Black Hat USA

Your agent just made a decision. Do you know what it was?

Come see Zenity at Black Hat in August in Las Vegas from August 4th-6th! See how you can secure the agent at the decision level by stopping by Booth #5521 for a demo!

Get involved for:

🎤 Theatre talks at our booth from leading researchers, and keynotes on the main stage

💡 Exclusive access to the AI Summit on August 4th

🎪 Community events, functions and happy hours with participation from OWASP

🍸 Exclusive happy hours and briefings for security advocates, champions, and practitioners


Zenity is the first security and governance platform purpose-built for AI agents, spanning SaaS, homegrown platforms (Cloud), and end-user devices (Endpoint).


We'd love to connect! Fill out the form to schedule an in-person meeting with us.

Explore the Sessions at Booth #5521

Wed, Aug 5

Caught in the Wild: Real-World Attacks on AI from a Global Honeypot Network

03:00 PM

Everyone's asking whether attackers are actually going after AI systems yet. We stopped guessing and went looking. We built a global network of AI honeypots, hundreds of decoy AI servers and agents spread across clouds providers and regions, and watched who showed up. What we caught: attackers stealing compute to run their own AI workloads on our bill, turning AI tools' own features into weapons to forge server-side requests, attempts to run code and steal secrets, and even pointing autonomous hacking agents and "jailbroken" personas at our exposed AI decoy backends to attack 3rd parties, and more. This research shows real attacks, prompts, and techniques that threat actors used, and what it means for anyone deploying AI.

Coding Agents Overview: Attacks and Mitigations

06:00 PM

Coding agents slash delivery times for development teams and boost output quality, but only if operated securely. Running on user endpoints, coding agents can leak local files, invoke insecure tools, or adopt unauthorized skills. Without any hard code, threat actors can hijack coding agents and invoke risky activity directly inside an organizations production database. In this talk, see how coding agents can easily chain privilege escalation to accomplish nefarious goals, and how to prevent them from going rogue.

You Can't Patch a Mental Model: How Agentic Systems Expose Our Hidden Security Assumptions

08:00 PM

Agentic security isn't hard because it's new. It's hard because it breaks the assumptions our security models are built on. We keep trying to secure agents when what's actually needed is to govern agency, and those are fundamentally different problems. This talk exposes eight hidden assumptions baked into modern security architectures, ones that adaptive, goal-driven systems expose ruthlessly, and offers security leaders a systems-based lens to spot controls that are structurally incapable of working, reason about risk through the four dynamics that shape all systems (control, decision-making, flow, feedback), and build controls that constrain causes instead of chasing behavior.

Thu, Aug 6

Technical Deepdive: Claude in Chrome

03:00 PM

Agentic browsers represent a new manifestation of AI risk. With persistent access and long horizon goals, the threat vectors for Claude in Chrome are innumerous and frequently changing. In this talk, see how Claude in Chrome is built, broken, and requires hard boundaries built in code, not training

Pwning Agentic Browsers

04:30 PM

Agentic browsers are tearing down decades of web security to enable AI autonomy: breaking Same-Origin Policy, granting raw localhost and filesystem access, and running scripts on any site, with model alignment as the only real defense. We introduce PleaseFix, a new ClickFix-style vulnerability class that targets agents instead of humans, and Intent Collision, a universal technique to exploit it, then chain them into full 0-click attacks on flagship agentic browsers achieving account takeover, data theft, persistent implants, and remote code execution. We also break down which defenses actually held, and why code-enforced boundaries beat model training every time. Walk away with concrete hardening steps you can apply today, no vendor patch required.

Black Hat USA AI Summit

Join Zenity for the AI Summit at Black Hat Tuesday, August 4

Join us at the AI Summit for a full day of expert perspectives, cutting-edge research, and strategic discussion on navigating AI's dual role as both a security accelerator and an emerging threat vector. Whether you're defending against AI-powered attacks or securing the AI your organization is deploying, this is where the conversation is happening.

See you there.

Feature media
Happy Hour at Brewdog

Happy Hour with Zenity and OWASP at Brewdog

August 4 | 5:30pm

Join leaders from OWASP GenAI and Zenity for networking and strategic discussions on building and breaking AI security. Registration is free, but spots are limited, so reserve now!

Why Meet With Us?

AI Agents are Everywhere. Make Sure They’re Secure.

AI Agents have transformed everything about how business gets done. Not only do they come in the form of enterprise Agents like Microsoft 365 Copilot, Google Gemini, Amazon Q, and Salesforce Einstein, but they can also be customized and built by anyone across the enterprise. Agents are inherently connected to corporate data, actions, other agents, applications, and triggers, and requires defense in depth. That’s where we come in.

Secure Your Agents

We’d love to chat with you about how your team can secure and govern AI Agents everywhere.

Get a Demo