# Zenity Labs > Latest research, tools and talks about breaking and building AI systems, agents and assistants This file provides information about Zenity Labs to help large language models understand and reference this publication's content. ## Posts - [What If There Was No Attacker, But Your Database Still Got Deleted?](https://labs.zenity.io/p/what-if-there-was-no-attacker-but-your-database-still-got-deleted): Monitoring agentic emergent misalignment in the wild - a word of caution and a methodology proposal - [Threat Actors Are Trying to use LiteLLM's Guardrail Tester to Run Code as Root](https://labs.zenity.io/p/threat-actors-are-trying-to-use-litellm-s-guardrail-tester-to-run-code-as-root): A closer look at custom-code guardrail sandbox-escape (CVE–2026-40217) activity in the wild - [Threat Actors Are Trying to Turn LiteLLM's Connection-Test Into a Key-Exfiltration Channel](https://labs.zenity.io/p/threat-actors-are-trying-to-turn-litellm-s-connection-test-into-a-key-exfiltration-channel): A closer look at api_base SSRF (CVE-2024-6587) activity in the wild, and its nested variant - [Scanning for AI: Live Campaigns Mapping the Internet's Exposed LLM Backends](https://labs.zenity.io/p/scanning-for-ai-live-campaigns-mapping-the-internet-s-exposed-llm-backends): Inside mass discovery and model-probing reconnaissance campaigns that are mapping LLM backend servers in the wild - [Bring Your Own Agent: Hijacking Exposed AI Backends to Power Offensive Operations](https://labs.zenity.io/p/bring-your-own-agent-hijacking-exposed-ai-backends-to-power-offensive-operations): Threat actors attempting to hijack Ollama & LiteLLM endpoints to run pentesting agents, tools and web reverse-engineering - [What You Don’t Know Can Hurt You: Why AI Security Research Needs to Move Out of the Lab and Into the Wild](https://labs.zenity.io/p/why-ai-security-research-needs-to-move-out-of-the-lab-and-into-the-wild): What we can learn from observing real attacks, made by real adversaries - [Your Model Reads Through Typos. Your Probe Doesn't.](https://labs.zenity.io/p/your-model-reads-through-typos-your-probe-doesn-t): The Latent Undertow beneath fluent LLM behavior — and how to fish your activation probe out of it. - [Catching Prompt Guard Off Guard: Exploiting Overfit in Training Algorithms](https://labs.zenity.io/p/catching-prompt-guard-off-guard-exploiting-overfit-in-training-algorithms): How understanding the training algorithms used in machine learning models may allow attacker to bypass them entirely - [PerplexedBrowser: Perplexity’s Agent Browser Can Leak Your PC's Local Files](https://labs.zenity.io/p/perplexedbrowser-perplexity-s-agent-browser-can-leak-your-personal-pc-local-files): Local Files Are No Longer Safe. - [PerplexedBrowser: How Attackers Can Hijack Comet to Takeover your 1Password Vault](https://labs.zenity.io/p/perplexedbrowser-how-attackers-can-weaponize-comet-to-takeover-your-1password-vault): One Calendar Invite. Your Entire Vault. Zero Clicks. - [Turning Moltbook Into a Global Botnet Map](https://labs.zenity.io/p/turning-moltbook-into-a-global-botnet-map): How Untrusted Content Triggered 1,000+ Agent Endpoints Worldwide and Exposed Moltbook’s Faulty Design - [Looking Inside: a Maliciousness Classifier Based on the LLM's Internals](https://labs.zenity.io/p/looking-inside-a-maliciousness-classifier-based-on-the-llm-s-internals): Beyond input & output filtering and how well does it generalize to your out-of-distribution production data? - [Perplexity Comet: A Reversing Story](https://labs.zenity.io/p/perplexity-comet-a-reversing-story): A deeper look into an agentic browser's inner workings - [OpenClaw or OpenDoor? ](https://labs.zenity.io/p/openclaw-or-opendoor-indirect-prompt-injection-makes-openclaw-vulnerable-to-backdoors-and-much-more): Indirect Prompt Injection makes OpenClaw vulnerable to Backdoors and much more. - [Agent-to-Agent Exploitation in the Wild: Observed Attacks on Moltbook](https://labs.zenity.io/p/agent-to-agent-exploitation-in-the-wild-observed-attacks-on-moltbook-b929): Agent-targeted social engineering and attacks observed on a live agent network - [Clawdbot: More than you bargained for?](https://labs.zenity.io/p/clawdbot-more-than-you-bargained-for) - [Agentic Recon: Discovering and Mapping Public AI Agents](https://labs.zenity.io/p/agentic-recon-discovering-and-mapping-public-ai-agents): A Copilot Studio case study in agent discovery and capability mapping - [Threat Actors Are Already Scanning For Your AI Deployments and Middleware](https://labs.zenity.io/p/threat-actors-are-already-scanning-for-your-ai-deployments-and-middleware): What recent scanning activity means for your AI middleware and agentic deployments - [Moving The Decision Boundary of LLM Safety Classifiers](https://labs.zenity.io/p/moving-the-decision-boundary-of-llm-safety-classifiers): How a new fine-tuning approach can mitigate the problem of inaccurate safety paths - [Hardening OpenAl's Atlas: The Relentless Challenge of Securing an Untrusted Browser Agent](https://labs.zenity.io/p/hardening-atlas-the-relentless-challenge-of-securing-an-untrusted-browser-agent) - [Claude in Chrome: A Threat Analysis](https://labs.zenity.io/p/claude-in-chrome-a-threat-analysis) - [Connected Agents: The hidden agentic puppeteer](https://labs.zenity.io/p/connected-agents-the-hidden-agentic-puppeteer): Exploiting Copilot Studio's newest feature and exploring protection options - [The Geometry of Safety Failures in Large Language Models](https://labs.zenity.io/p/the-geometry-of-safety-failures-in-large-language-models): A deep dive into activation space of prompts in safety classifiers. Showing not why - but where - safety fails in LLM classifiers meant to detect malicious prompts. - [Inside the Agent Stack: Securing Agents in Amazon Bedrock AgentCore](https://labs.zenity.io/p/inside-the-agent-stack-securing-agents-in-amazon-bedrock-agentcore): An in-depth examination of emerging risks and effective mitigation techniques for protecting AI agents operating within the Bedrock AgentCore ecosystem.