AI Threat Research & Intelligence
800px
20px
150px
1px
Who We Are

Pillar has assembled the world's brightest minds from military intelligence and enterprise security to dismantle emerging threats in the new AI landscape. Our team’s expertise fuses deep offensive roots in traditional security (AppSec, Cloud, OS, Malware) with Frontier AI disciplines (Data Science, AI, Machine Learning). This hybrid DNA allows us to deconstruct complex attacks that cross the boundary between code, infrastructure, and autonomous systems.

What we do
What we do

Adversarial AI Research

Dissects Foundation Models and agents to identify zero-day vulnerabilities, novel jailbreaks, and prompt injection techniques.

Threat Intelligence

Monitors the wild for emerging trends in how attackers are weaponizing AI, delivering proactive insights rather than reactive alerts.

Red Teaming Operations

Simulates sophisticated attacks on AI pipelines to validate defenses and expose logic gaps that standard tools miss.

Architecting Enterprise Defense

Translates research into product capabilities, building next-gen features like the Safe MCP Registry and integrated Threat Intel feeds to secure the future of AI work.

Open Source & Supply Chain Security

Actively hunts for vulnerabilities in the open-source AI ecosystem—from coding agents to model hubs—to harden the community tools that enterprises rely on.

Our Work

Our research team have identified & reported security vulnerabilities in the most popular coding agents, IDEs, model hubs and agentic workflow platforms.

Latest Research:
What we discovered
The Week of Sandbox Escapes: Why agentic security needs its own threat model
tl;dr

Over several months, Pillar Research found and reproduced sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI, and Antigravity. In almost every case, the agent did not need to break the sandbox directly. It only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe. In aggregate, these vulnerabilities show that AI coding agents change the endpoint threat model, and that most sandbox designs have not caught up.

full Research

We are releasing the research  as The Week of Sandbox Escapes: one deep-dive a day, each showing a different route across the boundary. The bottom line is that an agent's blast radius is not the agent process; it includes everything the agent can write that the host later trusts.The productivity gains of agents are real, and developers are already using them. The problem is that these tools became infrastructure before most organizations governed them as infrastructure.

White geometric logo with three vertical bars of varying heights on a red background.

By

Pillar Research Team

read now
Diagram showing functions including get_ticket_status, search_tickets, update_ticket_status, provide_troubleshooting, and fetch_website, highlighting fetch_website as the root cause of prompt injection due to fetching untrusted content from URLs, with a suggested fix to isolate untrusted data and allowlist trusted domains using Adaptive Guardrails.
More AI vulnerability research

Dan Lisichkin

and

Dan Lisichkin

and

Dan Lisichkin

and

Meet the Pillar Research Team

Schedule a deep dive with the Pillar research team to learn about our latest research and findings. Get direct access to our experts and hear about the most novel attacks we are seeing in the wild

Thank you!
Oops! Something went wrong while submitting the form.