One ChatGPT link could smuggle a rogue AI agent into your company
Security researchers at Zenity Labs have disclosed a flaw in OpenAI's ChatGPT workspace agent builder that could let an attacker plant a malicious, autonomous AI agent inside a victim's corporate ChatGPT account via a single malicious link. Dubbed "AgentForger," the technique tricked ChatGPT into silently creating, configuring, publishing and scheduling an agent that could act through the victim's existing connected accounts and permissions, rather than relying on stolen passwords or session tokens. Because the rogue agent inherited the employee's genuine access to tools such as Outlook, Teams, Slack, SharePoint or Google Drive, researchers say it effectively became a "forged insider" capable of operating long after the initial phishing email had been dealt with.
In proof-of-concept tests, the agent monitored the victim's inbox for emails containing "TASK" in the subject line, treating each as a new instruction to search files, gather sensitive documents or send data back to the attacker by email. Demonstrated capabilities included mapping an organisation's staff and projects, hunting for passwords and API keys in chat histories, and sending convincing phishing messages from the victim's own Teams account. Zenity reported the issue to OpenAI via Bugcrowd on 4 June; OpenAI acknowledged it the next day and patched the flaw four days later by removing the URL parameter that enabled the attack, before any public disclosure.
- Flaw let a single ChatGPT link install a rogue AI agent
- Agent used victims' real access to Outlook, Slack, Teams, Drive
- OpenAI fixed the bug within days of Zenity's report
AI Americas Business Companies Cybersecurity Research Science Technology World