Uploaded December 2025 | Updated September 2026, 3 weeks ago
Compromising a well-protected enterprise used to require careful planning, proper resources, and ability to execute. Not anymore! Enter AI.
Initial access? AI is happy to let you operate on its users' behalf. Persistence? Self-replicate through corp docs. Data harvesting? AI is the ultimate data hoarder. Exfil? Just render an image. Impact? So many tools at your disposal. There's more. You can do all this as an external attacker. No credentials required, no phishing, no social engineering, no human-in-the-loop. In-and-out with a single prompt.
Last year we demonstrated one of the first real-world exploitation of AI vulnerabilities impacting enterprises, showing how attackers can manipulate Microsoft Copilot to do their bidding. A lot has changed in the AI space since... for the worse. AI assistants have morphed into agents. They read your search history, emails and chat messages. They wield tools that can manipulate the enterprise environment on behalf of users - or a malicious attacker once hijacked. We will demonstrate access-to-impact AI vulnerability chains in most flagship enterprise AI assistants: ChatGPT, Gemini, Copilot, Einstein, and their custom agent . Some require one bad click by the victim, others work with no user interaction - 0click attacks.
The industry has no real solution for fixing this. Prompt injection is not another bug we can fix. It is a security problem we can manage! We will offer a security framework to help you protect your organization-the GenAI Attack Matrix. We will compare mitigations set forth by AI vendors, and share which ones successfully prevent the worst 0click attacks. Finally, we'll dissect our own attacks, breaking them down into basic TTPs, and showcase how they can be detected and mitigated.
Tamir Ishay Sharbat
Zenity
AI Security Researcher
Tamir Ishay Sharbat is a software engineer and security researcher with a particular passion for AI security. His current focus is on identifying vulnerabilities in enterprise AI products such as Microsoft Copilot, Microsoft Copilot Studio, Salesforce Einstein, Google Gemini and more. Tamir conducts deep analysis of AI architectures to identify potential exploits, then crafts prompt injections and elaborate attacks accordingly. Tamir is also a core member of the OWASP Agentic Security Initiative where he helps with understanding the prevailing threats of AI agents.
@tamirishaysh
linkedin.com/in/tamir-ishay-sharbat-069496163
labs.zenity.io (blog)
zenity.io (company)
Managed by the OWASP® Foundation
owasp.org
Compromising a well-protected enterprise used to require careful planning, proper resources, and ability to execute. Not anymore! Enter AI.
Initial access? AI is happy to let you operate on its users' behalf. Persistence? Self-replicate through corp docs. Data harvesting? AI is the ultimate data hoarder. Exfil? Just render an image. Impact? So many tools at your disposal. There's more. You can do all this as an external attacker. No credentials required, no phishing, no social engineering, no human-in-the-loop. In-and-out with a single prompt.
Last year we demonstrated one of the first real-world exploitation of AI vulnerabilities impacting enterprises, showing how attackers can manipulate Microsoft Copilot to do their bidding. A lot has changed in the AI space since... for the worse. AI assistants have morphed into agents. They read your search history, emails and chat messages. They wield tools that can manipulate the enterprise environment on behalf of users - or a malicious attacker once hijacked. We will demonstrate access-to-impact AI vulnerability chains in most flagship enterprise AI assistants: ChatGPT, Gemini, Copilot, Einstein, and their custom agent . Some require one bad click by the victim, others work with no user interaction - 0click attacks.
The industry has no real solution for fixing this. Prompt injection is not another bug we can fix. It is a security problem we can manage! We will offer a security framework to help you protect your organization-the GenAI Attack Matrix. We will compare mitigations set forth by AI vendors, and share which ones successfully prevent the worst 0click attacks. Finally, we'll dissect our own attacks, breaking them down into basic TTPs, and showcase how they can be detected and mitigated.
Tamir Ishay Sharbat
Zenity
AI Security Researcher
Tamir Ishay Sharbat is a software engineer and security researcher with a particular passion for AI security. His current focus is on identifying vulnerabilities in enterprise AI products such as Microsoft Copilot, Microsoft Copilot Studio, Salesforce Einstein, Google Gemini and more. Tamir conducts deep analysis of AI architectures to identify potential exploits, then crafts prompt injections and elaborate attacks accordingly. Tamir is also a core member of the OWASP Agentic Security Initiative where he helps with understanding the prevailing threats of AI agents.
@tamirishaysh
linkedin.com/in/tamir-ishay-sharbat-069496163
labs.zenity.io (blog)
zenity.io (company)
Managed by the OWASP® Foundation
owasp.org










