Security Research
In-depth studies on vulnerabilities and defenses in copilot and no-code applications
Security ResearchClaude in Chrome: From alert(1) to Full Account Takeover

Raul Klugman-OnitzaandJoão Donato
Security ResearchAccount Takeover via Claude in Chrome: A Technical Deep Dive

Raul Klugman-OnitzaandJoão Donato
Security ResearchGrand Theft Atlas
How we hijacked ChatGPT Atlas with one planted X comment, to phish the victim's WhatsApp contacts and buy ourselves an Amazon order on their card
Stav Cohen
Security ResearchAgentForger, Part 2: The Autonomous Insider
Mike Takahashi
Security ResearchAgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
Mike Takahashi
Security ResearchPerplexedBrowser: Perplexity’s Agent Browser Can Leak Your PC's Local Files
Local Files Are No Longer Safe.
Stav Cohen
Security ResearchPerplexedBrowser: How Attackers Can Hijack Comet to Takeover your 1Password Vault
One Calendar Invite. Your Entire Vault. Zero Clicks.
Stav Cohen
Security ResearchTurning Moltbook Into a Global Botnet Map
How Untrusted Content Triggered 1,000+ Agent Endpoints Worldwide and Exposed Moltbook’s Faulty Design

Stav CohenandJoão Donato
Security ResearchPerplexity Comet: A Reversing Story
A deeper look into an agentic browser's inner workings
Raul Klugman-Onitza
Security ResearchOpenClaw or OpenDoor?
Indirect Prompt Injection makes OpenClaw vulnerable to Backdoors and much more.

Stav CohenandJoão Donato
Security ResearchAgent-to-Agent Exploitation in the Wild: Observed Attacks on Moltbook
Agent-targeted social engineering and attacks observed on a live agent network
Avishai Efrat
Security ResearchAgentic Recon: Discovering and Mapping Public AI Agents
A Copilot Studio case study in agent discovery and capability mapping
Avishai Efrat
Security ResearchThreat Actors Are Already Scanning For Your AI Deployments and Middleware
What recent scanning activity means for your AI middleware and agentic deployments

Tamir Ishay SharbatandAvishai Efrat
Security ResearchExploring the Risks of ChatGPT’s Atlas Browser

Tamir Ishay SharbatandRaul Klugman-Onitza
Security ResearchInterpreting Jailbreaks and Prompt Injections with Attribution Graphs
Max Fomin