#10
The Hacker News
general
July 24, 2026 at 11:53 UTC
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
By [email protected] (The Hacker News)
AI Summary
Zenity Labs disclosed 'AgentForger,' a critical vulnerability in OpenAI's ChatGPT Workspace Agents that allowed a single phishing link to silently create, authorize, and deploy an autonomous AI agent inside a victim organization's workspace, effectively inserting a persistent insider threat. OpenAI patched the vulnerability as of June 8, 2026. The attack required no user interaction beyond clicking the phishing link, and the rogue agent could operate with the victim's organizational permissions indefinitely.
Relevance score: 72.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →