Zenity Raises $125 Million to Secure the Era of 1 Billion AI Agents
Securing the Agent Supply Chain
Refael (Rafa) Lachmish

Securing the Agent Supply Chain

A developer installs a skill to make their coding agent less chatty. It works. It also, the first time the agent...

Research
Seeing Thousands of Real Incidents Means I Have No Choice But to Share What I Know
Keren Katz

Seeing Thousands of Real Incidents Means I Have No Choice But to Share What I Know

The Sentence I Cannot Stop Thinking About A few years ago, I was sitting across from a security leader at a large...

ResearchAI Security
Zenity Labs: The Bleeding Edge
Kayla Underkoffler

Zenity Labs: The Bleeding Edge

At Zenity, we like to say we don't only exist on the bleeding edge; we are the bleeding edge. It's a defensible...

Company AnnouncementsResearch
PerplexedBrowser: Accepting a Meeting or Handing Your Local Files to an Attacker?
Greg Zemlin

PerplexedBrowser: Accepting a Meeting or Handing Your Local Files to an Attacker?

Note: This post is part of a coordinated disclosure by Zenity Labs detailing the PleaseFix vulnerability family...

Company AnnouncementsResearch
GreyNoise Findings: What This Means for AI Security
Greg Zemlin

GreyNoise Findings: What This Means for AI Security

GreyNoise Findings: What This Means for AI Security Late last week, GreyNoise published one of the clearest signals...

Industry NewsResearch
Safe Harbor: An Open Source “Abort Mission” Button for Your AI Agent
Greg Zemlin

Safe Harbor: An Open Source “Abort Mission” Button for Your AI Agent

AI agents are increasingly connecting to more systems and workflows. They read structured data, follow multi-step...

Product AnnouncementsResearch
Inside the Agent Stack: Securing Agents in Amazon Bedrock AgentCore
Lana Salameh

Inside the Agent Stack: Securing Agents in Amazon Bedrock AgentCore

In the first installment of our Inside the Agent Stack series, we examined the design and security posture of agents...

Research
Inside the Agent Stack: Securing Azure AI Foundry-Built Agents
Lana Salameh

Inside the Agent Stack: Securing Azure AI Foundry-Built Agents

This blog kicks off our new series, Inside the Agent Stack, where we take you behind the scenes of today’s most...

Research
Zenity Labs & MITRE ATLAS Collaborate to Advance AI Agent Security with the First Release of Agent-Focused TTPs
Marina Simakov

Zenity Labs & MITRE ATLAS Collaborate to Advance AI Agent Security with the First Release of Agent-Focused TTPs

TL;DR Zenity Labs worked in collaboration with MITRE ATLAS to incorporate the first 14 agent-focused techniques...

Company AnnouncementsResearch
When “Secure by Design” Isn’t Enough: A Blind Spot in Power Platform Security Access Controls
Ziv Hagbi

When “Secure by Design” Isn’t Enough: A Blind Spot in Power Platform Security Access Controls

Security Groups play a pivotal role in tenant governance across platforms like Entra, Power Platform, and SharePoint....

Research
How Copilot Studio Agents Can Slip Past Power Platform’s Firewall
Ziv Hagbi

How Copilot Studio Agents Can Slip Past Power Platform’s Firewall

Microsoft’s Power Platform recently introduced an IP-based Firewall feature designed to restrict access to environments...

Research
Bypassing Tenant Isolation in Microsoft Power Platform: A Security Loophole You Should Know
Ziv Hagbi

Bypassing Tenant Isolation in Microsoft Power Platform: A Security Loophole You Should Know

Microsoft Power Platform, specifically Power Automate and Copilot Studio, makes it easy for organizations to quickly...

Research
All I Want For The Holidays Is…. Powerpwn
Lana Salameh

All I Want For The Holidays Is…. Powerpwn

In the ever-evolving landscape of cybersecurity, the use of open-source red teaming tools has become indispensable....

Research
Zenity Researchers Discover Over-Permissions in Salesforce Copilot Topics
Tamir Ishay Sharbat

Zenity Researchers Discover Over-Permissions in Salesforce Copilot Topics

The discoveries can lead to data leakage, exfiltration, phishing, and more. The Zenity Labs team has discovered...

Research
Building Apps at Scale in Power Platform? Not for the Faint of Heart… or CoE Security
Ziv Hagbi

Building Apps at Scale in Power Platform? Not for the Faint of Heart… or CoE Security

Introduction Enterprises are racing to adopt AI copilots and low-code/no-code platforms to innovate and maximize...

ResearchAI Security
Inherent Data Leakage in Microsoft Fabric Business-Led Development
Ziv Hagbi

Inherent Data Leakage in Microsoft Fabric Business-Led Development

Microsoft Fabric is an end-to-end analytics and data platform that covers a wide range of functionality, including...

ResearchAI Security
Microsoft Power Platform DLP Bypass Uncovered – Finding #5 – Parent and Child Flow Execution
Yuval Adler

Microsoft Power Platform DLP Bypass Uncovered – Finding #5 – Parent and Child Flow Execution

Analysis of Microsoft Power Platform’s security features revealed limitations that could expose organizations...

Research
Microsoft Power Platform DLP Bypass Uncovered – Finding #4 – Unblockable connectors
Yuval Adler

Microsoft Power Platform DLP Bypass Uncovered – Finding #4 – Unblockable connectors

Hello everyone! I’m Yuval Adler, Customer Success Director at Zenity. I’m inviting you to read my blog series...

Research
The Cross-Tenant Power Platform Connectors Vulnerability – Are You Safe Now?
Uriel Zilberberg

The Cross-Tenant Power Platform Connectors Vulnerability – Are You Safe Now?

What Happened Last week, on March 31st, NetSPI researchers announced that they found a cross-tenant Azure vulnerability...

Research
Microsoft Power Platform DLP Bypass Uncovered – Finding #3 – Custom Connectors
Yuval Adler

Microsoft Power Platform DLP Bypass Uncovered – Finding #3 – Custom Connectors

Hello everyone! I’m Yuval Adler, Customer Success Director at Zenity. I’m inviting you to read my blog series...

Research
Microsoft Power Platform DLP Bypass Uncovered- Finding #2 – HTTP calls
Yuval Adler

Microsoft Power Platform DLP Bypass Uncovered- Finding #2 – HTTP calls

Hello everyone! I’m Yuval Adler, Customer Success Director at Zenity. I’m inviting you to read my blog series...

Research
Microsoft Power Platform DLP Bypass Uncovered- Finding #1
Yuval Adler

Microsoft Power Platform DLP Bypass Uncovered- Finding #1

Hello everyone! I’m Yuval Adler, Customer Success Director at Zenity. I’m inviting you to read my blog series...

Research
ZAPESCAPE: Organization-wide control over Code by Zapier
Michael Bargury

ZAPESCAPE: Organization-wide control over Code by Zapier

In the middle of March 2022, Zenity research team discovered a sandbox-escape vulnerability in Code by Zapier,...

Research
ZAPESCAPE: Vulnerability Disclosure
Michael Bargury

ZAPESCAPE: Vulnerability Disclosure

Date: March 16th 2022 Severity: High Security impact: Privilege Escalation, Data Leakage, Data Manipulation Intro This...

Research

Secure Your Agents

We’d love to chat with you about how your team can secure and govern AI Agents everywhere.

Get a Demo