
Security Researchers: Digital Fighters Series
Zenity: “The threat AI creates is not about what AI models say, but about what agents do”
Tamir Ishay Sharbat, Director of Security Research at Zenity, explores what constitutes true innovation in AI security as part of CTech’s Security Researchers series.
“Prior to joining Zenity, I had no background in cyber. Literally nothing,” explains Tamir Ishay Sharbat, Director of Security Research at Zenity, a company that recently raised $125 million in a funding round led by Norwest. Having begun coding at age 12 out of a sheer love for the craft, Ishay Sharbat came up more as an engineer. The same passion led him to experiment with AI assistants like ChatGPT, which eventuated in the realization that he was actually doing security research upon meeting Zenity Co-Founder and CTO Michael Bargury. Fast forward through multiple Black Hat conferences, and his team was among “the first to recognize that the threat AI creates is not about what AI models say, but about what agents do.”
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
“Security research is the art of turning every stone, of pulling on elusive threads. That’s why researchers with a unique vision rise above,” Ishay Sharbat continues. Looking ahead, he believes the best researchers will share two qualities: a solid understanding of “what AI needs in order to succeed” as well as “unorthodox thinking”. “The field is becoming a lot about how you enable your AI rather than how it enables you,” he notes.
You can read the entire interview below.
ID Card
Company name: Zenity
Founders: Ben Kliger (CEO), Michael Bargury (CTO)
Year of founding: 2021
Current number of employees: 260
Company Description:
Zenity is the AI security and governance platform for AI agents. Zenity gives security teams the visibility, enforcement and response capabilities needed to secure every agent in the environment, so risks are reduced early, boundaries are enforced in real time and every incident response makes the platform stronger. Trusted by Fortune 500 enterprises and recognized by industry analysts, Zenity enables organizations to operationalize AI at scale without compromising security.
About Zenity's Security Research Team:
The Zenity Red Team is the offensive cybersecurity group in Zenity Labs, Zenity’s AI research lab.
The Red Team consists of about 10 top AI Security Researchers spread around the world, from Israel to Portugal to San Francisco, and the entire Zenity Research team has about 40 researchers. It’s an all star team in every sense of the word.
Zenity was among the first to recognize that the threat AI creates is not about what AI models say, but about what agents do. At Black Hat USA 2024, we demonstrated the industry's first indirect prompt injection attack that impacts real-world environments through Microsoft Copilot. That started a snowball where the world’s leading researchers wanted to join our team, leading to more cutting edge research that attracted even more researchers.
What is your background in cyber, and what led you to specialize in security research?
So this one’s kind of funny: prior to joining Zenity, I had no background in cyber. Literally nothing. I wasn’t at a top 8200 unit, I didn’t work in cyber before, I haven’t found a single vulnerability. I was more of an engineer, started coding at 12, loved it, and just rolled along with that (I went through some interesting “rolling” but that’s a story for another time). But then ChatGPT came out, and it was obvious to me that something very special was happening here.
I joined Zenity at an interesting point in time, it was early 2024, just when everyone was starting to use ChatGPT but it still wasn’t obvious how this amazing tech was going to change our lives. And when I started playing with it, I very quickly gravitated towards making it do things that it shouldn’t. I wasn’t very fond of it refusing my instructions. At the time I didn’t realize I was doing AI security research, but when I met Michael Bargury (Zenity’s Co-Founder and CTO) for the first time it was very clear to me that I wanted to dive deeper.
From there the road was paved; we were from the pioneers of AI Security research. We were among the first ones to show how dangerous this technology can be, hijacking notable AI assistants such as Microsoft Copilot and ChatGPT, by simply sending an email or sharing a document, and manipulating them to steal sensitive data, carry out phishing attacks and much more. I personally spoke twice at Black Hat USA – the biggest security conference in the world. And overall, Zenity Labs has produced seven Black Hat talks in the last four years. It’s been one hell of a ride.
What does your security research team look like in action?
The mission of Zenity Labs is to break new ground in AI security. That one simply articulated goal guides all of the decisions we make on a daily basis. We’re constantly tracking new developments across the AI ecosystem and when something significant comes out we drop everything and start to investigate, usually disclosing the first vulnerability within a week. The rate of innovation in AI is insane, and being at the top of the AI security field means you have to keep challenging yourself. Each major release, from MCPs to Coding Agents and to Agentic Browsers, expands what LLMs can do and the environment they operate in. And all this innovation, well you guessed it, creates new ways in which things can go wrong. Innovating in AI security means understanding the security implications of these major releases, and it demands moving quickly to uncover and demonstrate how these new capabilities can be abused.
Innovating in AI security also means going deep. We spend months diving into how the technology is built behind the scenes, breaking apart every cog and screw in it, uncovering new attack vectors and vulnerability classes. Sometimes what seems like a small change can lead to some very unexpected consequences, especially when you put AI in the mix.
How does the research team influence your company at large?
That’s a great question, Zenity is the category leader when it comes to AI security, recognized by Gartner as the “Vendor to Beat”. We partner with some of the most innovative companies in the F500 to help them secure their AI adoption. And that’s a lot of AI adoption to secure. With every new release coming out, our customers are already adopting it within a month. This is unheard of in large enterprises, but AI moves at a different pace. So to make sure our customers are safe we need to come up with solutions within that time frame. But you can’t come up with security solutions without having a deep and true understanding of the risks, and that’s where we come in.
We react fast because that’s what securing AI demands. Our customers trust us to have their backs and secure their AI adoption. In order to do that we need to be experts in risk. When we dive in to uncover vulnerabilities in major AI releases a big part of the result is a deep understanding of the threat model of the specific technology. This threat model then guides the support Zenity needs to provide in order to keep our customers secure.
What has been your team’s most significant security discovery to date?
Two years ago, at Black Hat 2024, we presented major research into Microsoft Copilot. Back then, Microsoft was the main player driving AI adoption into the enterprise, while OpenAI and Anthropic hadn't cracked it yet. Indirect prompt injections and hijacking AI were still theoretical risks, demonstrated in academic settings but yet to be shown on an enterprise-grade product with real impact. We set out to change exactly that, demonstrating indirect prompt injection could create real harm in a widely used enterprise product.
What we showed was that by simply sending an email, an attacker can hijack Microsoft Copilot to give misleading answers, phish the victim by abusing their over-reliance on it, and even get Microsoft Copilot to harvest and exfiltrate sensitive data from the user’s personal files. All of this, and the only thing that needed to happen was for Microsoft Copilot to read a random email. It was breakthrough research, the first time indirect prompt injections and AI hijacking were demonstrated at the enterprise level.
The second discovery that comes to mind we presented just a few weeks ago: it was a deep dive into the risks of Agentic Browsers. How they break the browser security model completely – a security model we spent about 20 years perfecting. This research for me is the poster child of how AI fundamentally changes security, how integrating it into a previously secure technology can lead to a series of unexpected consequences.
We took Agentic Browsers apart completely, demonstrating how a simple comment at a random location on the internet that your AI browser reads can lead to anything from 0-click data exfiltration, to full account takeovers of your password manager, executing code on your machine, and the list goes on. These risks are relevant to all agentic browsers, the technology itself is vulnerable by design. This is usually the case with AI: the more capable it is, the more dangerous.
Who or what is your 'Moby Dick'?
I myself don't have a specific Moby Dick. That’s probably because of what we do at Zenity Labs – we’re always after the next crucial vulnerabilities and new attack vectors that might impact millions of people around the world. It’s an elusive goal that keeps changing as the field of AI evolves. My Moby Dick is keeping up with it.
How would you characterize the competition between research teams today?
The competition between research teams today is intense, especially when it comes to AI Security.
Everyone is finding new vulnerabilities all the time, and it’s becoming harder and harder to rise above the noise. We live in a reality where in order to stand out you must find truly compelling and groundbreaking discoveries. And finding them requires creativity, vision and a unique type of intuition.
Security research is the art of turning every stone, of pulling on elusive threads. That’s why researchers with a unique vision rise above. And in AI security truly ground breaking discoveries come from the combination of traditional security and a deep understanding of AI. It’s a unique type of expertise that produces unique insights. Researchers who have this combination conduct their research differently from the get-go; they notice different risks and find new ways in which things can break. They know which threads they should follow through on and notice stones other people would have completely missed. True innovation and pushing the field forwards comes from going where only a few thought to go before.
Working with large enterprises every day gives you a deeper understanding of the risks that matter most; this helps focus where to look in the first place and leads to finding vulnerabilities with real-world impact. Having direct visibility into the threats that target large enterprises gives us an unfair advantage in finding the exposures that matter.
What is your take on the future of the human security researcher?
As a security researcher today, you have to use AI; it has become a requirement. Security researchers explore a lot and try different ideas that lead nowhere. Before AI, you needed to do all of this by hand, but now you have a personal assistant who can explore and pursue your ideas for you and provide you with the results. That’s the initial point; today, this is a minimum requirement for a security researcher.
Where it gets more interesting is that AI can find vulnerabilities by itself now, without human guidance. Today everyone is aware of it, especially with the recent OpenAI and HuggingFace incident or the release of Mythos, but the frontier of AI security research knew it 18 months ago. AI gives researchers the ability to pull on hundreds of threads instead of just one. Used correctly, it amplifies human agency rather than replacing it.
I believe the best researchers will have two qualities. First, they understand very well what AI needs in order to succeed. The field is becoming a lot about how you enable your AI rather than how it enables you. This is a differentiator; researchers who become experts in this will outshine the competition. This is true both for speed and, as LLMs become even better at security research, the types of findings as well.
The second quality will be unorthodox thinking: figuring out new questions to ask and threads to pull that LLMs would not have thought about themselves. The understanding of how to instruct the LLMs and where to focus the effort will come from the researchers themselves, driven by their own creativity regarding what they set out to achieve.














