ChatGPT 'AgentForger' Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
ID: 3193a331-2914-55e1-ba24-9f7f6461cdf4
STIX ID: report--3193a331-2914-55e1-ba24-9f7f6461cdf4
Feed Name: CosmicBytez Labs
## Executive summary Zenity Labs disclosed "AgentForger," a Cross-Site Agent Forgery (CSAF) vulnerability in ChatGPT Workspace Agents that let a single phishing link auto-create and authorize a persistent autonomous agent using the victim's identity and enterprise connectors (Gmail, Outlook, Slack, Drive, SharePoint, etc.), enabling reconnaissance, data exfiltration, impersonation, internal phishing, and automated task execution; OpenAI removed the vulnerable URL parameter and patched the issue within four days with no known in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
