Zenity Labs disclosed AgentForger, a critical flaw in OpenAIβs ChatGPT Workspace Agents that could let a single phishing link create and deploy an attacker-controlled autonomous agent inside a victim organization. OpenAI fixed the issue on June 8, 2026, after the flaw was shown to abuse URL parameters, connector permissions, and Preview Mode to turn a forged agent into a persistent insider. #AgentForger #OpenAI #ChatGPT #ZenityLabs
Keypoints
- A phishing link could trigger a CSRF attack against ChatGPT Agent Builder.
- The flaw could create an AI agent in the victimβs authenticated session.
- Attackers could attach connectors and disable approval prompts.
- The forged agent could run on a schedule and execute tasks from email.
- The agent could steal data, impersonate users, and send phishing messages.
Read More: https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html