Security · 2h ago
ChatGPT Workspace Bug Let Phishing Link Deploy Rogue AI Agents
Researchers at Zenity Labs disclosed AgentForger, a critical vulnerability in OpenAI's ChatGPT Workspace Agents that allowed a single phishing link to create, authorize, and deploy an autonomous AI agent inside a victim's organization. OpenAI patched the flaw on June 8. The attack required no user interaction beyond clicking a malicious link.
Meridian48 take
The disclosure underscores how AI agent platforms introduce new attack surfaces that traditional security tools may miss, especially when agents can be authorized and deployed via a single click.
Read the full reporting
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link →
The Hacker News
chatgpt-vulnerabilityai-agent-security