Michael Bargury
Hacker, builder and a cybersecurity practitioner. He is the co-founder and CTO of Zenity, the first application security company enabling enterprises to empower business users without paying for it in security incidents. He leads the OWASP LCNC Top 10, has a column on DarkReading, and delivers research, tools and talks regularly at top conferences including BlackHat, DEFCON and RSAC.

Posts by Michael Bargury

Attackers Target Agents via The Skill Supply Chain
Michael Bargury
AI Enterprise Compromise - 0click Exploit Methods
Michael Bargury
Why Aren’t We Making Any Progress In Security From AI
Guardrails Are Soft Boundaries. Hard Boundaries Do Exist.
Michael Bargury
Reconstructing a timeline for Amazon Q prompt infection
How a rogue GitHub commit, automation missteps, and a deceptive AI assistant led to one of the most bizarre prompt injection cases in recent memory.
Michael Bargury
TalksZenity Research Published at RSAC 2025
Copilots and agents are a new access vector; How to build an AppSec program that scales to the level of citizen development
Michael Bargury
TalksLinks and materials for Scaling AppSec With an SDLC for Citizen Development
Links, demos, tools and slides for RSAC 2025
Michael Bargury
TalksLinks and materials for Your Copilot Is My Insider
Links, demos, tools and slides for RSAC 2025
Michael Bargury
TalksScaling AppSec With an SDL for Citizen Development
A blog version for the talk presented at BlueHat 2024

Michael BarguryandDon Willits
TalksLinks and materials for Scaling AppSec With an SDL for Citizen Development
Links, demos, tools and slides for BlueHat 2024
Michael Bargury
Security ResearchSure, Let AI Browse the Internet—What Could Possibly Go Wrong?
Internet browsing for AI agents leads to 0click compromise but these mitigations can help
Michael Bargury
Security ResearchTTPs.ai for GenAI-Targeted Attacks
Guiding threat simulation and defense for Copilots and Agents
Michael Bargury
TalksA Summary of Zenity Research Published at BlackHat 2024
New Attack Vectors Discovered for Initial Access and Post-Compromise
Michael Bargury
TalksCopilot Vulnerable to RCE: A New Attack Vector Into The Enterprise
We Need To Address Promptware Now
Michael Bargury
TalksLinks and materials for Living off Microsoft Copilot
Links, source code, tools and slides for BlackHat USA 2024
Michael Bargury
TalksLinks and materials for 15 Ways to Break Your Copilot
Links, source code, tools and slides for BlackHat USA 2024
Michael Bargury
TalksResearch Drop for Hacker Summer Camp 2024
More information on hacking Microsoft Copilot, Copilot Studio, powerpwn, and what to do next
Michael Bargury