Home / Jul 25, 2026 / Story
0
#10 The Hacker News general July 24, 2026 at 11:53 UTC

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

By [email protected] (The Hacker News)

AI Summary

Zenity Labs disclosed 'AgentForger,' a critical vulnerability in OpenAI's ChatGPT Workspace Agents that allowed a single phishing link to silently create, authorize, and deploy an autonomous AI agent inside a victim organization's workspace, effectively inserting a persistent insider threat. OpenAI patched the vulnerability as of June 8, 2026. The attack required no user interaction beyond clicking the phishing link, and the rogue agent could operate with the victim's organizational permissions indefinitely.

Relevance score: 72.0/100

# More from July 25