Zenity Labs Unveils AgentFlayer Vulnerabilities in Major AI Systems
Zenity Labs has revealed significant vulnerabilities in major AI systems, including OpenAI's ChatGPT and Microsoft Copilot, announced in a press release. These vulnerabilities, termed 'AgentFlayer,' allow attackers to silently hijack AI agents without any user interaction, posing a serious threat to enterprise environments.
The research, presented at Black Hat USA 2025, demonstrated how AI agents from vendors like OpenAI, Microsoft, and Salesforce can be compromised to exfiltrate data, manipulate workflows, and act autonomously. Zenity Labs showcased working exploits against widely used AI systems, highlighting the potential for attackers to bypass human oversight entirely.
Key findings include the ability to compromise OpenAI ChatGPT through email-triggered prompt injections, allowing access to connected Google Drive accounts and implanting malicious memories. Similarly, Microsoft Copilot Studio was shown to leak CRM databases, and Salesforce Einstein could be manipulated to reroute communications to attacker-controlled addresses.
Despite some vendors issuing patches following responsible disclosure, others have not addressed these vulnerabilities, citing them as intended functionality. This underscores a critical gap in AI security approaches, as enterprises rapidly adopt AI agents without adequate security controls.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Sep 16 AV-Comparatives Certifies 11 Endpoint Security Products in 2026 Test Sep 16 Cohesity Adds AI Agent Backup and Recovery to Data Cloud Sep 15 Hexnode Introduces Synapse for IT and Security Operations Sep 15 Cisco Expands Splunk AI for Private and Isolated Environments Sep 15 Zip Security Joins CrowdStrike Coalition to Protect Small BusinessesCybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Market report
2025 Generative AI in Professional Services Report
Thomson Reuters
This report by Thomson Reuters explores the integration and impact of generative AI technologies, such as ChatGPT and Microsoft Copilot, within the professional services sector. It highlights the growing adoption of GenAI tools across industries like legal, tax, accounting, and government, and discusses the challenges and opportunities these technologies present. The report also examines professionals' perceptions of GenAI and the need for strategic integration to maximize its value.
Read moreYou may also like
US Agencies Accuse Chinese AI Firms of Industrial Scale Model Distillation
OpenAI Releases Report on Hugging Face Breach
Anthropic's Threat Report Finds AI Moving From Assistant to Orchestrator
Researchers Link OpenAI Agents to May RubyGems Attack
Harness Survey Finds AI Agent Controls Lag Enterprise Confidence
Daily AI Brief: the AI news that matters, in your inbox.