logo

AI Agents Access Everything, Fall to Zero-Click Exploit

ID: 9d4a121e-ea2e-5c0b-a396-acf994eeb26e

STIX ID: report--9d4a121e-ea2e-5c0b-a396-acf994eeb26e

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-08-19

Date Updated: 2026-04-21

Author: Rob Wright

...
...

This transcript summarizes Zenity CTO Michael Bargury's Black Hat 2025 discussion of 'AgentFlayer' research showing a zero-click method to compromise enterprise AI assistants and agents (Microsoft, Google, OpenAI, Salesforce, etc.). An attacker who knows only a user's email can allegedly take over AI agents, access connector data (emails, docs, calendars, source code), and manipulate users via trusted assistant interactions; the interview calls for defense-in-depth security programs and warns that vendor guardrails alone are insufficient.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.