Featured research
The incident that made this concrete
AI Agent Security · Flagship incident researchAnatomy of an AI-Orchestrated Intrusion: A Technical Reconstruction of GTG-1002The flagship. In November 2025 Anthropic disclosed a campaign in which an agent ran the majority of an intrusion lifecycle at machine speed. We reconstruct the architecture, isolate the boundary that failed, and build the counterfactual secure deployment.Active research cluster · latest
All publications in this cluster
Research areas
What we investigate
Research questions
Questions driving the cluster
Open questionsOPEN QUESTION
- Can any defense drive indirect prompt-injection success low enough for high-privilege production agents?
- How much autonomous offensive capability is real versus an artifact of information handed to the benchmark?
- What is the right identity model for an agent that acts for a user but is not the user?
- Is behavioral alignment ever a sufficient substitute for architectural containment?
- How do you detect an agent that is doing exactly what it was told — by an attacker?
Incident research
Real-world incidents we analyze
Engineering evidence
Recent papers we are following
- Anthropic. Disrupting the first reported AI-orchestrated cyber espionage campaign (GTG-1002). Anthropic — Primary disclosure, 2025. https://www.anthropic.com/news/disrupting-AI-espionage
- T. Shi, J. He, Z. Wang, H. Li, L. Wu, W. Guo, D. Song. Progent: Securing AI Agents with Privilege Control. arXiv:2504.11703, 2025. https://arxiv.org/abs/2504.11703
- R. Fang, R. Bindu, A. Gupta, D. Kang. LLM Agents can Autonomously Exploit One-day Vulnerabilities. arXiv:2404.08144, 2024. https://arxiv.org/abs/2404.08144
- Y. Zhu, A. Kellermann, A. Gupta, P. Li, R. Fang, R. Bindu, D. Kang. Teams of LLM Agents can Exploit Zero-Day Vulnerabilities. arXiv:2406.01637, 2024. https://arxiv.org/abs/2406.01637
- Y. Zhu, A. Kellermann, D. Bowman, P. Li, A. Gupta, et al.. CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application Vulnerabilities. arXiv:2503.17332, 2025. https://arxiv.org/abs/2503.17332
- E. Debenedetti, J. Zhang, M. Balunović, L. Beurer-Kellner, M. Fischer, F. Tramèr. AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents. arXiv:2406.13352, 2024. https://arxiv.org/abs/2406.13352
- K. Huang, V. S. Narajala, J. Yeoh, J. Ross, R. Raskar, et al.. A Novel Zero-Trust Identity Framework for Agentic AI: Decentralized Authentication and Fine-Grained Access Control. arXiv:2505.19301, 2025. https://arxiv.org/abs/2505.19301
- M. M. Hasan, H. Li, E. Fallahzadeh, G. K. Rajbahadur, B. Adams, A. E. Hassan. Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers. arXiv:2506.13538, 2025. https://arxiv.org/abs/2506.13538
From the ProxyTech blog
Accessible lead-ins
ProxyTech Research is an independent engineering-analysis project. We reference public academic papers and primary security disclosures; we do not claim peer review, journal publication, arXiv affiliation, or academic positions, and we do not represent the cited authors or vendors.