Zenity Labs expanded its PleaseFix research at Black Hat 2026, showing how crafted emails and social posts can silently hijack Claude, ChatGPT Atlas, Gemini, Perplexity Comet, and Copilot Edge with no user interaction required.
Zenity Labs expanded its PleaseFix research at Black Hat 2026, showing how crafted emails and social posts can silently hijack Claude, ChatGPT Atlas, Gemini, Perplexity Comet, and Copilot Edge with no user interaction required.
Zenity Labs disclosed AgentForger on July 23, a ChatGPT Workspace Agents flaw that let a single crafted URL silently build and deploy an attacker-controlled AI agent with full access to an enterprise's connected apps — email, calendar, Slack, Teams, and more.
Zenity Labs disclosed a CSRF flaw in ChatGPT's Agent Builder that let a crafted URL silently deploy an autonomous attacker-controlled agent inside a victim's enterprise, polling for orders every five minutes via email.
Zenity Labs has documented attackers exploiting unpatched LiteLLM vulnerabilities and unauthenticated Ollama endpoints to run autonomous pentesting campaigns, steal compute, and exfiltrate data from victim organisations.