Threat Labs

Read Our Latest blogs here

Categories
Category Filter Radio
A Fake Bug Report
Threat Labs
10 min read
One Fake Bug Report Hijacked a $250 Billion Company’s AI Agent - Then 100+ More
Tenet Threat Labs has demonstrated a new class of attack "Agentjacking" that hijacks AI coding agents into running attacker-controlled code on a developer's machine, triggered by a single fake error report and invisible to every security control.
deploy ai agents
Threat Labs
10 min read
What Security Leaders Need to Know Before Deploying AI Agents
AI agents are being deployed faster than the security controls to manage them. Three questions every security leader should be able to answer before any agent ships: what it can do, what controls exist if it misbehaves, and how you'll know when something goes wrong.
AI Agents Under Attack
Threat Labs
5 min read
AI Agents Under Attack
Tenet Threat Labs recently captured three live attacks targeting enterprise AI agents — prompt injection, CoT goal manipulation, and MCP-layer exploitation. None were flagged by conventional tools. Active exploitation isn't coming - it's already here.
private llm at risk
Threat Labs
5 min read
Private LLMs at Risk: How We Leaked Hugging Face Private Models via S3 Misconfigurations
Tenet Research declassifies a critical S3/CDN flaw in Hugging Face that exposed private LLM weights via a "header-override" exploit. This case proves that static configs aren't enough. Runtime defense is the only way to secure the agentic baseline. Full teardown here:
what is agentjacking_
Threat Labs
5 min read
What is Agentjacking?
Enterprise AI has evolved. We have moved past simple chat interfaces to autonomous agents with the power to query databases, call APIs, and execute code. But this autonomy comes with a trade-off: a new breed of sophisticated, multi-stage attacks that turn an agent's reasoning against itself.