Researchers say a single malicious ChatGPT link could plant an attacker-controlled AI agent inside a company’s ChatGPT workspace and make it act with an employee’s access. Zenity Labs said the flaw, dubbed AgentForger, affected OpenAI’s workspace agent builder and let a crafted URL silently create, configure, publish, and schedule a rogue agent that could use approved connectors such as Outlook, Teams, Slack, SharePoint, and Google Drive. OpenAI reportedly fixed the issue in June 2026 by removing the vulnerable URL parameter.
Why it matters: This matters because it turns a normal phishing click into a persistent insider-style foothold that can search company data, send messages as an employee, and continue operating after the initial lure. Organizations using ChatGPT workspace agents should review agent-creation permissions, connected app access, and logs for unexpected agents or scheduled tasks.
Kevin Townsend
2026.07.23
98% relevant
This article is a direct report on the same AgentForger vulnerability, adding detail on the attack chain: abuse of Agent Builder URL parameters, use of the Chief of Staff template and initial_assistant_prompt, invisibility conditions, and post-compromise uses such as recon, credential harvesting, internal phishing, and business email compromise.
2026.07.23
100% relevant
This article appears to be the first tracked report of the specific OpenAI 'AgentForger' workspace-agent vulnerability and its phishing-based abuse path.
← Back to all stories