A security vulnerability in OpenAI's ChatGPT workspace agents allowed attackers to deploy rogue AI agents inside corporate accounts with a single click. The flaw, identified by security firm Zenity Labs, exploited the agent builder feature to create autonomous assistants that could access connected business applications under the victim's identity and permissions.
How the attack worked
The technique, dubbed "AgentForger," relied on tricking ChatGPT into processing malicious instructions embedded in what appeared to be a standard ChatGPT link. When clicked by a user with agent creation permissions, the link triggered the workspace to automatically configure, publish, and schedule an attacker-controlled AI agent. The agent could then leverage the victim's existing connections to services like Outlook, Teams, Slack, SharePoint, or Google Drive—provided the workspace allowed those actions.
Unlike traditional phishing methods that steal credentials or session tokens, this attack created a persistent insider threat. The rogue agent operated autonomously, using the victim's permissions to search corporate data, send messages, or exfiltrate documents. Zenity's proof-of-concept demonstrated how the agent could map organizational structures by scanning emails, chats, and calendars, or hunt for sensitive information like passwords and API keys in messages. Attackers could issue new tasks by sending emails with "TASK" in the subject line, turning the agent into a long-term corporate mole.
Background: ChatGPT workspace agents are AI assistants designed to automate tasks across business applications like email, calendars, and collaboration tools. Organizations enable these agents to streamline workflows, but they require permissions to interact with connected services. The vulnerability exploited the trust model between the agent builder and the user's existing integrations.
Impact and response
Zenity reported the vulnerability to OpenAI via Bugcrowd on June 4. OpenAI acknowledged the issue the following day and implemented a fix four days later by removing the URL parameter that enabled the attack. The patch was deployed before the flaw was publicly disclosed, preventing exploitation in the wild.
The attack surface highlighted by AgentForger extends beyond this specific bug. As AI agents evolve from passive assistants to active participants in corporate systems, they introduce new risks. Traditional security controls, such as endpoint protection or session monitoring, may not detect malicious agents operating within trusted environments. The incident underscores the need for granular permission models and behavioral monitoring for AI-driven workflows.
For professionals: Organizations using ChatGPT workspace agents should audit connected services and permissions, even if the immediate vulnerability has been patched. Review agent activity logs for unusual patterns, such as unexpected data access or message-sending behavior. Consider implementing approval workflows for agent actions until AI-specific security controls mature.
Broader implications
The AgentForger flaw illustrates a shift in attack vectors. Instead of breaching systems directly, attackers can now exploit the trust placed in AI agents to create insider threats. This method bypasses conventional security measures, as the malicious activity originates from within the organization's approved tools and permissions. As AI agents become more integrated into business processes, the distinction between software vulnerabilities and human-like threats will continue to blur.
Zenity's research also raises questions about the long-term security of AI-driven automation. Agents designed to act independently across multiple platforms may require new layers of oversight, such as real-time behavior analysis or AI-specific access controls. Without these measures, organizations risk exposing sensitive data to attacks that traditional security tools cannot detect.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 23 Jul 2026. Passed independent editor verification (score 92/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No existing article covers this specific AI agent phishing vulnerability in OpenAI's ecosystem.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers this specific AI agent phishing vulnerability.
- Writing the article — Draft created article_id=349 slug=chatgpt-workspace-flaw-let-attackers-forge-ai-agents
-
Editor review — Approved
- Score: 92/100
- Factual grounding: The draft states the fix was implemented 'four days later' after acknowledgment, but the source only says 'four days later' without specifying if this is calendar days or business days. While likely correct, the exact timing is slightly ambiguous in the source.
- Style compliance: The standfirst ('One-click link could deploy rogue AI inside corporate ChatGPT accounts') is 78 characters, slightly under the 90-character limit but could be more specific (e.g., 'malicious workspace agent' instead of 'rogue AI').
- Quote integrity: The draft does not use a blockquote for Michael Bargury's quote, though it paraphrases his statement accurately. The source contains a verbatim quote that could have been used as a blockquote if desired.
- No copied phrasing: The phrase 'autonomous assistant that could act through the employee's connected accounts and permissions' closely mirrors the source's 'autonomous assistant that could act through the employee's connected accounts and permissions.' While the idea is correctly paraphrased elsewhere, this instance is too similar.
- Generating reader Q&A — Generated 5 items
- Assigning hero image — Reused library image reused image #7
- Linking related stories — Linked 2 relations from 294 candidates
- Publishing — Published chatgpt-workspace-flaw-let-attackers-forge-ai-agents
- Mastodon — Posted https://mstdn.social/@hostingpaper/116969857437424205



Discussion · coming soon
Be the first to join the thread when community discussion launches.