One ChatGPT link could smuggle a rogue AI agent into your company
ID: c44022a9-0895-52f0-9e27-f154e01942dd
STIX ID: report--c44022a9-0895-52f0-9e27-f154e01942dd
Feed Name: The Register (Security)
Researchers at Zenity Labs disclosed a vulnerability called "AgentForger" in OpenAI's ChatGPT workspace agent builder that allowed a single-click link to silently create and publish a malicious autonomous agent within a victim's workspace. If a user belonged to a workspace with agents enabled and had connectors (Outlook, Teams, Slack, SharePoint, Google Drive) permitted, the forged agent could use those permissions to browse files, send messages as the user, and receive attacker instructions via email, effectively acting as a persistent insider; OpenAI removed the vulnerable URL parameter within days of disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
