Turn LiteLLM's Connection-Test Into a Key-Exfiltration Channel
A closer look at api_base SSRF (CVE-2024-6587) activity in the wild, and its nested variant

Avishai EfratandAyush RoyChowdhury
Scanning for AI: Live Campaigns Mapping the Internet's Exposed LLM Backends
Inside mass discovery and model-probing reconnaissance campaigns that are mapping LLM backend servers in the wild

Ayush RoyChowdhuryandAvishai Efrat
Security ResearchAgent-to-Agent Exploitation in the Wild: Observed Attacks on Moltbook
Agent-targeted social engineering and attacks observed on a live agent network
Avishai Efrat
Security ResearchAgentic Recon: Discovering and Mapping Public AI Agents
A Copilot Studio case study in agent discovery and capability mapping
Avishai Efrat
Security ResearchThreat Actors Are Already Scanning For Your AI Deployments and Middleware
What recent scanning activity means for your AI middleware and agentic deployments

Tamir Ishay SharbatandAvishai Efrat
Exhibit & Exploit: Two DEF CON 33 Highlights from the Past & Future of Hacking
Humans, hacker culture and AI: Notes from Hacker Summer Camp
Avishai Efrat
Security ResearchThe Long and Winding Road of DLP Patches in Power Platform
Reviewing Microsoft's Fix for the 'All You Need Is Guest' DLP Bypass
Avishai Efrat