Zenity demos at Black Hat: one poisoned doc can make enterprise agents leak data
_clickfix_ · reddit · 2026-09-24
- At Black Hat USA 2025, Zenity Labs showed that a single poisoned document or message can drive enterprise AI agents' connectors to exfiltrate data, with demos spanning multiple vendors.
- One demo: ChatGPT Connectors were tricked into reading API keys from a connected Google Drive and leaking them via a crafted image URL.
- Another: a Copilot Studio agent was manipulated into emailing a knowledge-base file and Salesforce records to the attacker.
- Takeaway: an agent's own tools (email, connectors, external links) can serve as the attack payload — no model compromise needed, just instruction. Enterprises deploying agents need tool-misuse defenses.
More from coding & agent
- Garry Tan says capy makes his PR workflow 4x faster than raw Codex/Claude Code — garrytan · 2026-09-24
- Claude Code launches Projects: auto-split threads run as parallel cloud sessions, now with local support — ClaudeDevs · 2026-09-24
- Anthropic expands Claude Code Projects beta to more Pro and Max users via waitlist — ClaudeDevs · 2026-09-24
- Ex-Google engineer built a boss fight and spaceflight into his personal site — kieranklaassen · 2026-09-24
- Dan Grover: agent memory systems write and retrieve memories sparingly and arbitrarily — DanGrover · 2026-09-24
- Continuous Benchmarks: Treat Evals Like Software, Not Static Artifacts — kenbwork · 2026-09-24