Zenity Blog
Securing the Agent Supply Chain


Securing the Agent Supply Chain
A developer installs a skill to make their coding agent less chatty. It works. It also, the first time the agent...

Seeing Thousands of Real Incidents Means I Have No Choice But to Share What I Know
The Sentence I Cannot Stop Thinking About A few years ago, I was sitting across from a security leader at a large...

Zenity Labs: The Bleeding Edge
At Zenity, we like to say we don't only exist on the bleeding edge; we are the bleeding edge. It's a defensible...

PerplexedBrowser: Accepting a Meeting or Handing Your Local Files to an Attacker?
Note: This post is part of a coordinated disclosure by Zenity Labs detailing the PleaseFix vulnerability family...

GreyNoise Findings: What This Means for AI Security
GreyNoise Findings: What This Means for AI Security Late last week, GreyNoise published one of the clearest signals...

Safe Harbor: An Open Source “Abort Mission” Button for Your AI Agent
AI agents are increasingly connecting to more systems and workflows. They read structured data, follow multi-step...

Inside the Agent Stack: Securing Agents in Amazon Bedrock AgentCore
In the first installment of our Inside the Agent Stack series, we examined the design and security posture of agents...

Inside the Agent Stack: Securing Azure AI Foundry-Built Agents
This blog kicks off our new series, Inside the Agent Stack, where we take you behind the scenes of today’s most...

Zenity Labs & MITRE ATLAS Collaborate to Advance AI Agent Security with the First Release of Agent-Focused TTPs
TL;DR Zenity Labs worked in collaboration with MITRE ATLAS to incorporate the first 14 agent-focused techniques...

When “Secure by Design” Isn’t Enough: A Blind Spot in Power Platform Security Access Controls
Security Groups play a pivotal role in tenant governance across platforms like Entra, Power Platform, and SharePoint....

How Copilot Studio Agents Can Slip Past Power Platform’s Firewall
Microsoft’s Power Platform recently introduced an IP-based Firewall feature designed to restrict access to environments...

Bypassing Tenant Isolation in Microsoft Power Platform: A Security Loophole You Should Know
Microsoft Power Platform, specifically Power Automate and Copilot Studio, makes it easy for organizations to quickly...

All I Want For The Holidays Is…. Powerpwn
In the ever-evolving landscape of cybersecurity, the use of open-source red teaming tools has become indispensable....

Zenity Researchers Discover Over-Permissions in Salesforce Copilot Topics
The discoveries can lead to data leakage, exfiltration, phishing, and more. The Zenity Labs team has discovered...

Building Apps at Scale in Power Platform? Not for the Faint of Heart… or CoE Security
Introduction Enterprises are racing to adopt AI copilots and low-code/no-code platforms to innovate and maximize...

Inherent Data Leakage in Microsoft Fabric Business-Led Development
Microsoft Fabric is an end-to-end analytics and data platform that covers a wide range of functionality, including...

Microsoft Power Platform DLP Bypass Uncovered – Finding #5 – Parent and Child Flow Execution
Analysis of Microsoft Power Platform’s security features revealed limitations that could expose organizations...

Microsoft Power Platform DLP Bypass Uncovered – Finding #4 – Unblockable connectors
Hello everyone! I’m Yuval Adler, Customer Success Director at Zenity. I’m inviting you to read my blog series...

The Cross-Tenant Power Platform Connectors Vulnerability – Are You Safe Now?
What Happened Last week, on March 31st, NetSPI researchers announced that they found a cross-tenant Azure vulnerability...

Microsoft Power Platform DLP Bypass Uncovered – Finding #3 – Custom Connectors
Hello everyone! I’m Yuval Adler, Customer Success Director at Zenity. I’m inviting you to read my blog series...

Microsoft Power Platform DLP Bypass Uncovered- Finding #2 – HTTP calls
Hello everyone! I’m Yuval Adler, Customer Success Director at Zenity. I’m inviting you to read my blog series...

Microsoft Power Platform DLP Bypass Uncovered- Finding #1
Hello everyone! I’m Yuval Adler, Customer Success Director at Zenity. I’m inviting you to read my blog series...

ZAPESCAPE: Organization-wide control over Code by Zapier
In the middle of March 2022, Zenity research team discovered a sandbox-escape vulnerability in Code by Zapier,...

ZAPESCAPE: Vulnerability Disclosure
Date: March 16th 2022 Severity: High Security impact: Privilege Escalation, Data Leakage, Data Manipulation Intro This...
Secure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo