LogoZenity Labs
AI Agent Security Summit (On Demand)
Join Us
Authors
Subscribe
LogoZenity Labs
Oliver Buchannon
Avishai Efrat

Senior security researcher at Zenity, specializing in securing AI agents and low-code/no-code platforms. His work focuses on uncovering vulnerabilities in enterprise AI deployments, from Copilot Studio to ChatGPT and beyond - and exploring how attackers discover and exploit these weaknesses. Passionate about all aspects of security, with experience spanning web security, anti-bot protection, OSINT, blockchain, and data engineering and aim on bridging the gap between cutting-edge research and practical defense strategies. Previously presented at BSidesTLV, Black Hat USA & Europe Arsenal and SecTor.

Threat Actors Are Trying to use LiteLLM's Guardrail Tester to Run Code as Root

Jun 30, 2026

•

5 min read

Threat Actors Are Trying to use LiteLLM's Guardrail Tester to Run Code as Root

A closer look at custom-code guardrail sandbox-escape (CVE–2026-40217) activity in the wild

Avishai Efrat
Ayush RoyChowdhury
Avishai Efrat, +1
Threat Actors Are Trying to Turn LiteLLM's Connection-Test Into a Key-Exfiltration Channel

Jun 30, 2026

•

6 min read

Threat Actors Are Trying to Turn LiteLLM's Connection-Test Into a Key-Exfiltration Channel

A closer look at api_base SSRF (CVE-2024-6587) activity in the wild, and its nested variant

Avishai Efrat
Ayush RoyChowdhury
Avishai Efrat, +1
Scanning for AI: Live Campaigns Mapping the Internet's Exposed LLM Backends

Jun 30, 2026

•

5 min read

Scanning for AI: Live Campaigns Mapping the Internet's Exposed LLM Backends

Inside mass discovery and model-probing reconnaissance campaigns that are mapping LLM backend servers in the wild

Ayush RoyChowdhury
Avishai Efrat
Ayush RoyChowdhury, +1
Bring Your Own Agent: Hijacking Exposed AI Backends to Power Offensive Operations

Jun 30, 2026

•

7 min read

Bring Your Own Agent: Hijacking Exposed AI Backends to Power Offensive Operations

Threat actors attempting to hijack Ollama & LiteLLM endpoints to run pentesting agents, tools and web reverse-engineering

Ayush RoyChowdhury
Avishai Efrat
Ayush RoyChowdhury, +1
What You Don’t Know Can Hurt You: Why AI Security Research Needs to Move Out of the Lab and Into the Wild

Jun 30, 2026

•

5 min read

What You Don’t Know Can Hurt You: Why AI Security Research Needs to Move Out of the Lab and Into the Wild

What we can learn from observing real attacks, made by real adversaries

Ayush RoyChowdhury
Avishai Efrat
Ayush RoyChowdhury, +1

Security research

Agent-to-Agent Exploitation in the Wild: Observed Attacks on Moltbook

Feb 3, 2026

•

14 min read

Agent-to-Agent Exploitation in the Wild: Observed Attacks on Moltbook

Agent-targeted social engineering and attacks observed on a live agent network

Avishai Efrat
Avishai Efrat

Security research

Agentic Recon: Discovering and Mapping Public AI Agents

Jan 19, 2026

•

17 min read

Agentic Recon: Discovering and Mapping Public AI Agents

A Copilot Studio case study in agent discovery and capability mapping

Avishai Efrat
Avishai Efrat

Security research

Threat Actors Are Already Scanning For Your AI Deployments and Middleware

Jan 13, 2026

•

21 min read

Threat Actors Are Already Scanning For Your AI Deployments and Middleware

What recent scanning activity means for your AI middleware and agentic deployments

Tamir Ishay Sharbat
Avishai Efrat
Tamir Ishay Sharbat, +1
Exhibit & Exploit: Two DEF CON 33 Highlights from the Past & Future of Hacking

Aug 25, 2025

•

9 min read

Exhibit & Exploit: Two DEF CON 33 Highlights from the Past & Future of Hacking

Humans, hacker culture and AI: Notes from Hacker Summer Camp

Avishai Efrat
Avishai Efrat

Security research

The Long and Winding Road of DLP Patches in Power Platform

Sep 17, 2024

•

8 min read

The Long and Winding Road of DLP Patches in Power Platform

Reviewing Microsoft's Fix for the 'All You Need Is Guest' DLP Bypass

Avishai Efrat
Avishai Efrat
Zenity Labs

Zenity Labs

Latest research, tools and talks about breaking and building AI systems, agents and assistants


Home

Meet Us

Join Us

© 2026 Zenity Labs.
beehiivPowered by beehiiv