In-depth studies on vulnerabilities and defenses in copilot and no-code applications
Security research
Jul 23, 2026
•
5 min read
6 min read
Mar 3, 2026
26 min read
One Calendar Invite. Your Entire Vault. Zero Clicks.
25 min read
Local Files Are No Longer Safe.
Feb 18, 2026
22 min read
How Untrusted Content Triggered 1,000+ Agent Endpoints Worldwide and Exposed Moltbook’s Faulty Design
Feb 11, 2026
13 min read
A deeper look into an agentic browser's inner workings
Feb 4, 2026
14 min read
Indirect Prompt Injection makes OpenClaw vulnerable to Backdoors and much more.
Feb 3, 2026
Agent-targeted social engineering and attacks observed on a live agent network
Jan 19, 2026
17 min read
A Copilot Studio case study in agent discovery and capability mapping
Jan 13, 2026
21 min read
What recent scanning activity means for your AI middleware and agentic deployments
Oct 23, 2025
11 min read
Oct 21, 2025
15 min read
Oct 10, 2025
9 min read
A deep dive into OpenAI's AgentKit guardrails, how they are implemented, and where they fail
Oct 8, 2025
Aug 14, 2025
Aug 7, 2025
7 min read
Exploiting ChatGPT with Language Alone: A Deep Dive into 0Click and 1Click Attacks.
Aug 6, 2025
Aug 1, 2025
10 min read
TL;DR: A 0click attack through a malicious Jira ticket can cause Cursor to exfiltrate secrets from the repository or local file system.
Jul 7, 2025
Jun 20, 2025
Jun 11, 2025
Jun 5, 2025
Talks
+1
May 1, 2025
2 min read
Copilots and agents are a new access vector; How to build an AppSec program that scales to the level of citizen development
+2
Apr 30, 2025
3 min read
Links, demos, tools and slides for RSAC 2025