Zenity Raises $125 Million to Secure the Era of 1 Billion AI Agents

Black Hat USA

Your agent just made a decision. Do you know what it was?

Come see Zenity at Black Hat in August in Las Vegas from August 4th-6th! See how you can secure the agent at the decision level by stopping by Booth #5521 for a demo!

Get involved for:

🎤 Theatre talks at our booth from leading researchers, and keynotes on the main stage

💡 Exclusive access to the AI Summit on August 4th

🎪 Community events, functions and happy hours with participation from OWASP

🍸 Exclusive happy hours and briefings for security advocates, champions, and practitioners


Zenity is the first security and governance platform purpose-built for AI agents, spanning SaaS, homegrown platforms (Cloud), and end-user devices (Endpoint).


We'd love to connect! Fill out the form to schedule an in-person meeting with us.

Sessions on the Black Hat Main Stage

Wed, Aug 5

Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover
11:30 PM – 12:10 AMOceanside A, Level 2

Agentic browsers are dismantling decades of browser security by design, reintroducing attacks like XSS, sandbox escapes, and drive-by exploitation. We'll reveal PleaseFix, the evolution of ClickFix targeting AI agents, and Intent Collision, a universal exploitation technique, demonstrating zero-click attack chains that compromise leading agentic browsers to take over accounts, exfiltrate sensitive data, establish persistence, abuse trusted applications, and ultimately achieve remote code execution outside the browser sandbox. We'll also examine the security boundaries that actually slowed us down, the techniques we used to bypass them, our collaboration with affected vendors, and the key lesson for anyone building or deploying AI agents: traditional browser security assumptions no longer hold, agentic browsers should be treated as highly privileged software with access to your digital identity, and meaningful protection requires deterministic, code-enforced boundaries rather than relying on AI model alignment alone.

Thu, Aug 6

You Can't Patch a Mental Model: How Agentic Systems Expose our Hidden Security Assumptions
06:05 PM – 06:45 PMMandalay Bay H, Level 2

This talk exposes eight hidden assumptions embedded in modern security architectures; assumptions that are laid bare in adaptive, goal-driven systems. We'll discuss a systems-based lens for security leaders and architects to: Recognise when your controls are structurally incapable of working, Reason about agentic risk using the four dynamics that shape the behaviour of all systems (control, decision-making, flow, feedback), and Derive controls that constrain causes, rather than reacting to behaviour.

Promptware EOD: Skillful Agent Detonation
10:35 PM – 11:15 PMSouth Seas C&D, Level 3

The AI agent supply chain has become a fertile ground for malware. It lurks in skill markdown files, rug-pulled MCP servers, misaligned models, and weaponized moltbook posts. In a blink of an eye, we find ourselves with an outdated supply chain security model. Intelligence gathering based on build-time static scanning has been sidestepped by agents pulling, writing, and executing code at runtime. Standing on the shoulders of giants, we introduce an old-new approach: agent detonation chamber. Analysis based on kernel-level truths, not a wishful analysis by an LLM judge. We detonated tens of thousands of skills from public marketplaces, and uncovered hundreds of malicious skills. We'll reveal how cryptominers and infostealers blinded static scanning tools with trivial "these aren't the droids you're looking for" instructions, remaining undetected for months until we spotted them.

Sessions at Booth #5521

Wed, Aug 5

Caught in the Wild: Real-World Attacks on AI from a Global Honeypot Network

05:00 PMBooth #5521

Everyone's asking whether attackers are actually going after AI systems yet. We stopped guessing and went looking. We built a global network of AI honeypots, hundreds of decoy AI servers and agents spread across clouds providers and regions, and watched who showed up. What we caught: attackers stealing compute to run their own AI workloads on our bill, turning AI tools' own features into weapons to forge server-side requests, attempts to run code and steal secrets, and even pointing autonomous hacking agents and "jailbroken" personas at our exposed AI decoy backends to attack 3rd parties, and more. This research shows real attacks, prompts, and techniques that threat actors used, and what it means for anyone deploying AI.

Coding Agents Overview: Attacks and Mitigations

08:00 PMBooth #5521

Coding agents slash delivery times for development teams and boost output quality, but only if operated securely. Running on user endpoints, coding agents can leak local files, invoke insecure tools, or adopt unauthorized skills. Without any hard code, threat actors can hijack coding agents and invoke risky activity directly inside an organizations production database. In this talk, see how coding agents can easily chain privilege escalation to accomplish nefarious goals, and how to prevent them from going rogue.

You Can't Patch a Mental Model: How Agentic Systems Expose Our Hidden Security Assumptions

11:00 PMBooth #5521

Agentic security isn't hard because it's new. It's hard because it breaks the assumptions our security models are built on. We keep trying to secure agents when what's actually needed is to govern agency, and those are fundamentally different problems. This talk exposes eight hidden assumptions baked into modern security architectures, ones that adaptive, goal-driven systems expose ruthlessly, and offers security leaders a systems-based lens to spot controls that are structurally incapable of working, reason about risk through the four dynamics that shape all systems (control, decision-making, flow, feedback), and build controls that constrain causes instead of chasing behavior.

Thu, Aug 6

Technical Deepdive: Claude in Chrome

05:00 PMBooth #5521

Agentic browsers represent a new manifestation of AI risk. With persistent access and long horizon goals, the threat vectors for Claude in Chrome are innumerous and frequently changing. In this talk, see how Claude in Chrome is built, broken, and requires hard boundaries built in code, not training

Pwning Agentic Browsers

06:30 PMBooth #5521

Agentic browsers are tearing down decades of web security to enable AI autonomy: breaking Same-Origin Policy, granting raw localhost and filesystem access, and running scripts on any site, with model alignment as the only real defense. We introduce PleaseFix, a new ClickFix-style vulnerability class that targets agents instead of humans, and Intent Collision, a universal technique to exploit it, then chain them into full 0-click attacks on flagship agentic browsers achieving account takeover, data theft, persistent implants, and remote code execution. We also break down which defenses actually held, and why code-enforced boundaries beat model training every time. Walk away with concrete hardening steps you can apply today, no vendor patch required.

Black Hat USA AI Summit

Join Zenity for the AI Summit at Black Hat Tuesday, August 4

Join us at the AI Summit for a full day of expert perspectives, cutting-edge research, and strategic discussion on navigating AI's dual role as both a security accelerator and an emerging threat vector. Whether you're defending against AI-powered attacks or securing the AI your organization is deploying, this is where the conversation is happening.

See you there.

Feature media
Happy Hour at Brewdog

Happy Hour with Zenity and OWASP at Brewdog

August 4 | 5:30pm

Join leaders from OWASP GenAI and Zenity for networking and strategic discussions on building and breaking AI security. Registration is free, but spots are limited, so reserve now!

Why Meet With Us?

AI Agents are Everywhere. Make Sure They’re Secure.

AI Agents have transformed everything about how business gets done. Not only do they come in the form of enterprise Agents like Microsoft 365 Copilot, Google Gemini, Amazon Q, and Salesforce Einstein, but they can also be customized and built by anyone across the enterprise. Agents are inherently connected to corporate data, actions, other agents, applications, and triggers, and requires defense in depth. That’s where we come in.

Secure Your Agents

We’d love to chat with you about how your team can secure and govern AI Agents everywhere.

Get a Demo