Related Threat Clusters
-
AgentForger: New Phishing Attack Creates Autonomous AI Insiders
Zenity Labs has identified a critical vulnerability named AgentForger in OpenAI's ChatGPT Workspace Agents. This flaw allows attackers to create a malicious AI agent within an organization by embedding instructions in a…
11 articles · Updated July 23, 2026 -
New 'PleaseFix' Vulnerabilities Threaten Agentic Browsers with Widespread Attacks
Security researchers have identified a new class of vulnerabilities called 'PleaseFix' that severely compromise agentic browsers. These vulnerabilities allow attackers to exploit the browsers using simple English…
11 articles · Updated July 29, 2026 -
Hackers Exploit Vulnerabilities in Copilot Studio's Connected Agents Feature
Security researchers at Zenity Labs have identified critical design flaws in Microsoft’s Copilot Studio, specifically in the newly introduced Connected Agents feature. These vulnerabilities enable attackers to…
3 articles · Updated December 30, 2025 -
Zenity Labs Reveals PleaseFix Vulnerabilities in Perplexity Comet and Other Browsers
Zenity Labs disclosed a family of critical vulnerabilities known as PleaseFix, affecting agentic browsers including Perplexity Comet. These vulnerabilities enable zero-click agent hijacking, local file exfiltration, and…
18 articles · Updated March 3, 2026
Recent Intelligence Reports
- Zenity Labs Discloses Pleasefix Perplexedagent Vulnerability — zenity.io · July 28, 2026
- One Click, One Attacker-Controlled Agentic Insider: Zenity Labs Uncovers 'AgentForger,' a ... — Morningstar · July 23, 2026
- Perplexity Comet browser hole was exploitable via cal invite • The Register — Theregister · March 4, 2026
- Researchers discover suite of agentic AI browser vulnerabilities — Cyberscoop · March 3, 2026
- Zenity Labs Discloses PleaseFix Vulnerability Family in Perplexity Comet and Other Agentic ... — Morningstar · March 3, 2026
- Until last month, attackers could've stolen info from Perplexity Comet users just by sending a calendar invite — Theregister · March 3, 2026
- Hackers Exploit Copilot Studio's New Connected Agents Feature to Gain Backdoor Access — Cyberpress · December 30, 2025