Observed Signal · Jun 30, 2026 · Research Report · Source: https://martechseries.com/feed/ · Impact: 3/5 · Sentiment: Negative
Zenity Labs: Attackers Weaponize Enterprise AI Infrastructure
Zenity Labs published research showing threat actors are actively exploiting vulnerabilities in enterprise AI infrastructure—particularly LiteLLM gateways—to hijack LLM endpoints, run offensive operations, and steal AI compute. Sensors across Zenity’s global AI threat network recorded thousands of real-world attack attempts, including same-day exploitation attempts against CVE-2026-40217 and campaigns targeting other LiteLLM flaws such as an admin-endpoint issue (CVE-2026-35029) patched by BerriAI and a novel SSRF variant related to CVE-2024-6587. Observed attacker behaviors included deploying autonomous pentesting tools (Strix) against live targets, routing multi-agent enterprise workflows through exposed infrastructure, and unintentionally exposing development artifacts via OpenAI’s Codex. Zenity’s co-founder and CTO Michael Bargury said the research reveals attacker TTPs and rapid exploitation timelines, and the company plans to publish additional findings.
Research documents active, large-scale exploitation of widely deployed LLM gateway (LiteLLM) vulnerabilities—including same-day exploitation—highlighting material operational and security risks for enterprise AI deployments and potential third-party abuse or compute theft.
Track OpenAI Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Zenity Labs research observed thousands of real-world attack attempts against enterprise AI infrastructure using a global network of AI threat intelligence sensors.
- Attackers exploited critical LiteLLM vulnerabilities, including widespread exploitation attempts targeting CVE-2026-40217 the same day it was patched.
- Zenity recorded campaigns exploiting additional LiteLLM issues, including a server-side request forgery variant linked to CVE-2024-6587 and CVE-2026-35029 (admin endpoint), the latter patched by BerriAI.
- Threat actors abused exposed LLM endpoints to direct autonomous tools (e.g., Strix) at third-party targets, route multi-agent workflows, and use exposed AI infrastructure as free compute (AI compute theft).
- Zenity’s methodology involved deploying traps that simulate vulnerable enterprise AI infrastructure and agents to capture attacker techniques, tactics and procedures (TTPs).
Connected Companies & Entities
3 Entities mapped“While another inadvertently exposed their full development environment, git history, and reconnaissance scripts through OpenAI’s Codex....”
“Author: Business Wire —June 30, 2026...”
“The article was published on MarTech Series and repurposed a Business Wire release on June 30, 2026....”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
AI Agents Enable Fully Autonomous Cyber Intrusions
An independent OSINT-based cyber threat analysis published 2026-05-30 documents five related incidents from late May 2026 that indicate a shift in attacker tradecraft: AI is moving from a human-accelerating tool to an autonomous operator and an exploitable attack surface. Notable cases include a Sysdig-documented Marimo notebook compromise (CVE-2026-39987, CVSS 9.3) where an LLM agent autonomously executed a multi-stage pivot and dumped an internal PostgreSQL database; ChatGPhish, a prompt-injection-style attack against ChatGPT’s renderer disclosed by Permiso Security; Wiz’s JINX-0164 supply-chain and dev-infrastructure attacks against crypto targets (macOS RATs, trojanized npm package @velora-dex/sdk); Rapid7’s unauthenticated-to-RCE chain in Gogs (CVSS 9.4, reported 2026-03-17) with a public Metasploit module and ~1,141 internet-exposed instances; and a KelpDAO/LayerZero bridge compromise illustrating off-chain verifier single points of failure. The author emphasizes reducing trusted dependencies, isolating credentials, runtime behavioral detection, and treating AI output as the start—not the end—of verification.
Anthropic Leak and LiteLLM Supply-Chain Hack Spotlight AppSec
A newsletter summarizing RSA 2026 highlights a pair of high‑profile AI security stories: Fortune reported leaked documents about Anthropic’s in-development model “Claude Mythos,” which Anthropic warned could pose “unprecedented cybersecurity risks,” and Snyk detailed a supply‑chain compromise of LiteLLM. Researchers attribute the LiteLLM incident to threat actor TeamPCP using an AI‑driven tool (hackerbot‑claw / openclaw) to automate targeting; a human developer, Callum McMahon at FutureSearch, first detected the compromise when a malicious payload caused a fork bomb. The author argues AI model releases expand both attack surface and defender opportunity, and RSA conversations favored a layered AppSec approach: LLM‑powered discovery plus deterministic verification and human oversight. Other RSA themes: agent identity/permissions, permission‑fatigue, social engineering rise, nation‑state activity, and accelerating platform consolidation and M&A dynamics in security.
Zenity Labs Reveals 'AgentForger' ChatGPT Vulnerability
Zenity Labs disclosed 'AgentForger,' a critical vulnerability in OpenAI's ChatGPT Workspace Agents that let attackers inject a malicious autonomous agent via a single phishing ChatGPT link. The forged agent could be created in the name of a clicked employee, inherit that employee's enterprise connectors (email, calendar, cloud storage, Slack/Teams) and existing authorizations without showing an OAuth consent screen, and be scheduled to repeatedly exfiltrate files, harvest credentials and MFA tokens, impersonate users, and persist inside the organization. Zenity Labs reported the issue to OpenAI via Bugcrowd on 2026-06-04; OpenAI acknowledged the report within a day and removed the vulnerable URL parameter within four days, patching the flaw before public disclosure. Zenity framed AgentForger as an evolution of CSRF and a new class of attacker-created, agentic insiders; exploitation in the wild is unknown.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
