Tel-Aviv, Israel
2021
  |  By Rock Lambros
Most of the industry discourse on agentic AI risk has settled into a comfortable framing: agents get attacked the way models get attacked, through some form of prompt manipulation, and the fix is a better guardrail. I think that framing is dangerously incomplete, and I want to walk through five specific scenarios that make the case directly rather than abstractly. Two of them are manipulation. One exploits trust between agents rather than any single agent's behavior.
  |  By Refael (Rafa) Lachmish
Zenity Labs is publicly launching AI Total: a free service that runs an AI agent skill in a sandbox and tells you what it actually did, before you let it near your agents.
  |  By Rock Lambros
Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know Many conversations about AI agent risk over the past year start from the same unspoken assumption: something bad happened because someone or something manipulated the agent. A hidden instruction in a document, a poisoned prompt, an adversary steering the model toward an action it shouldn't take. That's a real category of risk, and it deserves the attention it's getting.
  |  By Bob Clinton
Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know.
  |  By Bob Clinton
Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know Healthcare, as an industry vertical, is moving faster on agentic AI than it has in past technology evolutions. Some reports say it is outpacing other regulated industries. Ambient scribes are documenting patient visits in real time. Prior-authorization and revenue-cycle agents are handling payer workflows that used to require staff to log into multiple systems manually.
  |  By Cinthia Portugal
Zenity has been named a Market Shaper in Gartner's inaugural Emerging Market Quadrant for AI Application Security — Startup Vendors, a new report evaluating vendors on their ability to secure AI agents across the full agent lifecycle.
  |  By Molly Bauer
Enterprises aren't standardizing on one AI agent platform. Security teams are watching Copilot run alongside ChatGPT Enterprise, homegrown agents built on internal frameworks, and endpoint coding agents like Claude and Codex, often all inside the same organization. Each platform brings its own credentials, tool access, and blind spots, and none of them wait for a security review before taking an action.
  |  By Taylor Roberts
Ask ten people what "AI regulation" means, and you'll get ten different answers, and most of them will assume the others are talking about the same thing. They're not. "Regulate AI" has become a catch-all phrase covering several genuinely distinct regulatory questions, each with its own goal, its own toolkit, and its own plausible answer, bundled together so tightly that arguing about one gets mistaken for arguing about all of them.
  |  By Tomer Teller
Security teams evaluating an AI agent security platform tend to ask the same question after the first demo: will this keep up? Agentic AI changes shape every few weeks, with new frameworks, new coding agents, and new ways for an agent to reach a tool or a credential. A platform that covers today's stack and stalls on next quarter's isn't much of a bet.
  |  By Tomer Teller
AI agents are moving into production faster than security teams can govern them. And unlike traditional applications, agents continuously make decisions, invoke tools, access data, and take actions. Every one of those interactions creates security context that needs to be understood. At enterprise scale, asking analysts to manually evaluate every finding becomes impossible.
  |  By Zenity
Zenity's low-code security research team is exposed to real world low-code applications on a daily basis, and we're glad to share our knowledge in this domain in order to help you to design and develop secure low-code applications.

Continuously protecting all low-code/no-code applications and components! Design and implement governance policies, identify security risks, detect emerging threats and drive automatic mitigation and response.

Low-code/no-code development and automation platforms are the wave of the future. The largest companies in the world are already adopting low-code/no-code development for their core business units. But with all their benefits, low-code/no-code development brings with it a host of governance challenges and risks that are unaddressed by existing InfoSec and AppSec solutions.

Zenity, the first and only governance and security platform for low-code/no-code applications, creates a win-win environment where IT and information security can give business and pro developers the freedom and independence they want in order to continue pushing their business forward while retaining full visibility and control.

Our Platform:

  • Discover: Identify shadow-IT business applications across your low-code/no-code fleet and track sensitive and business data movement.
  • Mitigate: Identify insecure, vulnerable and risky configurations. Drive mitigation and remediation immediately.
  • Govern: Design policies and implement automatic enforcement. Eliminate risks without disrupting business.
  • Protect: Detect suspicious and malicious activity, such as supply-chain attacks, malware obfuscation and data leakage.

Governance and Security for Low-Code/No-Code Applications.