Recent research from Zenity Labs reveals that some of the most widely used AI agents and assistants from major tech companies such as Microsoft, Google, and OpenAI are at risk of being hijacked, with attackers able to carry out attacks with little to no user interaction.

In a demonstration at the Black Hat USA cybersecurity conference, Zenity researchers showed how hackers can steal data, manipulate critical workflows within target organizations, and even impersonate users in some cases.

The researchers noted that beyond infiltrating these agents, attackers can also achieve memory persistence, thereby maintaining long-term access and control.

"Attackers can tamper with instructions, poison knowledge sources, and completely alter agent behavior," Greg Zemlin, product marketing manager at Zenity Labs, told Cybersecurity Dive. "This opens the door to sabotage, operational disruption, and long-term misinformation, especially in environments where agents are trusted to make or support critical decisions."

The researchers demonstrated vulnerabilities in several popular AI agents, including:

  • OpenAI's ChatGPT: Through an email-based prompt injection attack, attackers could gain access to connected Google Drive accounts.
  • Microsoft Copilot Studio's customer support agents: Leaked the full CRM database, and researchers also found that over 3,000 in-the-wild agents posed a risk of leaking internal tools.
  • Salesforce's Einstein platform: Was manipulated to redirect customer communications to email accounts controlled by the researchers.
  • Google Gemini and Microsoft 365 Copilot: Attackers could turn these into insider threats, targeting users through social engineering attacks and stealing sensitive conversations.

Zenity Labs has disclosed its findings to the relevant companies. Some companies immediately released patches, but it is unclear what guidance others have provided.

"We appreciate Zenity identifying and responsibly reporting these techniques through coordinated disclosure," a Microsoft spokesperson told Cybersecurity Dive. "Our investigation determined that the reported behaviors are no longer effective against our systems due to ongoing systematic improvements and updates to our platform."

Microsoft stated that Copilot agents are designed with built-in security protections and access controls, emphasizing the company's commitment to continuously strengthening systems against emerging attack techniques.

OpenAI confirmed it has communicated with the researchers and has released a patch for ChatGPT. The company stated it maintains a bug bounty program for disclosing similar issues.

Salesforce said it has fixed the issues reported by Zenity.

Google said it recently deployed new layered defenses to address issues like those found by Zenity.

"A layered defense strategy against prompt injection attacks is critical," a Google spokesperson said, referencing the company's recent blog post on AI system protections.

This research comes as AI agents rapidly proliferate in enterprise environments, with companies encouraging employees to view the technology as a significant productivity booster.

Researchers at Aim Labs demonstrated similar zero-click risks involving Microsoft Copilot earlier this year, and they said Zenity Labs' findings indicate a lack of adequate security protections in the rapidly growing AI ecosystem.

"Unfortunately, most agent-building frameworks, including those from AI giants like OpenAI, Google, and Microsoft, lack proper guardrails, leaving the burden of managing the high risk of such attacks on enterprises," Itay Ravia, head of Aim Labs, told Cybersecurity Dive.

Read more Black Hat USA 2025 news, clickhere