
Key Takeaways
- Zenity spent the week on the ground at Black Hat, from the AI Summit to booth sessions, Briefings talks, and ancillary events, making the case that agent-centric security is now table stakes.
- Zenity Labs revealed the full scope of PleaseFix, a zero-click vulnerability class that reached every major agentic browser the team tested.
- Zenity Labs uncovered an active credential-stealing campaign hidden inside AI agent skills and launched AI Total, a free service that runs a skill in a sandbox to see what it actually does.
- Zenity closed a $125 million Series C led by Norwest to accelerate its work securing AI agents from build time to runtime.
Enterprise AI agents stopped being a pilot project a while ago. They read email, touch source code, operate browsers, and increasingly make decisions inside production systems, which means the security model built for chatbots and prompts no longer covers what is actually happening inside the enterprise.
Black Hat USA 2026 turned out to be the week that gap became impossible to ignore. Zenity used the event to close a major funding round, publish new agent security research, and put its team in front of thousands of practitioners grappling with the same question: how do you govern something that acts on its own? Here is a look at what Zenity announced and where the team showed up.
A New Round to Secure the Era of 1 Billion Agents
The week opened with Zenity announcing a $125 million Series C led by Norwest, bringing the company's total funding to roughly $185 million. New investors Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures, and LG Technology Ventures joined existing backers Vertex Ventures, Third Point Ventures, DTCP, and Intel Capital.
The round reflects a broader shift the Zenity team has been tracking closely: AI agent security has historically focused on the model layer or the prompt layer, but the real exposure now sits at the agent layer, where a system can access enterprise data, invoke tools, and carry out entire business processes on its own. The new capital is earmarked for global expansion, continued platform development, and deeper investment in Zenity Labs, the company's security research arm.
Zenity Labs Proves the Browser's Oldest Trust Boundary Doesn't Hold for Agents
For three decades, the same-origin policy has kept one website from reaching into another or into whatever else a person is logged into. Zenity Labs leveraged the community at Black Hat to announce new research showing that agentic browsers quietly give that guarantee away: once an agent can read content from one source and act on another inside an authenticated session, that boundary stops doing its job.
The research, presented as “Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover,” exposed the full scope of PleaseFix and a technique the team calls Intent Collision, in which hidden instructions buried in ordinary content redirect an agent to act on an attacker's behalf. The demonstrations spanned Claude in Chrome, Perplexity Comet, ChatGPT Atlas, and other leading agentic browsers, with attack paths ranging from data exfiltration and account takeover to remote control of a victim's machine, all without a single click from the user.
Vendor response varied sharply: some patched quickly, others treated the behavior as intended functionality, but the underlying pattern is structural rather than incidental.
Dig into the technical detail in Zenity Labs' PleaseFix research:
- Claude in Chrome: From alert(1) to Full Account Takeover
- Claude in Chrome: Breaking down the injection
- Account Takeover via Claude in Chrome: A Technical Deep Dive
- Grand Theft Atlas
Skills Are the New Supply Chain, and AI Total Watches What They Actually Do
Alongside the browser research, Zenity Labs detailed an active credential-stealing campaign distributed through Vercel's skills.sh registry. Attackers cloned legitimate AI agent skills, let the copies build a clean track record, and only later slipped in instructions telling the agent to hunt for SSH keys, cloud credentials, and other secrets across developer workstations and CI environments before shipping them to attacker-controlled infrastructure. The affected skill family had amassed well over a million aggregate installs before Vercel and GitHub removed the listings within hours of disclosure.
The finding points to a harder problem: static analysis of a skill's code or instructions misses malicious behavior that only shows up once the skill actually runs. To close that gap, Zenity Labs built AI Total, a free threat intelligence service that executes a skill inside a sandbox seeded with realistic bait and records exactly what it does. Beyond the active campaign, the same technique turned up dozens of additional skills exhibiting malicious or dangerous behavior in public registries.
On the Ground at Black Hat
Research and funding news aside, Zenity's team spent the week talking directly with the people who will have to defend against all of this. Alongside a full day at the Black Hat AI Summit and a run of ancillary events, Zenity held a handful of booth talks focused on its latest research, in addition to three Black Hat Briefings sessions.
Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover
Presented by Zenity co-founder and CTO Michael Bargury and Zenity Labs AI security researcher Stav Cohen, this session laid out how agentic browsers are dismantling decades of browser security by design, reintroducing risks like XSS, sandbox escapes, and drive-by exploitation. Bargury and Cohen walked through PleaseFix and Intent Collision, then chained them into 0-click attacks against flagship agentic browsers that achieved account takeover, data theft, persistence, and remote code execution, closing with a breakdown of which defenses actually held and concrete hardening steps that don't depend on waiting for a vendor patch.
You Can't Patch a Mental Model: How Agentic Systems Expose Our Hidden Security Assumptions
Ben Hanson took a more architectural angle, examining eight hidden assumptions baked into modern security controls that fall apart once systems become adaptive and goal-driven. Rather than a single exploit, the talk offered security leaders and architects a systems-based lens for recognizing when a control is structurally incapable of working, reasoning about agentic risk through the dynamics that shape any system's behavior, and building controls that constrain causes rather than reacting to symptoms.
Promptware EOD: Skillful Agent Detonation
Michael Bargury returned to the stage with Zenity Labs researcher Tamir Ishay Sharbat to unpack the malicious AI agent skills research covered above. The session dug into how the AI agent supply chain, skill files, MCP servers, misaligned models, and weaponized web content, has outrun the build-time, static-scanning model that used to be good enough, and introduced the agent detonation chamber as an old idea applied to a new problem: judge a skill by what it does at runtime, not by what an LLM judge thinks it says.
Taken together, it was a week that made the same point from three directions at once: investors, researchers, and practitioners are all converging on the same conclusion. Securing AI agents is no longer a future problem.
See It for Yourself
Between the PleaseFix disclosures, the AI Total launch, and a fresh $125 million to build on, Zenity's Black Hat week was really one argument told three ways: agents need security built for how they actually behave, not just for the prompts they receive or the models underneath them. If your team is still relying on point-in-time scans or prompt-level filtering, this is a good time to see what agent-centric, runtime-aware security actually looks like. Sign up for a demo, and we'll walk through it.
All ArticlesRelated blog posts

Risk Discussed, Security Defined: AI Agent Security Summit On-Demand
Almost two weeks have passed since the 2026 AI Agent Security Summit wrapped at the Commonwealth Club in San Francisco,...

Automation, Intent, and Ownership: What to Learn from the AI Agent Security Summit
When the AI Agent Security Summit launched in San Francisco last October, agent-based threats had already escalated...

Here's what's waiting for you in San Francisco at The AI Agent Security Summit
May 27, 2026. Commonwealth Club. It’s going to be epic. Last October was our biggest summit yet. But this one...
Secure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo