Critical ChatGPT AgentForger Vulnerability Enables Rogue AI Agent Deployment via Phishing
A critical CSRF vulnerability in OpenAI's ChatGPT Workspace Agents allowed attackers to deploy persistent rogue AI agents via phishing links, enabling unauthorized access to enterprise systems. The flaw exploited the Agent Builder tool to create autonomous agents that could execute tasks, exfiltrate data, and impersonate users without user interaction.
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization.
The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June 8,
*** END OF TRANSMISSION ***