# Sitemap

Table of contents of public pages on Zenity Labs. Append `.md` to any path or send `Accept: text/markdown` for Markdown.

## Pages

- [pwnai-security-research-initiative](/pwnai-security-research-initiative)
- [meet-us](/meet-us)
- [Authors](/authors)
- [Author: avishai-efrat](/authors/avishai-efrat)
- [Author: ayush-roychowdhury](/authors/ayush-roychowdhury)
- [Author: dmitry-lozovoy](/authors/dmitry-lozovoy)
- [Author: don-willits](/authors/don-willits)
- [Author: elad-david](/authors/elad-david)
- [Author: gal-malka](/authors/gal-malka)
- [Author: inbar-raz](/authors/inbar-raz)
- [Author: jo-o-donato](/authors/jo-o-donato)
- [Author: lana-salameh](/authors/lana-salameh)
- [Author: marina-simakov](/authors/marina-simakov)
- [Author: max-fomin](/authors/max-fomin)
- [Author: michael-bargury](/authors/michael-bargury)
- [Author: mike-takahashi](/authors/mike-takahashi)
- [Author: ofri-nachfolger](/authors/ofri-nachfolger)
- [Author: raul-klugman-onitza](/authors/raul-klugman-onitza)
- [Author: stav-cohen](/authors/stav-cohen)
- [Author: tamir-ishay-sharbat](/authors/tamir-ishay-sharbat)
- [Author: tomer-wetzler](/authors/tomer-wetzler)
- [Author: zenity-labs](/authors/zenity-labs)
- [Topic: engineering](/topic/engineering)
- [Topic: security-research](/topic/security-research)
- [Topic: talks](/topic/talks)
- [Topic: tools](/topic/tools)
- [Post: interpreting-jailbreaks-and-prompt-injections-with-attribution-graphs](/post/interpreting-jailbreaks-and-prompt-injections-with-attribution-graphs)
- [Post: links-and-materials-for-hacking-your-enterprise-copilot-a-direct-guide-to-indirect-prompt-injections](/post/links-and-materials-for-hacking-your-enterprise-copilot-a-direct-guide-to-indirect-prompt-injections)
- [Post: agentforger-part-2-the-autonomous-insider](/post/agentforger-part-2-the-autonomous-insider)
- [Post: echoleak-a-reminder-that-ai-agent-risks-are-here-to-stay-3cf3](/post/echoleak-a-reminder-that-ai-agent-risks-are-here-to-stay-3cf3)
- [Post: moving-the-decision-boundary-of-llm-safety-classifiers](/post/moving-the-decision-boundary-of-llm-safety-classifiers)
- [Post: rsac-2025](/post/rsac-2025)
- [Post: summary-zenity-research-published-blackhat-2024](/post/summary-zenity-research-published-blackhat-2024)
- [Post: reconstructing-a-timeline-for-amazon-q-prompt-infection-81e5](/post/reconstructing-a-timeline-for-amazon-q-prompt-infection-81e5)
- [Post: bluehat24](/post/bluehat24)
- [Post: phantom-references-microsoft-copilot](/post/phantom-references-microsoft-copilot)
- [Post: inside-the-agent-stack-securing-agents-in-amazon-bedrock-agentcore](/post/inside-the-agent-stack-securing-agents-in-amazon-bedrock-agentcore)
- [Post: hsc24](/post/hsc24)
- [Post: connected-agents-the-hidden-agentic-puppeteer](/post/connected-agents-the-hidden-agentic-puppeteer)
- [Post: the-power-of-one-ssrf-vulnerability-a-multi-platform-threat](/post/the-power-of-one-ssrf-vulnerability-a-multi-platform-threat)
- [Post: enabling-safety-in-ai-agents-via-choice-architecture](/post/enabling-safety-in-ai-agents-via-choice-architecture)
- [Post: appendix](/post/appendix)
- [Post: techniques-from-zenitys-genai-attacks-matrix-incorporated-into-mitre-atlas-to-track-emerging-ai-thr](/post/techniques-from-zenitys-genai-attacks-matrix-incorporated-into-mitre-atlas-to-track-emerging-ai-thr)
- [Post: turning-moltbook-into-a-global-botnet-map](/post/turning-moltbook-into-a-global-botnet-map)
- [Post: rce](/post/rce)
- [Post: the-geometry-of-safety-failures-in-large-language-models](/post/the-geometry-of-safety-failures-in-large-language-models)
- [Post: breaking-down-agentkit-s-guardrails](/post/breaking-down-agentkit-s-guardrails)
- [Post: agentic-recon-discovering-and-mapping-public-ai-agents](/post/agentic-recon-discovering-and-mapping-public-ai-agents)
- [Post: looking-inside-a-maliciousness-classifier-based-on-the-llm-s-internals](/post/looking-inside-a-maliciousness-classifier-based-on-the-llm-s-internals)
- [Post: links-materials-living-off-microsoft-copilot](/post/links-materials-living-off-microsoft-copilot)
- [Post: hardening-atlas-the-relentless-challenge-of-securing-an-untrusted-browser-agent](/post/hardening-atlas-the-relentless-challenge-of-securing-an-untrusted-browser-agent)
- [Post: claude-in-chrome-a-threat-analysis](/post/claude-in-chrome-a-threat-analysis)
- [Post: exhibit-exploit-two-def-con-33-highlights-from-the-past-future-of-hacking-5fcb](/post/exhibit-exploit-two-def-con-33-highlights-from-the-past-future-of-hacking-5fcb)
- [Post: i-just-wanted-to-take-a-note-and-your-token-came-along-c615](/post/i-just-wanted-to-take-a-note-and-your-token-came-along-c615)
- [Post: inside-microsoft-365-copilot-technical-breakdown](/post/inside-microsoft-365-copilot-technical-breakdown)
- [Post: agentflayer-chatgpt-connectors-0click-attack-5b41](/post/agentflayer-chatgpt-connectors-0click-attack-5b41)
- [Post: why-ai-security-research-needs-to-move-out-of-the-lab-and-into-the-wild](/post/why-ai-security-research-needs-to-move-out-of-the-lab-and-into-the-wild)
- [Post: links-materials-15-ways-break-copilot](/post/links-materials-15-ways-break-copilot)
- [Post: outsmarting-copilot-creating-hyperlinks-copilot-365](/post/outsmarting-copilot-creating-hyperlinks-copilot-365)
- [Post: indirect-prompt-injection-advanced-manipulation-techniques](/post/indirect-prompt-injection-advanced-manipulation-techniques)
- [Post: clawdbot-more-than-you-bargained-for](/post/clawdbot-more-than-you-bargained-for)
- [Post: threat-actors-are-trying-to-use-litellm-s-guardrail-tester-to-run-code-as-root](/post/threat-actors-are-trying-to-use-litellm-s-guardrail-tester-to-run-code-as-root)
- [Post: a-copilot-studio-story-2-when-aijacking-leads-to-full-data-exfiltration-bc4a](/post/a-copilot-studio-story-2-when-aijacking-leads-to-full-data-exfiltration-bc4a)
- [Post: threat-actors-are-already-scanning-for-your-ai-deployments-and-middleware](/post/threat-actors-are-already-scanning-for-your-ai-deployments-and-middleware)
- [Post: llm-vs-llm-its-a-mad-world](/post/llm-vs-llm-its-a-mad-world)
- [Post: agent-to-agent-exploitation-in-the-wild-observed-attacks-on-moltbook-b929](/post/agent-to-agent-exploitation-in-the-wild-observed-attacks-on-moltbook-b929)
- [Post: agentflayer-version-en-espanol](/post/agentflayer-version-en-espanol)
- [Post: links-and-materials-for-scaling-appsec-with-an-sdlc-for-citizen-development](/post/links-and-materials-for-scaling-appsec-with-an-sdlc-for-citizen-development)
- [Post: perplexedbrowser-perplexity-s-agent-browser-can-leak-your-personal-pc-local-files](/post/perplexedbrowser-perplexity-s-agent-browser-can-leak-your-personal-pc-local-files)
- [Post: openclaw-or-opendoor-indirect-prompt-injection-makes-openclaw-vulnerable-to-backdoors-and-much-more](/post/openclaw-or-opendoor-indirect-prompt-injection-makes-openclaw-vulnerable-to-backdoors-and-much-more)
- [Post: what-if-there-was-no-attacker-but-your-database-still-got-deleted](/post/what-if-there-was-no-attacker-but-your-database-still-got-deleted)
- [Post: perplexedbrowser-how-attackers-can-weaponize-comet-to-takeover-your-1password-vault](/post/perplexedbrowser-how-attackers-can-weaponize-comet-to-takeover-your-1password-vault)
- [Post: indirect-prompt-injection-initial-success-robustness](/post/indirect-prompt-injection-initial-success-robustness)
- [Post: copilot-reads-email-teams-messages](/post/copilot-reads-email-teams-messages)
- [Post: phishing-dead-long-live-spear-phishing](/post/phishing-dead-long-live-spear-phishing)
- [Post: agentflayer-minimum-clicks-maximum-leaks-tilling-chatgpt-s-attack-surface-c4c7](/post/agentflayer-minimum-clicks-maximum-leaks-tilling-chatgpt-s-attack-surface-c4c7)
- [Post: inside-salesforce-einstein-a-technical-background](/post/inside-salesforce-einstein-a-technical-background)
- [Post: scaling-appsec-with-an-sdl-for-citizen-development](/post/scaling-appsec-with-an-sdl-for-citizen-development)
- [Post: exploring-the-risks-of-chatgpt-s-atlas-browser](/post/exploring-the-risks-of-chatgpt-s-atlas-browser)
- [Post: access-copilot-m365-terminal](/post/access-copilot-m365-terminal)
- [Post: why-aren-t-we-making-any-progress-in-security-from-ai-bf02](/post/why-aren-t-we-making-any-progress-in-security-from-ai-bf02)
- [Post: tools-of-the-trade](/post/tools-of-the-trade)
- [Post: stealing-copilots-system-prompt](/post/stealing-copilots-system-prompt)
- [Post: autonomous-copilots-is-your-copilot-flying-solo-c8cf](/post/autonomous-copilots-is-your-copilot-flying-solo-c8cf)
- [Post: analyzing-the-security-risks-of-openai-s-agentkit](/post/analyzing-the-security-risks-of-openai-s-agentkit)
- [Post: long-winding-road-dlp-patches-power-platform](/post/long-winding-road-dlp-patches-power-platform)
- [Post: labs-zenity-io](/post/labs-zenity-io)
- [Post: bring-your-own-agent-hijacking-exposed-ai-backends-to-power-offensive-operations](/post/bring-your-own-agent-hijacking-exposed-ai-backends-to-power-offensive-operations)
- [Post: threat-actors-are-trying-to-turn-litellm-s-connection-test-into-a-key-exfiltration-channel](/post/threat-actors-are-trying-to-turn-litellm-s-connection-test-into-a-key-exfiltration-channel)
- [Post: sure-let-ai-browse-the-internet-what-could-possibly-go-wrong](/post/sure-let-ai-browse-the-internet-what-could-possibly-go-wrong)
- [Post: a-copilot-studio-story-discovery-phase-in-ai-agents-f917](/post/a-copilot-studio-story-discovery-phase-in-ai-agents-f917)
- [Post: ai-agents-the-new-frontier-for-security-researchers](/post/ai-agents-the-new-frontier-for-security-researchers)
- [Post: perplexity-comet-a-reversing-story](/post/perplexity-comet-a-reversing-story)
- [Post: catching-prompt-guard-off-guard-exploiting-overfit-in-training-algorithms](/post/catching-prompt-guard-off-guard-exploiting-overfit-in-training-algorithms)
- [Post: threat-actors-are-using-ollama-s-model-downloader-as-a-server-side-weapon](/post/threat-actors-are-using-ollama-s-model-downloader-as-a-server-side-weapon)
- [Post: inside-the-agent-stack-securing-microsoft-foundry-built-agents](/post/inside-the-agent-stack-securing-microsoft-foundry-built-agents)
- [Post: your-copilot-is-my-insider-rsac-2025](/post/your-copilot-is-my-insider-rsac-2025)
- [Post: over-permissions-in-salesforce-einstein-and-unexpected-consequences](/post/over-permissions-in-salesforce-einstein-and-unexpected-consequences)
- [Post: ai-agents-0-click-exploits-the-new-battle-ground-for-ai-security-c377](/post/ai-agents-0-click-exploits-the-new-battle-ground-for-ai-security-c377)
- [Post: ttps-ai-for-genai-targeted-attacks](/post/ttps-ai-for-genai-targeted-attacks)
- [Post: modeling-llms-via-structured-self-modeling-ssm](/post/modeling-llms-via-structured-self-modeling-ssm)
- [Post: your-model-reads-through-typos-your-probe-doesn-t](/post/your-model-reads-through-typos-your-probe-doesn-t)
- [Post: when-a-jira-ticket-can-steal-your-secrets](/post/when-a-jira-ticket-can-steal-your-secrets)
- [Post: rag-poisoning-need-one-document](/post/rag-poisoning-need-one-document)
- [Post: scanning-for-ai-live-campaigns-mapping-the-internet-s-exposed-llm-backends](/post/scanning-for-ai-live-campaigns-mapping-the-internet-s-exposed-llm-backends)
- [Post: prompt-mines-0-click-data-corruption-in-salesforce-einstein-1cfb](/post/prompt-mines-0-click-data-corruption-in-salesforce-einstein-1cfb)
- [Post: agentforger-part-1-chatgpt-cross-site-agent-forgery](/post/agentforger-part-1-chatgpt-cross-site-agent-forgery)
- [Post: data-structure-injection-dsi-in-ai-agents](/post/data-structure-injection-dsi-in-ai-agents)
- [Post: hsc25](/post/hsc25)
- [Post: a-look-inside-copilot-rag-system](/post/a-look-inside-copilot-rag-system)
- [join-us](/join-us)
- [Home](/)

---

Developed by [monogram.io](https://monogram.io)