Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Researchers Boot Jailbroken iOS 17 on iPhone 11 Pro
July 27, 2026
Google Names Cybercrime Groups to Detail Motives and Origins
July 27, 2026
Critical ChatGPT AgentForger Flaw Lets Attackers Deploy Rogue Agents
July 27, 2026
Home/CyberSecurity News/Critical ChatGPT AgentForger Flaw Lets Attackers Deploy Rogue Agents
CyberSecurity News

Critical ChatGPT AgentForger Flaw Lets Attackers Deploy Rogue Agents

Key Takeaways A critical flaw, dubbed “AgentForger,” was discovered in OpenAI’s ChatGPT Workspace Agents. The vulnerability allowed attackers to deploy rogue AI agents within a...

Emy Elsamnoudy
Emy Elsamnoudy
July 27, 2026 4 Min Read
5 0

Key Takeaways

  • A critical flaw, dubbed “AgentForger,” was discovered in OpenAI’s ChatGPT Workspace Agents.
  • The vulnerability allowed attackers to deploy rogue AI agents within a victim’s organization via a single phishing link.
  • These malicious agents could silently access and exfiltrate sensitive data, impersonate users, and establish covert command-and-control.
  • Zenity Labs reported the issue to OpenAI, which promptly patched the vulnerability on June 8, 2026.

ChatGPT AgentForger Flaw Enables Rogue Agent Deployment

Cybersecurity researchers have uncovered a severe vulnerability, named AgentForger, within OpenAI’s ChatGPT Workspace Agents. This critical flaw allowed malicious actors to silently create, configure, and publish fully autonomous, attacker-controlled AI agents inside a victim’s organizational environment, requiring only a single click on a phishing link.

Table Of Content

  • Key Takeaways
  • ChatGPT AgentForger Flaw Enables Rogue Agent Deployment
  • The Mechanics of the AgentForger Vulnerability
  • Potential Impact and Exploitation
  • Resolution and Mitigation
  • What You Should Do

Unlike conventional Cross-Site Request Forgery (CSRF) attacks, which typically manipulate a single request, AgentForger facilitated the complete orchestration of an autonomous AI agent, operating with the implicit trust of the victim’s enterprise infrastructure. This distinction elevates the threat significantly, as the rogue agent could then perform a wide array of unauthorized actions.

The Mechanics of the AgentForger Vulnerability

ChatGPT Workspace Agents are designed to integrate with essential enterprise services such as Outlook, Gmail, Slack, Google Drive, SharePoint, and Microsoft Teams. Under normal operational procedures, users interact with a conversational builder canvas to create and customize these agents.

However, an in-depth technical analysis by security researchers at Zenity Labs revealed a critical design flaw. The agent builder interface accepted its initial state directly through URL parameters, specifically template_name and initial_assistant_prompt. Crucially, the initial_assistant_prompt parameter did not merely pre-populate an input field; instead, its contents were automatically submitted and executed the moment the page loaded.

This architectural oversight allowed an attacker to craft a seemingly innocuous ChatGPT link containing a comprehensive set of malicious instructions. When a logged-in victim, who had previously authorized at least one connector, clicked this link, the Builder autonomously initiated the agent creation process. The rogue agent automatically connected to all previously authorized integrations and, alarmingly, switched the write-action approval setting from “Always ask” to “Never ask.” This effectively neutralized a primary security safeguard designed to prevent silent, sensitive actions.

Once forged, the agent was published live and scheduled to execute every five minutes. It would then poll a designated attacker inbox for commands prefixed with “TASK” and email the results back, thereby transforming ChatGPT into a covert command-and-control (C2) channel. Since the necessary connectors were already authorized from legitimate prior usage, no new OAuth consent screen appeared, providing no indication of compromise to the victim.

Potential Impact and Exploitation

Researcher Mike Takahashi demonstrated the extensive capabilities of such a forged agent. Acting as an “agentic insider,” it could map organizational structures, exfiltrate sensitive documents, harvest credentials, and impersonate the victim across various communication platforms like Slack, Teams, and email. These tactics mirror sophisticated AI-assisted phishing operations, highlighting the severe risk posed by this vulnerability.

Zenity attributes the AgentForger flaw to a combination of two fundamental architectural weaknesses:

  1. Cross-Site Auto-Execution: The agent Builder’s readiness to execute unvalidated URL parameters immediately upon page load.
  2. Overpermissive Natural-Language Control: The ability of natural-language prompts to modify critical security settings, such as approval policies and execution schedules.

These factors collectively formed what the researchers termed a “lethal trifecta”: untrusted input, access to private data, and an unmonitored channel for data exfiltration.

Attack Stage Mechanism Impact
Delivery Phishing link containing crafted initial_assistant_prompt Initial execution trigger
Execution Auto-submitted prompt builds agent & attaches connectors Unauthorized workspace access
Privilege Bypass Approval setting flipped to “Never ask” Silent action execution
Persistence Recurring 5-minute schedules polling attacker inbox Continuous C2 communication
Impact Data exfiltration, credential harvesting, BEC staging Full workspace takeover

Resolution and Mitigation

Zenity reported the vulnerability to OpenAI via Bugcrowd on June 4, 2026. OpenAI promptly triaged and accepted the report within 24 hours, deploying a full patch on June 8, 2026. The fix involved removing the vulnerable URL parameter handler, effectively mitigating newly initiated attacks. Zenity confirmed that there was no evidence of active exploitation in the wild prior to the patch being applied.

Zenity’s subsequent analysis underscored the gravity of the flaw, demonstrating how a successfully forged agent could be commanded like a genuine insider threat, performing internal reconnaissance and facilitating business email compromise (BEC) schemes across an enterprise.

What You Should Do

  • Ensure all software, especially AI-powered agents and integrations, is kept up to date with the latest security patches.
  • Educate users about sophisticated phishing tactics, particularly those involving trusted application flows and unusual link structures.
  • Implement robust security policies that restrict AI agents from modifying critical security settings without explicit, multi-factor authenticated user approval.
  • Regularly audit the permissions and activities of all integrated AI agents within your enterprise environment.
  • Monitor for unusual network traffic or C2 patterns originating from within your trusted application ecosystem.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitPatchphishingSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

NodeBB Critical Vulnerabilities Let Attackers Read Private Chats, Take Over Forums

Next Post

Google Names Cybercrime Groups to Detail Motives and Origins

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Claude AI Chat History Exposed in Google Search Results
July 26, 2026
PentesterFlow AI Tool Automates Workflows for Pen Testers
July 26, 2026
Researcher Claims Jailbreak for GPT-5.6, Claude Opus 5, and Fable AI Models
July 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us