
Zenity Labs has developed a vulnerability called "Intent Collision" that enables 0-click attacks by deploying autonomous agents within organizations, bypassing traditional security measures. The attack is demonstrated through a case involving AgentForger, where a crafted link installed an agent without user interaction. The framework "Zenity's CISO's Guide to Securing Agentic AI" outlines "least agency" principles and runtime boundaries to prevent such attacks, even when model alignment and identity checks fail.


