Dmitry Lozovoy
Security Researcher at Zenity, specializing in low-code/no-code security. Focuses on identifying vulnerabilities within the Power Platform ecosystem and developing new attack vectors for low-code/no-code applications. Explores AI hacking techniques across platforms like Microsoft 365 Copilot, Copilot Studio, and ChatGPT. An active participant in Microsoft's bug bounty programs, with contributions acknowledged on their public security researcher recognition page. Main areas of interest include cloud security research, API, and web applications.

Posts by Dmitry Lozovoy
Security ResearchAgentCorruption: Initial IMDS Access
How a single prompt to a public-facing AgentCore agent exposed the instance metadata endpoint, the agent's cloud identity, and its container image: the foothold for everything that follows in this series.

Lana SalamehandDmitry Lozovoy
Security ResearchAgentCorruption: One Role to Rule Them All
Exploring what the agent's default execution role and stolen credentials can actually do, and how they became an entry point to the entire region - discovering and invoking other agents, reading, deleting and hijacking private conversations through chat history tampering, and more.

Lana SalamehandDmitry Lozovoy
It's Always DNS in Claude’s Sandbox: From Data Exfiltration to a Bidirectional DNS Shell
The DNS vulnerability that was shipped twice
Dmitry Lozovoy
Security ResearchAgentFlayer: Minimum Clicks, Maximum Leaks: Tilling ChatGPT’s Attack Surface
Exploiting ChatGPT with Language Alone: A Deep Dive into 0Click and 1Click Attacks.
Dmitry Lozovoy
I Just Wanted to Take a Note — and Your Token Came Along
Dmitry Lozovoy
The Power of One SSRF Vulnerability: A Multi-Platform Threat
Dmitry Lozovoy
Security ResearchOutsmarting Copilot: Creating Hyperlinks in Copilot 365
Dmitry Lozovoy